▲ -10 ▼ Death of encryption - the real agenda behind Copilot & Recall? (youtu.be) submitted 2 years ago by Misk@lemmy.world to c/privacy@lemmy.ml 15 comments fedilink hide all child comments I know people have mixed opinions on Braxman but I don't see any huge leaps in logic here tbh... Thoughts?
[–] jet@hackertalks.com 5 points 2 years ago (3 children) Physical access trumps all. permalink fedilink source parent hideshow 6 child comments replies: [–] Misk@lemmy.world [S] 3 points 2 years ago (1 child) Physical access like an NPU chip fixed onto your motherboard? permalink fedilink source parent hideshow 2 child comments replies: [–] jet@hackertalks.com 2 points 2 years ago (1 child) Sure, anything with direct bus access to unencrypted data.... that'll do it permalink fedilink source parent hideshow 2 child comments replies: [–] GolfNovemberUniform@lemmy.ml 3 points 2 years ago (1 child) I didn't mean that. I meant if the hacker has access to the administrator (or just user in case with E2EE messengers) account, they can see and download anything, no matter how encrypted it is. The chips can do stuff as well but idk any proof of that tbh permalink fedilink source parent hideshow 2 child comments replies: [–] jet@hackertalks.com 1 point 2 years ago* (1 child) Sure, side channel leakage if you can run locally. Honestly, most machines have enough cores, that you could pin a process to a specific core giving it independent cache, and work around a lot of these side channel attacks. So you're encrypted end to end messenger would get an exclusive core. Kind of like how we do VM pinning nowadays permalink fedilink source parent hideshow 2 child comments replies: [–] GolfNovemberUniform@lemmy.ml 3 points 2 years ago (1 child) What? permalink fedilink source parent hideshow 2 child comments replies: [–] jet@hackertalks.com 1 point 2 years ago (1 child) Bone apple tea. Fixed permalink fedilink source parent hideshow 2 child comments replies: [–] GolfNovemberUniform@lemmy.ml 3 points 2 years ago Sus permalink fedilink source parent [–] PM_Your_Nudes_Please@lemmy.world 3 points 2 years ago* Eh, kind of. Remote Desktop with an admin account would be more useful than physical access to a locked computer. Because if Bitlocker is enabled, then all that matters is that you can sign into the computer. Use strong passwords, don’t open RDP to the WAN, lock your workstations when walking away, etc… Even cloning the drive to crack later (historically, this was a popular choice if you had physical access) is pretty useless if you don’t have a user’s password. permalink fedilink source parent [–] dwindling7373@feddit.it 3 points 2 years ago Not really? If disks are encrypted good luck getting anything out of it. A remote access to a running machine? It's all laid there. permalink fedilink source parent
[–] Misk@lemmy.world [S] 3 points 2 years ago (1 child) Physical access like an NPU chip fixed onto your motherboard? permalink fedilink source parent hideshow 2 child comments replies: [–] jet@hackertalks.com 2 points 2 years ago (1 child) Sure, anything with direct bus access to unencrypted data.... that'll do it permalink fedilink source parent hideshow 2 child comments replies: [–] GolfNovemberUniform@lemmy.ml 3 points 2 years ago (1 child) I didn't mean that. I meant if the hacker has access to the administrator (or just user in case with E2EE messengers) account, they can see and download anything, no matter how encrypted it is. The chips can do stuff as well but idk any proof of that tbh permalink fedilink source parent hideshow 2 child comments replies: [–] jet@hackertalks.com 1 point 2 years ago* (1 child) Sure, side channel leakage if you can run locally. Honestly, most machines have enough cores, that you could pin a process to a specific core giving it independent cache, and work around a lot of these side channel attacks. So you're encrypted end to end messenger would get an exclusive core. Kind of like how we do VM pinning nowadays permalink fedilink source parent hideshow 2 child comments replies: [–] GolfNovemberUniform@lemmy.ml 3 points 2 years ago (1 child) What? permalink fedilink source parent hideshow 2 child comments replies: [–] jet@hackertalks.com 1 point 2 years ago (1 child) Bone apple tea. Fixed permalink fedilink source parent hideshow 2 child comments replies: [–] GolfNovemberUniform@lemmy.ml 3 points 2 years ago Sus permalink fedilink source parent
