Forgot your password?
typodupeerror
China Portables Security IT

The Trouble With Bringing Your Business Laptop To China 402

Posted by Soulskill
from the laptops-are-the-panda's-favorite-food dept.
snydeq writes "A growing trend faces business executives traveling to China: government or industry spooks stealing data from their laptops and installing spyware. 'While you were out to dinner that first night, someone entered your room (often a nominal hotel staffer), carefully examined the contents of your laptop, and installed spyware on the computer — without your having a clue. The result? Exposure of information, including customer data, product development documentation, countless emails, and other proprietary information of value to competitors and foreign governments. Perhaps even, thanks to the spyware, there's an ongoing infection in your corporate network that continually phones home key secrets for months or years afterward.'"
This discussion has been archived. No new comments can be posted.

The Trouble With Bringing Your Business Laptop To China

Comments Filter:
  • encryption (Score:5, Insightful)

    by Anonymous Coward on Tuesday December 04, 2012 @08:41PM (#42186741)

    Why doesn't your business mandate HDD encryption?

    China isn't the only place this goes on...

  • by stevenh2 (1853442) on Tuesday December 04, 2012 @08:43PM (#42186761)
    Who leaves their business secrets in the open. Especially laptops, they get lost stolen, or as the article says people examining it. Really you can use a truecrypt container and hide it somewhere.
  • by sconeu (64226) on Tuesday December 04, 2012 @08:56PM (#42186889) Homepage Journal

    If your boot partition is encrypted, and you can't boot without entering the password, it's harder to put a trojan or a keylogger on the system.

  • Sources Please? (Score:2, Insightful)

    by Anonymous Coward on Tuesday December 04, 2012 @09:07PM (#42186979)

    I see a lot of unsubstantiated opinions. How about some credible sources that this is happening?

  • by DNS-and-BIND (461968) on Tuesday December 04, 2012 @09:59PM (#42187445) Homepage
    Industrial espionage is one thing. This is a government employee entering your hotel room to install software on your laptop and image your hard drive. It has been happening for years in China (but has just now made Slashdot). It is practically a signature move of theirs.
  • by CoderJoe (97563) * on Tuesday December 04, 2012 @11:37PM (#42188009)

    How about just doing a boot-time truecrypt volume? They can't boot the system from the hard drive, and booting from a live CD/USB is also useless, as the data on the hard drive is encrypted. (unless they want to take the time to image the whole hard drive so they can work on cracking it elsewhere)

  • Yeah (Score:3, Insightful)

    by bytesex (112972) on Wednesday December 05, 2012 @03:45AM (#42189253) Homepage

    We have the same problem. With an obscure little country called the USA.

    Sorry, but the hypocrisy is staggering. We are NOT allowed to even bring an encrypted laptop across US borders.

  • Re:Fix 'em good. (Score:4, Insightful)

    by Dr_Barnowl (709838) on Wednesday December 05, 2012 @05:15AM (#42189547)

    Even more vulnerable - your compromised host machine could be screen-scraping the virtual image for all it's worth and sending the snapshots to Uncle Chang (side note - what is the Chinese equivalent of "Uncle Sam"?).

    The guest machine also needs an unencrypted bootloader - because it's a virtual computer with the same BIOS implementation, which could be compromised in exactly the same way as the host.

    UEFI Secure Boot? Not a defence. If you can get access to the machine, you can swap the BIOS out with one that trusts the signing key of Chinese Intelligence, and will load their signed bootloader. Or they'll just filch the Microsoft signing key and use that.

    Boot from a USB that you keep on your person? Doesn't preclude your compromised laptop running some kind of hypervisor that captures all your keystrokes and again, mails them to Uncle Chang.

    At the basic level they could just insert a traditional hardwired keylogger between your keyboard and motherboard, and you'd never detect it unless you were around when it decided to phone home (some models will run commands to send their logs out).

    The only defence is not to leave your hardware unattended. Maybe this is a good use case for a Raspberry Pi in a physically secure case - powerful enough for basic productivity computing but portable enough to keep on your person. For maximum security you'd also have to carry the display and any input devices, so a visor display (like Google Glass), and a roll-up USB keyboard and mini-mouse would be reasonable.

  • Re:encryption (Score:4, Insightful)

    by Dr_Barnowl (709838) on Wednesday December 05, 2012 @05:38AM (#42189635)

    They defeat your HDD encryption by attacking the weak spot - the non-encrypted bits on your laptop.

    The same physical attack pattern would work for VPN - keylogger, hypervisor, whatever, because it's still a compromised machine with access to the sensitive data.

    The only defence is not to be separated from your hardware - which means carrying your laptop on your person at all times. They can still arrange to have it stolen by a "mugger", but it was all encrypted, right? But if the police conveniently "find" the culprit and give it back, you can't use it.

  • Re:Fix 'em good. (Score:4, Insightful)

    by Electricity Likes Me (1098643) on Wednesday December 05, 2012 @09:48AM (#42190887)

    This is also unreasonable.

    While it is technically possible to do most of these things, for low-grade espionage it's way too expensive to do and requires a well-defined target (i.e. building up a stock of compromised ROMs, of every laptop you're likely to hit, would be expensive as hell and even then you might end up tripping something or damaging the hardware doing it).

    The BIOS swap for example would be particularly troublesome - you'd need to pull apart the laptop, desolder the BIOS chips and solder new ones. No matter how good you are, that's not going to be done in anything less then a few hours, presuming you had all the tools, the chips, and it went flawlessly. And it would require knowing the exact make and model of the target machine.

"It is better to have tried and failed than to have failed to try, but the result's the same." - Mike Dennison

Working...