8 ms·
The author is right that USB-C docks can be used to hide malicious devices - but the same is true of any USB device. You could hide a Pi Zero in a mouse, keyboa
by seanherron 4y ago
The author is right that USB-C docks can be used to hide malicious devices - but the same is true of any USB device. You could hide a Pi Zero in a mouse, keyboard, memory stick, or anything else that you can open up and access the USB headers. Scary - but also requires a higher level of physical access than other vectors such as phishing.
- snow_mac 4y agoOr they could pre-make a bunch of docks and swap them out at a cowering space or target office building. Easy enough to gain physical access to most offices. You could get a job with the cleaning crew
- micromacrofoot 4y agoI imagine this is how a lot of basic espionage already happens?
- tedivm 4y agoThey could order a bunch from amazon or newegg and then return them. It wouldn't be as targeted but it would still get some interesting results.
- LanceH 4y agoSlap the companies logo on it and mail 100 of them to the office.
- npteljes 4y agoThey also bundle a separate CPU inside the real CPU, and gave it full access over the system. https://en.wikipedia.org/wiki/Intel_Management_Engine https://en.wikipedia.org/wiki/Intel_Management_Engine https://en.wikipedia.org/wiki/AMD_Platform_Security_Processor https://en.wikipedia.org/wiki/AMD_Platform_Security_Processo...
- metadat 4y agoDo ARM processors have a similar mechanism? Edit: Yes, it's called TrustZone. https://en.wikipedia.org/wiki/ARM_architecture_family#Security_extensions https://en.wikipedia.org/wiki/ARM_architecture_family#Securi...
- dmitrygr 4y agonot the same at all. Trustzone is a special mode of the very same main CPU (more like intel's SMM), whereas PSP and ME are a separate core
- elromulous 4y agoMore specifically, trustzone is the arm equivalent of Intel's (mostly deprecated) sgx. https://en.m.wikipedia.org/wiki/Software_Guard_Extensions https://en.m.wikipedia.org/wiki/Software_Guard_Extensions
- qbasic_forever 4y agoARM doesn't have a concept of anything like the management engine, but remember it's just an ISA and actual SoC implementations like from Qualcomm, Samsung, Apple, Amazon, etc. are free to add their own logic and side controllers.
- ace2358 4y agoWhich I feel like Apple does do? When I turn my iPhone off, it says it’ll still be able to be found using find my phone…
- concinds 4y agoThat's different. It's a feature where Apple deliberately keeps some components running after shutdown, in a very low-power way, and provides an option to turn that off. Those components (the Bluetooth chip, for example) are all strictly separated from each other by IOMMUs. Intel Management Engine is very different. It's basically another CPU within your real CPU, running its own software with no visibility to the main OS, and it has (AFAIK) full access to other components. If it's compromised, or has a factory backdoor, you're 0wned. The closest thing to Intel IME that the iPhone has, is the baseband, which can run its own code. But if I'm reading marcan correctly (https://news.ycombinator.com/item?id=30393283 https://news.ycombinator.com/item?id=30393283), modern iPhones/Android phones all use IOMMUs to isolate that (with the exception of a few so-called "free/libre" phones). The IOMMUs can be easily inspected from the OS to make sure they're correct, so it's just not a concern, unlike IME.
- bobsmooth 4y agoDo co-working spaces usually have shared peripherals besides docks?
- dotancohen 4y agoI've seen monitors, keyboards, mice, network printers, wifi access.
- Cthulhu_ 4y agoEven a simple charging cable can contain e.g. a HID chip while still working as a charging cable. I saw an unattended cable on a table at work once, I'm sure someone who needs one would've used it without second thought. But our employer is also sending fake phishing emails to make people aware, I wouldn't be surprised if they also plant devices like that. ...and if they don't I should propose it, sounds like a fun project. Leave a random cable or USB stick that just shows a warning that it could have been malicious. Or something that just opens up https://nyan.cat https://nyan.cat and sets the volume to max :D.