8 ms·
At a previous employer (Fortune 500, not a software co.) the IT security team would sometimes seed the parking lots with thumb drives that were "infected" with
by Merad 8y ago
At a previous employer (Fortune 500, not a software co.) the IT security team would sometimes seed the parking lots with thumb drives that were "infected" with a program that would phone home to them if plugged into a PC on the corporate network. IIRC there was a depressingly high (> 50%) rate of them being plugged in.
- ravenstine 8y agoThat's shocking. I know people are dopey, but 50%? I'd have guessed 20% at most.
- goldenCeasar 8y agoI would guess that some people may try more than one, or if there are lots of people and few thumbs given time someone more gullible will try them.
- a3n 8y agoNever underestimate the distribution of stupid. I worked at a hardware / software company where management distributed USB drives as a reward for something or other. The USB drives weren't even in blister packs they were just loose in plastic envelopes. I threw mine out, and wrote a complaint.
- ghaff 8y agoCompanies routinely distribute software/presentations/etc. on USB drives. I suppose it's poor security hygiene these days but it's still routine.
- TheOtherHobbes 8y agoEspecially when stupid is an observable attribute in the industry. Time and time again the technology industry has failed to consider security as a serious issue, never mind develop systems that are robust and transparent. We don't have botnets, booby-trapped mail attachments, script-hackable servers, USB drives that can carry a viral payload, and all the rest because users are stupid, but because the industry's default culture is to think of security as an esoteric side issue, and not a non-negotiable critical feature in all IT systems.
- evilDagmar 8y agoMore specifically, they tend to view it as a cost center that does nothing to increase profits. Thing #1 to remember if you're in infosec is that you must pitch it based on the money saved by not having expensive problems like having to hire outside consultants and auditors after a breach.
- akira2501 8y ago> the IT security team would sometimes seed the parking lots with thumb drives that were "infected" with a program that would phone home to them if plugged into a PC on the corporate network. Which is clever, but given the current level of small scale integration you could just as easily hide the same exploits inside of a charging cable, a USB fan, or really any other small-form factor USB-pluggable gadget. The problem isn't them discriminating between "hacked" and "non-hacked" devices -- it's them plugging _anything_ non work related or issued into their USB ports.
- eponeponepon 8y agoAnecdotally, I heard of a toy radio control quadcopter belonging to western military personnel in Afghanistan that turned out to be trying to phone home to ${badguy} when they plugged it into a laptop to charge. This stuff is everywhere, and has been for years.
- badwolf 8y agoThis is why I keep a large supply of "USB Condoms" (little dongles that short circuit the data, and allow charging/power only)
- illumin8 8y agoProduct idea: internal condoms for every USB port on a business computer. Let employees charge their phones in USB ports or plug whatever in, data wires never connect - problem solved: Employees can charge their ${device} without risking security compromise of the host workstation.
- colejohnson66 8y agoWouldn’t everything then only charge at 100 mA?
- cesarb 8y ago
- 3rdAccount 8y agoA lot of IT security teams do this. On one side it is depressing, but on another side it is annoying to have to hear them talk about it every staff meeting. All companies seem to have people with zero understanding of computers and will fall for anything. I wonder how effective the education is. I guess if it prevents one attack it can pay for itself.
- yjftsjthsd-h 8y ago> it is annoying to have to hear them talk about it every staff meeting Aren't you shooting the messenger?
- 3rdAccount 8y agoOnly a little bit. Most IT CyberSecurity teams can use bad stats to justify their value and additional staff, so they want to bring it up at every opportunity. I don't necessarily disagree, but power users often get frustrated by red tape applied to everyone and not just those who consistently misuse their computer privileges.
- deytempo 8y agoI’m not sure I understand what the big deal is unless your machine tries to run software automatically from devices that are plugged into it. If you plug something into a centOS machine it’s not going to be able to do anything until you mount it and even then why would code be able to run from it?
