लैपटाप और कंप्यूटर सुरक्षा

Layer
Software Why package install need root access?
Not all of them need root access to run. Something is not right.
Software an innocent looking PDF file can be hacked PDF dangers
Can't we make default Gnome/Evince PDF viewer safe(r) ?
Software Linux distributions including non-free-firmware
Citing potential bigger base with far more users by Debian team voting for non-free binary drivers in 2022 (Debian 12)
Microsoft Windows
Hardware Embedded Controller
this doesn't let you read the SPI flash image. In some cases replacing this IC can lead to unusable laptop. Its fused with one-time programmable code.
Hardware BIOS
Even without Intel ME, manufacturers that don't use open source bios many times include Computrace baked into the bios. Computrace is an IT asset management and theft recovery software, now known as Absolute Home & Office, that is embedded in the firmware of many computers. It is designed to deter theft and aid in the recovery of stolen devices by using a persistent module that can track the computer even if the hard drive is reformatted or replaced. Users can purchase a subscription to activate and use the service to track their computers and work with law enforcement in case of theft.
Coreboot
Hardware

Intel processor backdoors and side-effects

Since 2009 all intel processors have a less-transparent and less-documented extra processor within processor die/board. Its called by names - Intel backdoor - Intel AMT (IME).

It is not visible to Linux running on top of system, yet has abnormal access to - memory, devices and ethernet traffic.

Ring -3 : deep hidden backdoor (2026 updated analysis)
Overview video about hacks and possible defenses - ports 623, 664, 5900, 9971, 16992-16995

3 impact analysis presentations

Hackers sharing their findings - 2017-me_cleaner, ME version 11.x

Feature/vulnerability Security concerns General safety precautions Specific solution
ME (management engine) + vPro (AMT) - Almost all AMT features are available even if the PC/laptop is in a powered-off state but with its power cord attached, if the operating system has crashed, if the software agent is missing, or if hardware (such as a hard drive or memory) has failed.
- AMT is available on PCs built on the vPro platform. Platforms equipped with AMT can be managed remotely, regardless of its power state or if it has a functioning OS or not.
1. Switch off electrical power supply when PC/laptop is not in use.
2. Switch off Wifi/router when not in use.
3. Disable IPv6 on Wifi router.
4. Use MAC filtering and all possible firewall rules on Wifi/router.
1. ME firmware is stored on SPI flash memory.
SPI can be re-flashed to remove ME (step-by-step detailed video).
2. ME hardware utilises network controller chip on motherboard. So install a new network card (PCI based) which will remain independent OR use a USB to LAN adapter Wifi/wired.
3. Get someone else to do it for you.
vPro(has AMT/IME) SA-00086
CSME - (Convergence Security and Management Engine Exploit)
- 2017, Gain elevated admin priviledge, Keyboard logging (similar to iphone conclave chip)
needs physical access to computer -
Spectre - - -
Meltdown - - -
CSME - - -

TIP :- reverse engineering tool Ghidra

वाई फाई Wifi / Modem

- Tor network tracing is exposed in Surveillance Valley by Yasha Levine.


- Remote control of your Wifi lies with ISP company


- Wifi modem can track your physical movements within your ़home

Use open-source routers. Security patches are important.

भारत में इंटरनेट सुरक्षा

M.Sc. Cyber Security

Naval office WESEE

M-Sigma app, part of Sambhav


चुनौती

Digital colonialism


Free Software GNU/Linux poisoning

Sabotage and subversion from NSA / RedHat ?

Lots of developers observed GNU Linux Desktop development getting "sabotage" from Red Hat developers.

Excellent video - above and beyond the Edward Snowden 2013 leaks, PHK describes "ways" to disturb the development ( video)

- GNOME vs KDE
- udev systemd complexity
- too much complexity in desktop,
- GNOME bug tracker restriction

- Libraries - Open source patches still needs to be code reviewed for security vulnerabilities. detailed video here

इंटरनेट सुरक्षा


Cyber Power Index 2022


अलग-अलग देशों में की स्थिति देखें।

भारत अमरीका चीन से रशा जर्मनी वियतनाम
बहुत पिछड़े हुए हैं। जानकारी नहीं है। कुछ मुट्ठी भर जानकार कुछ कर भी नहीं पाए हैं। माइक्रोसोफ्ट विंडोज (*), एप्पल, Kali Linux डीपिन लिनक्स, ओपन काइलिन Vanilla Linux ओपन सूजी
क्यूं मामू Qmamu गूगल खोज Baidu (blocked in India)
इंडस ऐप स्टोर गूगल प्लेस्टोर
YouTube, Rumble RuTube,
app link
Koo (now closed) Facebook, Twitter Weibo Mastodon
Instagram RedNote (Xiaohongshu)
Amazon अलीबाबा , Taobao and Jingdong (JD.com)
अरत्ताई ऐप
WhatsApp, सेशन Session (Open source) WeChat Max, Telegram
Bhim Google Pay AliPay
Youtube Reels RedNote (Xiaohongshu) , TikTok, Douyin RuTube Libre Office
Vikram 32-bit chip Intel (*), AMD Biren BR100
Huawei Ascend 910C
MetaX
Cambricon
Loongson
Elbrus राउटर TP-Link

Chip war in AI