[–] jet@hackertalks.com 2 points 2 years ago (1 child) Sure, anything with direct bus access to unencrypted data.... that'll do it permalink fedilink source parent hideshow 2 child comments replies: [–] GolfNovemberUniform@lemmy.ml 3 points 2 years ago (1 child) I didn't mean that. I meant if the hacker has access to the administrator (or just user in case with E2EE messengers) account, they can see and download anything, no matter how encrypted it is. The chips can do stuff as well but idk any proof of that tbh permalink fedilink source parent hideshow 2 child comments replies: [–] jet@hackertalks.com 1 point 2 years ago* (1 child) Sure, side channel leakage if you can run locally. Honestly, most machines have enough cores, that you could pin a process to a specific core giving it independent cache, and work around a lot of these side channel attacks. So you're encrypted end to end messenger would get an exclusive core. Kind of like how we do VM pinning nowadays permalink fedilink source parent hideshow 2 child comments replies: [–] GolfNovemberUniform@lemmy.ml 3 points 2 years ago (1 child) What? permalink fedilink source parent hideshow 2 child comments replies: [–] jet@hackertalks.com 1 point 2 years ago (1 child) Bone apple tea. Fixed permalink fedilink source parent hideshow 2 child comments replies: [–] GolfNovemberUniform@lemmy.ml 3 points 2 years ago Sus permalink fedilink source parent
[–] GolfNovemberUniform@lemmy.ml 3 points 2 years ago (1 child) I didn't mean that. I meant if the hacker has access to the administrator (or just user in case with E2EE messengers) account, they can see and download anything, no matter how encrypted it is. The chips can do stuff as well but idk any proof of that tbh permalink fedilink source parent hideshow 2 child comments replies: [–] jet@hackertalks.com 1 point 2 years ago* (1 child) Sure, side channel leakage if you can run locally. Honestly, most machines have enough cores, that you could pin a process to a specific core giving it independent cache, and work around a lot of these side channel attacks. So you're encrypted end to end messenger would get an exclusive core. Kind of like how we do VM pinning nowadays permalink fedilink source parent hideshow 2 child comments replies: [–] GolfNovemberUniform@lemmy.ml 3 points 2 years ago (1 child) What? permalink fedilink source parent hideshow 2 child comments replies: [–] jet@hackertalks.com 1 point 2 years ago (1 child) Bone apple tea. Fixed permalink fedilink source parent hideshow 2 child comments replies: [–] GolfNovemberUniform@lemmy.ml 3 points 2 years ago Sus permalink fedilink source parent
[–] jet@hackertalks.com 1 point 2 years ago* (1 child) Sure, side channel leakage if you can run locally. Honestly, most machines have enough cores, that you could pin a process to a specific core giving it independent cache, and work around a lot of these side channel attacks. So you're encrypted end to end messenger would get an exclusive core. Kind of like how we do VM pinning nowadays permalink fedilink source parent hideshow 2 child comments replies: [–] GolfNovemberUniform@lemmy.ml 3 points 2 years ago (1 child) What? permalink fedilink source parent hideshow 2 child comments replies: [–] jet@hackertalks.com 1 point 2 years ago (1 child) Bone apple tea. Fixed permalink fedilink source parent hideshow 2 child comments replies: [–] GolfNovemberUniform@lemmy.ml 3 points 2 years ago Sus permalink fedilink source parent
[–] GolfNovemberUniform@lemmy.ml 3 points 2 years ago (1 child) What? permalink fedilink source parent hideshow 2 child comments replies: [–] jet@hackertalks.com 1 point 2 years ago (1 child) Bone apple tea. Fixed permalink fedilink source parent hideshow 2 child comments replies: [–] GolfNovemberUniform@lemmy.ml 3 points 2 years ago Sus permalink fedilink source parent
[–] jet@hackertalks.com 1 point 2 years ago (1 child) Bone apple tea. Fixed permalink fedilink source parent hideshow 2 child comments replies: [–] GolfNovemberUniform@lemmy.ml 3 points 2 years ago Sus permalink fedilink source parent
[–] PM_Your_Nudes_Please@lemmy.world 3 points 2 years ago* Eh, kind of. Remote Desktop with an admin account would be more useful than physical access to a locked computer. Because if Bitlocker is enabled, then all that matters is that you can sign into the computer. Use strong passwords, don’t open RDP to the WAN, lock your workstations when walking away, etc… Even cloning the drive to crack later (historically, this was a popular choice if you had physical access) is pretty useless if you don’t have a user’s password. permalink fedilink source parent
[–] dwindling7373@feddit.it 3 points 2 years ago Not really? If disks are encrypted good luck getting anything out of it. A remote access to a running machine? It's all laid there. permalink fedilink source parent