hobune Channels Contact About Donate

Buying a USED laptop is a Security Risk! Here's how to help mitigate that.

Back to video page | Download comments jsonl

Comments (archived 2022-07-03 15:15; 43 top, 68 total comments)

jnex26 2020-08-24 17:32:45

Righty oh ... mr paranoid spreading fear here ... OK he is partially right tho there is such a thing as firmware malware its rare and unlikely to be used in a random attack as its uber traceable .. and as this is ring zero its pretty damn awkward to remove at times there are engines out there that can detect this firmware like trapezoid firmware integrity engine.

Onto the O/S so he created a forensic image (for what purpose) and sniffed through deleted files ( let's hope its not a ssd as once trimmed a ssd is irrecoverable) but looking for deleted files is frankly attempting to access unauthorised data and maybe depending on your country and laws possibly punishable.

So my list buy If I buy second hand laptop.
Flash firmware(bios)
Reset bios
Format disk and install operating system. ( if you want to install Windows just google Windows boot disk creator)

For those using Linux, you already know all the above..

43 likes
Replies (1)
jnex26 2020-09-08 21:41:27

@no, as a matter of fact spent a bit of time in data recovery world.. rotational disks you can reassemble partitions, ssds just a quick trim

0 likes
jablue 2020-08-27 23:22:29

While I think the risk is small, there's no reason to even take a small risk. Good on you for sharing these tips.

11 likes
Replies (1)
Smug Anime Girl 2020-10-14 09:26:13

Then you have to buy a ThinkPad old enough to be able to be CoreBooted and have the Intel ME disabled. ;^)
There's no point in being too paranoid with opsec, you are not as important as you think in the eyes of the government, unless you're a terrorist, drug dealer, pedo movie producer, or a journalist or political activist in an authoritarian country. Computers are too complex for you to be ever able to trust them, carrier pigeons may actually be safer to use.

1 like
kintustis 2020-09-03 10:37:05

You should reinstall the OS anyways because either:

You run windows and don't want to deal with someone else's programs and files, or manufacturer bloatware

Or
You run Linux and would have to anyways.

You should update the UEFI/BIOS not because of some boogeyman firmware malware, but because most people never do anyways, and it's good practice, plus it can increase compatibility with hardware if nothing else.

Snooping into other people's deleted files is creepy and invasive as hell. Frankly it's just as bad as someone planting malware in the first place: it's data you shouldn't have access to and just because you can, doesn't make it okay. It's like breaking into someone's house because they left their back door unlocked.

If you go to this level of trouble not just for a tidy, updated system, but because you're terrified of the one in a million chance someone spent days, maybe months or years, engineering a semi-custom firmware/hardware malware, you're insane. Especially when at the same time, there are plenty of real, for-profit software and hardware organizations that can barely even get WiFi, webcams, GPUs, or microphones working. Planting malware in the OS it came with, I can understand as it's easier to do, but again, you should be installing a fresh os anyways.

If you do it because you're a security expert who finds it fun, or a snowden, a spy, a terrorist, a "poor little journalist investigating sensitive subjects" (always seems to be the go-to example), or just happen to be buying a used laptop to carry millions of dollars of your company's IP, then I can understand. Otherwise it's doing more harm than good to suggest that not doing these things is going to leak people's bank info.

10 likes
Replies (1)
Fette Taube 2020-09-16 12:37:11

Imo selling a hard drive means selling the data on it. What does the law in your country say about this?

0 likes
『CHAR』 Ninja 2020-08-10 16:10:28

hey sir, i would recommend you to insert the text so i can clearly understand what are you sayibg coz u speak lil faster ... IT's not necessarily but i love your 1 min rich videos..

