Can’t you just check network connections for suspicious activity? At some point the thing affected by the KTH would send an outbound signal either of data collected, or inbound signals if it’s updating the backdoor.
I think the point is that you can’t trust any software. Hardware you can only trust if you built it yourself from simple logic components like transistors. Not sure how you would observe network traffic on that basis, but it’s probably physically impossible to do because it would be so slow that you would die before you finished checking just one day worth of HTTPS requests.
You can automate a task to analyze the network traffic (though don’t underestimate human checks - remember the guy that noticed something was off by like 0.1% and discovered the logistics attack on Linux?).
Also, you can probably trust hardware made yourself that’s more than that, like FPGA.
Can’t you just check network connections for suspicious activity? At some point the thing affected by the KTH would send an outbound signal either of data collected, or inbound signals if it’s updating the backdoor.
I think the point is that you can’t trust any software. Hardware you can only trust if you built it yourself from simple logic components like transistors. Not sure how you would observe network traffic on that basis, but it’s probably physically impossible to do because it would be so slow that you would die before you finished checking just one day worth of HTTPS requests.
You can automate a task to analyze the network traffic (though don’t underestimate human checks - remember the guy that noticed something was off by like 0.1% and discovered the logistics attack on Linux?).
Also, you can probably trust hardware made yourself that’s more than that, like FPGA.