4 ms·
If you have a zero day takeover via usb/lightning why would you waste it on public charging infrastructure? That seems ridiculous.
by shiftpgdn 3y ago
If you have a zero day takeover via usb/lightning why would you waste it on public charging infrastructure? That seems ridiculous.
- aaron695 3y ago[dead]
- TedDoesntTalk 3y agoWhat other attack vector would you choose?
- aaomidi 3y agoYou’d use it to attack the targets you care about rather than just the general public.
- pc86 3y agoThe way you attack a specific target without alerting them (or at least making them suspicious) is to attack them indirectly. The sibling comment above is an excellent example of why you might specifically target public infrastructure if you only really care about one person.
- londons_explore 3y agoYou could ship the victim malicious USB cables in the mail with amazon branding on the box. Many people would use them, assuming they were just mis-shipped or ordered by their spouse.
- opwieurposiu 3y agoThis would totally work on me. My wife is always buying USB cables from amazon, IDK what we do with them all.
- lfowles 3y agoOr is she....
- Xylakant 3y agoHard learned fact: USB cables are consumables, just like ink or toner for your printer. They need to be refilled every so often.
- londons_explore 3y agoIt's a real shame that the USB standards creators didn't work harder on error-proofing and longevity. If I were on the standards committee, I would have made every pin interchangeable - ie. any pin can be gnd, any pin can be Vbus, any pin for data, etc. When plugged in, the device on the end would test every pin, and then decide which to use for data and which to use for power. That way, when a cable gets a bit old and 3 out of 30 pins are shorted or dirty or otherwise bad, the cable works but simply delivers 90% of the power it used to. The absolute cheapest cables could have just 2 pins, and would be slow and low power, but still fully 'working'. This wouldn't have added much cost to most devices either - most devices have a dedicated IC for USB functionality, and that IC can deal with muxing signals and power. On devices which only take power, a simple array of diodes can take power from any pin. Data signals could be capacitively coupled, meaning the muxing could be done on a single chip without needing special high voltage silicon processes (the cost of a chip goes up a lot as soon as you want it to deal with high voltages on any pin).
- thomastjeffery 3y ago...leaving a literal paper trail of package location tracking? Mail fraud is considered serious. Why commit an extra crime?
- kevin_thibedeau 3y agoYou can put a padded envelope into a public mailbox.
- NoZebra120vClip 3y agoLess serious than tampering with fixtures in a secure area at an American international airport?
- mywittyname 3y agoExactly, and you'll be on video. You can buy stamps from a vending machine with cash.
- pnpnp 3y agoIf, and that’s a big if, the victim was able to trace the infection back to a charging port, then have the time, resources, and capability to debug the chips. That’s all assuming the bad port wouldn’t have been removed, and video might just show regular “maintenance.” Yeah, it’s all above and beyond, but I think it’s in the realm of possibility for a high level target (see: stuxnet et al)
- thomastjeffery 3y agoI would imagine that leaving a charger plugged in to a public outlet is not as interesting as you have presented it to be. Sure, you would be leaving evidence, but if your plan works, that evidence won't be sought out anyway. If you sent a mysterious package, it wouldn't be strange or out-of-character for someone to investigate that package intentionally: which presents a significant attack surface for the discovery of your ruse.
- 3y ago
- rch 3y agoUSB charging ports on aircraft.
- bakugo 3y agoI'm inclined to agree, an exploit this powerful would almost definitely be used for targeted attacks only.
- ghostpepper 3y agoThis was the prevailing wisdom for many years but the recent watering-hole attack by China has made me reconsider this position. https://www.eff.org/deeplinks/2019/09/watering-holes-and-million-dollar-dissidents-changing-economics-digital https://www.eff.org/deeplinks/2019/09/watering-holes-and-mil...
- xeromal 3y agoIt's not really. Supposed a nefarious group wants to get ahold of an executives phone who always flies out of LAX or goes to a certain mall and uses a public charger. It would be smart to zero day one of those and if a few extra people are exploited, maybe some bonus bank info.
- bbarn 3y agoThis is typical hacker movie nonsense. In real life, if they want something from said executive they just kidnap him, threaten violence, and he gives them what they want instantly. Or just knock him out cold from behind, take his shit, and crack into it themselves.
- slig 3y agoAfter Stuxnet, I wouldn't discard that possibility.
- xeromal 3y agoExactly what I was thinking of when I wrote this. They left USBs on the ground hoping the right person would pick it up.
- yencabulator 3y agoIt's worth noting that Stuxnet was very careful not to even reveal its capabilities if it happened to infect a non-target host. It was still a very targeted attack, and not "everyone had their bank accounts hacked" risk. (It still infected untargeted PCs, and might have caused them to misbehave, but not intentionally. Stuxnet was designed for stealth, not for mass exploitation. You the average PC owner has very little to fear from such targeted attacks, you're not worth the 0days.)
- johncessna 3y agoI think it depends on what your goals are. If you want something that executive has and want to deal with the messiness of multiple other crimes, then sure, that'll work. If you're just passively collecting data and hoping to land 'a' executive or someone else in business with access to power and/or money, or can be used to pivot to someone else, I think it'd be an effective tool.