115 likes
Replies (7)
Rifqi L 2020-08-12 21:44:20

finally someone with same thought

10 likes
Filip 2020-08-14 08:35:44

or maybe get a pair or ears

5 likes
『CHAR』 Ninja 2020-08-17 12:37:27

@UN-common Sense AUS i'm learning but i ain't native but thank you

13 likes
Inertia Dorifto 2020-08-21 13:28:53

You can always reduce the playback speed to 0.75x

6 likes
CokaE CokaE 2020-08-25 02:17:00

nija problem alahai xtau ke perang abes forword lama buat apa alamak i ar

0 likes
CokaE CokaE 2020-08-25 02:17:17

@『CHAR』 Ninja tau pun haha

0 likes
#proderis 2020-09-24 04:40:58

change the video speed

1 like
Farid Neshat 2020-08-15 17:51:36

If you have reasons to be paranoid, never buy second hand hardware like that from untrusted sources/vendor. You'll never know if everything inside has not been tampered. Easiest would be a chip tapping into one of the usb slots. Google super micro chips in the news.

1 like
BellTheMarble 2020-09-11 05:11:22

Great, now i cant have a safe pc without having a phd in computer security wooo

3 likes
Piva Prera 2020-08-18 11:38:42

Oh wow that's why I never bought something used :c you could take a risk to be hacked or something like that

1 like
vppe05102 2020-08-07 18:51:33

Do you have a site online where you go into more detail on the tools you use and constructing a kali usb toolbox?

8 likes
Replies (1)
Monocle TheFifthWatcher 2021-04-25 22:37:59

No copying

0 likes
Yuri Moe 2020-08-07 14:14:33

Hey can you do some diy external hacking tools

5 likes
nauman qamar 2020-09-03 18:12:12

Watched this video a few times but still can't understand how to do it 😃☺️

3 likes
HAKSPY IN TELUGU 2020-08-26 11:49:33

If you make a full tutorials it will be a lot more helpful

1 like
chadthedad 2020-10-28 14:49:52

Could we get a more in depth video on this?

0 likes
LBSi UK 2020-09-06 16:55:51

No, it isn't. Just reinstall your OS and update the BIOS/UEFI (not because they will hack you but because it's just a good thing to do) and nobody can hack you.

0 likes
Soodless 2020-08-20 21:25:32

Umm...

I think I'll just buy a new laptop.

6 likes
C 2020-08-26 12:24:33

if this laptop has intel s management engine or amd s equivalent, is it secure?

1 like
Replies (1)
Sketchy 2020-08-30 18:56:35

by technicality no because it can be exploited but unless you want to buy something from 2008 or try and disable it yourself despite the major risks there's nothing you can do, everything else has the same flaw too

1 like
Making Pancakes 2020-08-07 14:15:24

Would you recommend buying of craigslist laptops, if we follow your procedure (to the point and beyond)?

2 likes
Replies (1)
H4ckantrieb 2020-09-03 02:00:05

@mister.T Jr lol almost every Job does pay monthly where the hell are you from?

0 likes
CaseyWX 2020-09-08 16:27:22

YouTube only recommends me videos with a ThinkPad in it!

1 like
Mels 2020-08-14 20:10:51

This good that you are doing this but the just sounds like pain I think I would just buy a brand new laptop instead.ps I did buy a use laptop before it was really nice I guess but the battery wasn't great and my charger broke in the end so I bought a new one but the changing port is broking or something wrong I don't know but suck so, want I'm trying to say is maybe don't buy a cheap/used laptop.

1 like
Replies (1)
Sketchy 2020-08-30 18:54:43 (edited 2020-08-30 18:54:59 )

You can get charging port replacements online, the connector isn't soldered onto the motherboard (usually)

0 likes
M Rusli 2020-10-04 10:47:39 (edited 2020-10-04 10:51:05 )

Can i ask a question? Some of the Lenovo Thinkpads only comes with Intel Integrated Graphic cards. Since it does not come a Dedicated GPU like Nvidia GT'X or AMD Radeon. I wonder any possibily doing password hashcat cracking with only Intel Graphic card as it only using 1GB shared memory with the RAM. How about the current lineup of Apple macbook pros? How to pentesting since it only using thunderbolt 3. And require using Thunderbolt 3 dongle. Any success rate of using Kali Linux with the current macbook pro line up that comes with Apple T2 chip problems???? There are numerous problems as it causing apple T2 chip crashing. What can you reckon me to buy a PC laptop or still a macbook pro 16 inch?????

0 likes
David Croteau 2020-08-22 20:43:08

If you just remove the BIOS battery could does it remove virus on the firmware

0 likes
DayananDh N 2020-08-09 05:20:04

Persistence boot for kali linux is not working, can you help me with that?

1 like
oSenzuYT 2020-08-21 17:54:56

Could someone explain to me in detail how to do everything he says to do?

0 likes
Replies (1)
Zack Davidson 2020-08-22 08:46:41

oSenzu YT yea: step one: don’t be insecure, this will never happen to you. Maybe 1 x 10 ^-50 % chance

2 likes
pur 2020-09-08 17:28:25

Wiping hard drive in a forest... How romantic

0 likes
A B 91 2020-08-13 15:25:38

I must learn.

0 likes
Red skull 2020-08-21 19:56:11

I am a beginner in security
Any advice

0 likes
Red skull 2020-08-21 19:55:44

I am a beginner in security
Any advice

0 likes
Replies (1)
K I R 4 N 2020-08-22 18:58:25

No system is safe.

0 likes
Braden Nye 2020-09-10 18:31:28

I'll just get a new one

0 likes
r00t d1ctat0r 2020-08-15 12:41:30

Camera closed XD💀

4 likes
Yuri Moe 2020-08-07 14:15:00

Like diy rubber ducky or something like that

1 like
Subhashish Mishra 2020-08-20 09:18:38

Anyone suggest me a good laptop please

3 likes
Amir Enik 2020-08-26 10:43:07

Hate when I delete my porn folders before sell laptop and then some guy finding them looking for deleted suspicious files :<

2 likes
Thein Win 2020-08-11 16:19:58

Thank

0 likes
Florida Man 2020-09-15 03:53:23

bro this mans speaking enchantment table what the frick

0 likes
Islam Mahoud 2020-08-24 21:03:57

Thnx

0 likes
nauman qamar 2020-09-03 18:13:00

Crypto the Lama. Help!

0 likes
Daniel Gjypi 2020-09-03 23:22:11

I have a fucking x250 too

0 likes
Sad Froggo 2020-08-16 10:12:07

Im too stupid for this

0 likes
HwiththeN hany amer 2020-09-08 19:17:27

Can you help me on my Inspiron Laptop? Mostly everyone has this problem with their dell inspiron computer, and most of the discussion is on dell support. The 2 w s x and caps lock are not working.

1 like
Freddie Jackson 2020-08-07 15:08:39

You must be rich

0 likes
GOLD moon 9999 2020-08-07 15:13:10

Are you hacker

1 like
nonasuomynona 173 2020-08-07 15:25:04

Why are you using kali as your main os?

3 likes
Replies (7)
Meh Meh 2020-08-13 17:09:43

Pen testing.

1 like
nonasuomynona 173 2020-08-13 17:11:18

@Meh Meh he can run it as a vm

0 likes
Meh Meh 2020-08-13 17:14:39

@nonasuomynona 173 And dual boot it from a usb, your point is?

0 likes
UN-common Sense AUS 2020-08-17 09:26:54

Why not ? ...

0 likes
nonasuomynona 173 2020-08-17 11:55:34

@UN-common Sense AUS on Kali Linux’s official page, it is explicitly mentioned that:

Kali is a Linux distribution specifically geared towards professional penetration testers and security specialists, and given its unique nature, it is NOT a recommended distribution if you’re unfamiliar with Linux or are looking for a general-purpose Linux desktop distribution for development, web design, gaming, etc.

1 like
UN-common Sense AUS 2020-08-17 12:23:32

@nonasuomynona 173 my point stands.

0 likes
nonasuomynona 173 2020-08-17 16:41:11

@UN-common Sense AUS sure

0 likes
Icicle 2020-09-06 07:50:17

Haha lenovo stinkpad

0 likes
Ashish Kumar 2020-08-10 16:23:09

Hey gib me a free laptop ..... Me really poor 😭

0 likes
Replies (2)
Israr Alam 2020-08-12 09:21:28

Mtlb maangne wali aadat nhi jayegi 😂😂

1 like
Meh Meh 2020-08-13 17:10:15

I'm good.

0 likes