Hacker News new | past | comments | ask | show | jobs | submit login

> I FedEx'd my SSD to the destination.

Are there any examples of laptops / ssds being searched in international mail?




If you take the time to FedEx your SSD to avoid customs you certainly made sure the disk was encrypted...


NSA can probably modify the firmware to create some sort of backdoor, if you actually look like that would be worthwhile?


Maybe the NSA can, maybe the NSA can't - but even if they could, I guarantee that customs/postal workers won't have access to it. Unless the NSA is specifically intercepting your particular SSD (in which case you have much bigger problems), standard enterprise-grade encryption will be good enough for shipping purposes.


This goes back to the level of protection you need/want, from whom, and whether you're a target of opportunity or a specific target.

Are you protecting against "drive-bys", the casually curious, motivated low-resource targeted attacks (e.g. disgruntled former employees, hated neighbors), "small" resource targeted attacks (<$50k?), high-resource attacks or state entities?


That would take a lot more work than just "searching through someone's private stuff on an airport" though;

I mean many "average" people get searched on airports, but i don't see why they would intercept an average guys Fedex shipped harddisk and do some voodoo on it. Unless of course you know you're being targeted for some specific reason.


If this is in your threat model, you shouldn't be taking advice from a forum thread.


Probably?

Snowden leaks already show NSA has badbios-style firmware viruses targeting every manufacturer, every model, going back a decade. Imagine what they have today. Why not mass infect all hard drives at the factory? Targeting individuals or "thematic warrants" are still too clunk and doesn't scale.

All these folks who say "I'll out smart them, I'll encrypt my SSD and Fedex it" are "Not Even Wrong."

http://www.spiegel.de/media/media-35661.pdf


As most encryption takes place at the software level, not the hardware level, wouldn't it be difficult to infect all hard drives with some virus targeting encryption?

Also, not to mention most of my hard drives are made by China, whom seem not to like the NSA very much. This leads me to believe that they may struggle with the mass infection part.




Join us for AI Startup School this June 16-17 in San Francisco!

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: