6 ms·
Great opportunity to remind people: never ever plug an unknown USB device in your computer. Even USB-C chargers can infect your machine as outlined here: https:
by ea016 8y ago
Great opportunity to remind people: never ever plug an unknown USB device in your computer. Even USB-C chargers can infect your machine as outlined here: https://twitter.com/_MG_/status/949684949614907395 https://twitter.com/_MG_/status/949684949614907395
- swebs 8y ago>Even USB-C chargers can infect your machine Why would anyone assume otherwise?
- eugeniub 8y agoNot everyone is an opsec expert
- mannykannot 8y agoIndeed - and an opsec expert needs to have a clue about human nature, anyway.
- swebs 8y agoOk, but why would you assume that USB-C is somehow more secure than USB-B?
- okmokmz 8y agoMy guess would be that many USB-C products are charging cables, dongles, and other items that the average user would not associate with having the capability to store data making them inherently "safe" in their eyes. USB-A, on the other hand, is commonly associated with storing data, and the majority of user awareness and education about the danger of unknown devices is focused on flash drives. For these reasons I can see how someone without technical experience may believe that flash drives specifically are potentially dangerous, while believing that other USB-A/USB-C cables/adapters/chargers are safe. In my experience most users don't even know what USB-B is
- dabernathy89 8y agoI'm a web developer and I had no idea ¯\_(ツ)_/¯
- mdip 8y agoOutside of this audience, it's rather common[0]. It's not something that people, outside of these communities, harp on all that much. But even take things we do harp on, like not reusing passwords, are still things that the majority of people do[1]. I worked in various security positions at one of the US's biggest ISPs and routinely brought these sorts of things up to family members. I am embarrassed by the kinds of practices my family employs. The excuses vary but most of them fall along the lines of the same excuses smokers give when asked about lung cancer risks: "It Won't Happen to Me(tm)". Even within our industry, bad practices exist all over the place. An example I often point to is Code Signing certificates[2] -- I went through the trouble of generating a CSR offline using a Linux live CD, backed up the private key to an encrypted thumb drive and placed the result on a Yubikey to protect it when I need to sign something. The best part was sorting out how to actually give the CSR to the CA I used to purchase the key from. They offer all kinds of convenient, (IE and Firefox-only) in-browser mechanisms which result in generating the key online in a potentially already-compromised machine, but I ended up having to go through several steps using phone support to get my CSR to the CA. The way they did things encourages people to not think about protecting the private key; simply leaving it on an unencrypted volume with (likely) no other encryption used to protect the key. [0] https://thenextweb.com/insider/2011/06/28/us-govt-plant-usb-sticks-in-security-study-60-of-subjects-take-the-bait/ https://thenextweb.com/insider/2011/06/28/us-govt-plant-usb-... And these are specifically the kinds of people that should expect to be targets of an attack like this. [1] https://digitalguardian.com/blog/uncovering-password-habits-are-users-password-security-habits-improving-infographic https://digitalguardian.com/blog/uncovering-password-habits-... [2] I mention this kind of certificate because its credentials are such that an individual or company is named -- it's meant to identify a person or a legal entity, not a domain name -- and things signed with it result in that legal entity or person's legal name being displayed on launch in operating systems like Windows. It's something that you really wouldn't want to have fall into the wrong hands lest your name end up being prominently displayed prior to the installation of malware.
- ramy_d 8y agoPeople assume cables are dumb metal connections, nothing more. It doesn't help anyone to be condescending about op-sec.
- gascan 8y agoPower/charging cables in particular. After all, when was the last time your power drill caught a virus from your extension cord?
- bluesnowmonkey 8y agoWe assume that bridges won't collapse, planes won't fall out of the sky. Engineers are supposed to build things that are safe to use. That's a reasonable expectation.
- overcast 8y agoYou're more naive than the people you're referring to.
- untog 8y agoBecause they are chargers. My 2015 Macbook charger is not vulnerable, my 2016 Macbook charger could be. It's not reasonable to assume that end users intuitively get that.
- maxxxxx 8y agoHow is the regular guy supposed to figure out if a USB device is OK or not? I guess the easy answer is to say "Don't use an unknown device" but I don't think this is practical especially in the case of a charger. It's like the constant battle with our IT department to get and keep admin privileges on our machines. Yes, this can cause a problem but we need admin rights to do our job.
- DaiPlusPlus 8y agoMake “USB Condoms” that only have the power pins, no data. Educate users to see if these no-data devices have data pins.
- seanp2k2 8y agoWithin the context of USB Power Delivery , it needs more than simple power and ground to actually work. While it’s theoretically possible to make such a device that would determine which device is the source and sink, determine voltages and charge rates, then smartly select one and begin charging without the devices directly communicating, no such off-the-shelf device currently exists as far as I’m aware. You basically want a USB PD firewall that would only allow commands relevant to changing through, or have it generate synthetic responses that would e.g. never allow it to expose things like a mass storage interface. You might also need drivers depending on how you implement it. It would be a cool project / crowdsupply / Kickstarter though. More info: http://www.usb.org/developers/powerdelivery/ http://www.usb.org/developers/powerdelivery/ Right now, USB-C is only just starting to get past the “which cables will physically harm my device with a given charger even though they plug in correctly” phase.
- floatingatoll 8y agoIn the case of a charger, you must always use a charge-stop adapter if you’re charging from a public charger. They’re cheap and a couple offer bulk discounts to companies.
- mimimihaha 8y agoNow thinking about it, if you made a malicious USB charging block that looks like the iPhone‘s and offered it to me, id probably fall for it.