By reverse-engineering[1] based on Snowden's leaks, they created the NSA
[1] reverse-engineering: https://en.wikipedia.org/wiki/Reverse_engineering
RADIO hackers have reverse-engineered some of the wireless spying devices used by the US National Security Agency (NSA). Drawing on documents leaked by Edward Snowden, the researchers have created simple but effective tools that can be hooked up to parts of a computer to collect personal information in a range of intrusive ways.
The NSA’s “Advanced Technology Network” catalog[1] was just one part of the avalanche of classified documents leaked by Snowden, the former contractor for the agency. The catalog contains a series of devices and photos of them that agents can use to spy on a target’s computer or phone (“target,” as the NSA calls a person they “single out” for surveillance from the data they collect through mass surveillance). These technologies include fake base stations for intercepting calls and monitoring cell phones and wireless devices on USB sticks that transmit the contents of a computer.
[1] https://www.eff.org/document/20131230-appelbaum-nsa-ant-catalog
see also: “NSA ANT catalog” https://en.wikipedia.org/wiki/NSA_ANT_catalog
But this list also lists a number of mysterious implantable computer devices, called “retro reflectors,” that have a number of different covert abilities, including recording the sounds made by keyboard keys when typing and harvesting images displayed on the screen.
Because no one outside the NSA and its collaborators knows how these reflectors work, security engineers cannot defend against their use (because their mechanism of action is unknown, they cannot build countermeasures or shields for them). Now, a team of security researchers led by Michael Ossmann[2] of Great Scott Gadgets[3] in Evergreen, Colorado, has not only figured out how these devices work, but has also managed to recreate them.
[2] https://www.defcon.org/html/defcon-22/dc-22-speakers.html#Ossmann
[3] https://greatscottgadgets.com/
Ossmann specializes in software-defined radio (SDR)[4], an emerging field of technology in which wireless devices are created with software rather than by building them from traditional hardware, such as modulators and oscillators. Instead of these circuits, an SDR uses digital signal processing chips to allow a programmer to specify the waveform of a radio signal, the frequency used, and its power level. It works like a sound card in a computer, but instead of playing sounds or processing incoming sound, it creates and receives radio signals. An SDR can switch to any radio band instantly, including AM, FM, GSM, and Bluetooth.
[4] https://en.wikipedia.org/wiki/Software-defined_radio
“SDR allows us to build any type of radio system we want very quickly, so we can investigate the security of a wireless network in any form of radio wave that works,” says Ossmann.
An SDR designed and built by Ossmann, called HackRF[5], was the key part of the project to replicate the NSA's reflector systems. Such systems come in two parts—a plantable “reflector” bug and a remote SDR-based receiver.
[5] https://greatscottgadgets.com/hackrf/
One such reflector, which the NSA calls Ragemaster, can be attached to a computer's display cable to eavesdrop on images displayed on the screen. Another, Surlyspawn, clips onto a keyboard cable and collects keystrokes. After much trial and error, Ossmann found that these bug-devices can be remarkably simple devices—little more than a tiny transistor and a 2-centimeter wire that acts as an antenna.
Receiving information from devices is the scope of SDR. Ossmann found that using radio waves to emit a high-power radio signal, which triggers a reflector to start wirelessly transmitting data, such as keystrokes, to a remote attacker. The whole setup can be likened to a long-range RFID-chip system[6]. Since the signals returning from reflectors are noisy and often scattered across several bands, the flexibility of SDR comes in handy, says Robin Heydon of Cambridge Silicon Radio in the UK. “SDRs are flexible, programmable and can be tuned to anything,” he says.
[6] https://en.wikipedia.org/wiki/Radio-frequency_identification
Ossmann will present his work in August at the Defcon hacking conference[7] in Las Vegas. Other groups will be there to reveal ways to hijack NSA spying technology. Joshua Datko of Cryptotronix[8] in Fort Collins, Colorado, will reveal a version of an NSA device he has developed that is loaded with malware that can reinstall itself, even after being “discovered” by antivirus software. It works by attaching a bug to an exposed part of a computer’s wiring system—called the I2C bus—on the back of the machine. “That means you can attack someone’s computer without even having to open the box,” says Ossmann.
[7] https://www.defcon.org/
[8] https://cryptotronix.com/
Having figured out how the NSA bugs work, Ossmann says hackers can now turn their attention to defending us against them—and they’ve launched a website to compile that knowledge, called NSAPlayset.org.[9] “Showing how these devices exploit the weaknesses in our systems means we can make our systems more secure in the future,” he says.
[9] https://www.nsaplayset.org/
—–
From: NewScientist, “Hackers reverse-engineer NSA's leaked bugging devices”, 18 June 2014 by Paul Marks”
https://www.newscientist.com/article/mg22229744.000-hackers-reverseengineer-nsas-leaked-bugging-devices.html#.U6KAYJR_uHs
Source: secnews.gr
