4 ms·
I don't know much about this case but depending on the level of concern, even just plugging the device into a safe, isolated machine and performing an image may
by steven777400 7y ago
I don't know much about this case but depending on the level of concern, even just plugging the device into a safe, isolated machine and performing an image may be insufficient.
You could imagine a USB device that presented as a harmless file store unless certain conditions were detected, in which case the device could re-present as a keyboard (providing pre-programmed keystrokes) or potentially a bluetooth or wireless network receiver that could log or analyze traffic to a hidden partition.
I think the question of how to safely analyze suspect USB devices, at the level of potential nation-state actors, needs a lot more consideration and probably some custom tooling.
- jakeinspace 7y agoI can't think of many things more fun than coming up with some clever USB descriptor hacks to allow an innocuous drive full of pictures of grandchildren to carefully switch into an HID device when it thinks the coast is clear. I have to imagine there's a lot of little tricks you could implement which would be difficult to trigger in a sandbox and might require dumping the EEPROM (if that's possible).
- j16sdiz 7y agoThere are quite a few usb descriptor related exploits. e.g. https://www.cvedetails.com/cve/CVE-2013-3200/ https://www.cvedetails.com/cve/CVE-2013-3200/
- exelius 7y ago> I think the question of how to safely analyze suspect USB devices, at the level of potential nation-state actors, needs a lot more consideration and probably some custom tooling. I would be absolutely shocked if the US’ three letter agencies did not have some form of custom tooling to detect this — especially considering the sophisticated multi-vector I/O exploitation they demonstrated a decade ago with Stuxnet and the Equation Group. Regardless of your views on his policy, Trump has demonstrated zero respect for opsec — even in a national security context — so I would also not be surprised if those three letter agencies have decided the White House is untrustworthy with its cyber warfare capabilities.
- vanattab 7y agoLook, I hate Trump as much as the next guy(or gal) but do we really have to make EVERYTHING about trump.?
- untog 7y agoIn this case we kind of do. The USB stick was recovered from a woman who was visiting Mar a Lago. Trump conducts government business there a lot, in a break with pretty much all advice. It's an incredibly insecure location.
- SerLava 7y agoKind of. Are you unaware of how much shit we're in?
- gjs278 7y agopretty much none. your day to day life has not and will not change.
- tropo 7y agoSuppose it is just harmless to the computer, but it uses the USB port to power something else. It could contain a microphone and a transmitter. A more evil device, for assassination, could contain explosives or nerve gas. Plugging in the device is fatal.
- russdill 7y agoGreat plot device. When a certain file is opened, the nerve gas is released. Or when a file is saved with certain text or properties (author, etc). However, I'm doubtful that a small USB drive would have enough volume to be effective. Wouldn't matter on TV though.
- fulafel 7y agoThis sounds like an effective way to stall investigations for months in exchange for a movie plot threat scenario. "Boss, the electron microscope reverse engineering from that USB stick 6 months ago came back. They said they didn't find anything out of ordinary. The bill is $400k. But I guess we can start analyzing the contents now.".