- wepple 8y agoWell for starters, if you’re curiously plugging it in, you’re going to mount it aren’t you? Second, it can emulate an HID keyboard device and type keystrokes faster than you can react and pull it out, at which point it’s far too late - it’s pulled a secondary payload down or mounted a USB mass storage device and you’re owned.
- deytempo 8y agoYou got me at the emulate a keyboard thing. Now I’m thinking that you shouldn’t plug strange keyboards or mice in because they could have an onboard payload. The crash cart at a data center is kind of a dumb idea in a way except the place is full of cameras usually
- deaps 8y agoYou're absolutely correct. You know those little desk fans that come with a USB now and also an adapter to plug into the electrical outlet. I don't plug those into my laptops ever - who knows if there's a payload on them. I will say this. I currently work, and have worked at, a few secret and top secret facilities - and the number of people I see plugging those (and similar) devices into their laptops is scary.
- jlgaddis 8y ago> the number of people I see plugging those (and similar) devices into their laptops is scary. If such a device is able to cause a compromise / incident in a secure facility, well, several different "failures" at several different levels have occurred in order for it to get to that point.
- sjwright 8y agoSo these IT genuises at a Fortune 500 company were clever enough to test their employees' computer security acumen (and get the predicted result) but they weren't clever enough to simply block all use of USB mass storage devices on their corporate operating system distribution? Surely by now all corporate desktops should be configured to not respond to any USB devices other than the generic HID for mouse and keyboard, plus a whitelist of approved devices (e.g. fingerprint readers, Yubikeys). Inserting a USB mass storage device into a corporate workstation should result in nothing. Plug-and-play shouldn't be triggered. The mass storage driver should not load.
- Merad 8y agoI don't think I've ever heard of a company that actually does this in practice. I suspect it ends up simply being more trouble than it's actually worth. I know at that company the list of approved device would probably end up being dozens of pages long... and yeah, thumb drives and USB hard drives were used a decent amount, especially outside of IT.
- acct1771 8y agoAnecdote for anecdote, I have.
- sjwright 8y agoMaybe someone needs to invent a USB-based thumb drive reader that only allows generic mass storage devices to be attached but does not work as a hub, rather as a proxy device. Bonus points: don't mount the drive directly, instead connect it to a centralised server on the corporate network that scans for threats and mounts a sanitised version of the drive's contents as a network share. Triple word score: audit everything contained on every drive and everything that is copied on and off. Sell that for $200 per unit to Fortune 500 companies and paranoid government agencies worldwide... and you'll retire early.
- thecatspaw 8y agoisnt that a NAS basically?
- DoubleGlazing 8y agoI was at a financial software firm that dealt with USB security issues by filling the USB sockets with epoxy. The keyboard and mouse could not be removed from their USB sockets as they were held in place with a metal collar bolted to the case. Simple and effective, although it destroyed any resale value of the PCs.
- LeonM 8y agoDo businesses (other than super small startups) actually sell their old hardware? Genuinely curious.
- majewsky 8y agoIn my company (Fortune 500), we get new notebooks every 3 years and IT persistently pesters owners of old notebooks to return them. Given the sheer number of devices, I can imagine a reselling contract to be a nice additional source of income.
- lllr_finger 8y agoYep, look on eBay for sellers that specialize in refurbishing them. It's a great way to get something like an older Thinkpad for really cheap. Perfect for a Linux laptop that doesn't need the latest and greatest.
- evilDagmar 8y agoIn the US, above a certain size you're basically required to sell off the old hardware because throwing it away counts as polluting, and the people who dispose of exclusively tech stuff charge you for that service.
- DoubleGlazing 8y agoIn this company's case the PCs were the cheapest of the cheap. Bottom end Dell and HP stuff. when they were life expired they were given over to a recycling company, whom I assume would take the time to pick the epoxy out of the USB sockets or probably just replace them. I think buying new USB sockets and connecting ribbons to the motherboards is probably quite cheap these days