5 ms·
“These problems can’t be patched,” says Nohl, who will join Lell in presenting the research at the Black Hat security conference in Las Vegas. “We’re exploiting
by jwcacces 12y ago
“These problems can’t be patched,” says Nohl, who will join Lell in presenting the research at the Black Hat security conference in Las Vegas. “We’re exploiting the very way that USB is designed.”
‘In this new way of thinking, you have to consider a USB infected and throw it away as soon as it touches a non-trusted computer.’
So now we need a USB abstinence campaign?
When you have a USB with someone, you are having a USB with everyone they had a USB with for the last ten years, and everyone they and their partners have had a USB with for the last ten years.
Also, we're just calling it a USB now? Not a USB thumbdrive, USB hard drive, or whatever? This article sounds like it was written by my mom.
- bitJericho 12y agoIt most surely can be patched. Allow a USB device to offer up a signature that the PC can verify. The CA would be the manufacturer which has a private key for each USB key manufactured (so hackers can't steal one private key and copy it). Make sure the manufacturer revokes keys that are compromised. Bam, instant manufacturer guarantee that the hardware is genuine. That is, until the private key is uncovered by the hackers, but that's what expiration dates are for I suppose.
- matthewmacleod 12y agoThat will work in the same way that DVD copy protection worked - briefly and ineffectively.
- bitJericho 12y agoIt's not a good DRM protection. It is a reasonable way to verify hardware for a user though.
- sp332 12y agoHow would the manufacturer know that an individual thumb drive has been compromised?
- bitJericho 12y agoThe user would need to receive the equipment in some secure fashion. Direct from the manufacturer in tamper-proof packaging or something. And from there it's up to the user of the key to ensure it is not physically compromised.
- maxerickson 12y agoHow do you ensure that a malicious firmware is not just impersonating the valid firmware for the device?
- nsajko 12y agoWith a signature
- mjg59 12y agoWhat prevents the firmware replaying a transaction with a valid signature? You're relying on the device to give you a true copy of the firmware it's running, but that means trusting something that's not trustworthy.
- bitJericho 12y agoOne could use some sort of RSA secure token technology that would be very hard to replicate the state of at the time of the attack. I guess my point is that there's loads of ways USB could be used in a secure fashion. To say it can't be "patched" is completely unfounded in reality.
- admax88q 12y agoThe firmware on a USB stick should not be writeable. When will you ever update the firmware on your storage device. Never, USB sticks are cheap and disposable. Mass produced ones should have their firmware burned into ROM.
- taeric 12y agoThis does nothing to protect you. Malicious users will just make their own usb stick. The parts aren't exactly expensive.
- MereInterest 12y agoOf course it does something to protect me. It means that I can plug my USB drive into a friend's computer, then plug it back into my own computer without worry.
- taeric 12y agoOnly if you fully trust the entire supply chain down to you. Do you have any way to verify that the mass storage device you bought was not a forgery?
- MereInterest 12y agoI'm not aiming for perfection, just aiming to improve. It is easier for me to trust that the sealed USB drive I bought has not been tampered with than it is for me to trust that all of my friends are knowledgeable and avoid malware.
- mikemoka 12y agoyes I agree that this looks like a good step, vendors should also probably release some tools to verify the integrity of their firmwares if possible.
- InclinedPlane 12y ago
- deleted 12y ago[deleted]
- DanBC 12y ago> So now we need a USB abstinence campaign? What's your risk assessment? Some places already have a USB abstinence campaign - they remove the ports and do as much as they can to remove the functionality from their OS. Or they remove as many ports as they can and lock other cables in place.