6 ms·
Dead Drops: what to do if you see a USB stick sticking out of a wall
- spiritplumber 12y agoLooks like a pretty good way to break the USB connector off. Wouldn't a short length of wire be better?
- Roritharr 12y agoIt seems you are already one step ahead of german law enforcement: http://www.express.de/image/view/2015/1/23/29952904,31875408,highRes,maxh,480,maxw,480,01K+22_71-80870384_ori.jpg http://www.express.de/image/view/2015/1/23/29952904,31875408... m( (From the german tabloid article: http://www.express.de/koeln/eingemauert-in-einer-fassade-bomben-bauplan-auf-oeffentlichem-usb-stick-in-der-koelner-suedstadt,2856,29952848.html http://www.express.de/koeln/eingemauert-in-einer-fassade-bom... )
- fennecfoxen 12y agoYeah, come on... one of these can be had from about $5 (and they're prime) http://www.amazon.com/s/?field-keywords=usb+extension+cable http://www.amazon.com/s/?field-keywords=usb+extension+cable
- freehunter 12y agoA more surreptitious spy would have a piece of hardware that can manipulate a USB drive without needing a full laptop. Any small USB host would do, from an old MP3 player to a Sony PSP.
- MaximillianII 12y agoTutorial? :)
- freehunter 12y agoWell you just need to find a piece of hardware that acts as a USB host. The Raspberry Pi mentioned above would work, but you'd need a keyboard/screen or scripts to do it automatically. With the right hardware (even a rooted Android phone), you would be able to see the USB drive as just more removable storage just like your PC would. Tutorial: 1) Have hardware that acts as a USB host 2) Work with the files just like you would on your PC 3) That's all there is to it
- xenophonf 12y agoStart here: http://youtu.be/D8Im0_KUEf8 http://youtu.be/D8Im0_KUEf8 See also: http://travisgoodspeed.blogspot.com/2012/07/emulating-usb-devices-with-python.html http://travisgoodspeed.blogspot.com/2012/07/emulating-usb-de... http://travisgoodspeed.blogspot.com/2012/10/emulating-usb-dfu-to-capture-firmware.html http://travisgoodspeed.blogspot.com/2012/10/emulating-usb-df... http://goodfet.sourceforge.net/hardware/facedancer21/ http://goodfet.sourceforge.net/hardware/facedancer21/
- tehmaco 12y agoSomething like the Raspberry Pi would probably work well. It's small, can be powered from a battery pack, you can add some scripts that automount the USB stick and copy everything off (and/or add some things of your own)
- ekianjo 12y agoAn OpenPandora would do even better and recognize sticks in ext formats on top of NTFS and FAT.
- 6d0debc071 12y agoIf we're talking about general tradecraft, in a how would you do it vein. I suspect a small internet-enabled device set to randomly transmit some time in the next few days or so, that sends OTP encrypted messages to as many people as it can, including the destination, and that self-destructs... releases acid or whatever into the chips... once it's done or if it's tampered with, would be hard to trace back the sender. Throw it in a bin along with your morning coffee in a place thousands of people go a day - it'll get mixed in with all the other trash in a landfill somewhere and then good luck finding whose trash it went there with....
- ufmace 12y agoAs far as small USB hosts, an Android phone with a USB OTG cable would be a pretty nice way to connect to something like this and copy files back and forth. I don't think they're very vulnerable to most of the usual potential nastiness of a malicious USB device. But no matter what sort of device you're using, it's pretty far from anything an actual spy might use. Any actual spy would want something discrete enough that you could be watched, videotaped, and photographed from multiple angles while making or picking up the drop, and even with endless analysis of the recordings, still have the security service not know that anything happened. Some of Tom Clancy's books are pretty decent on realistic spy tradecraft, even if they're dicey on other subjects.
- speakeron 12y agoNot a good idea. This risks getting owned from the BadUSB exploit.
- upofadown 12y agoSince the BadUSB exploit is a MITM for data going through the USB interface, it's existence doesn't increase the risk. All the executable files could just be infected to start with. It's pretty much the worst idea to execute random files you find in the street anyway so the risk probably isn't that high in the first place.
- yk 12y agoIs BadUSB possible with any USB stick? ( Or is this only a risk if a modified USB stick was installed in the first place?)
- tach4n 12y agoIn the article it's said that's explicitly part of the idea - it's supposed to be dangerous.
- onion2k 12y agoIt's supposed to appear dangerous. The first time anything actually dangerous happened the user would immediately stop using them. Or worse, they'll end up in prison. Copying a random zip file of the Anarchist's Cookbook on to your PC will get you a few hours of questioning by the police and a caution not to be so stupid as to be a pretend spy again; why you downloaded an archive of several thousand child porn pictures is quite a bit harder to explain away as a bit of fun.
- nodata 12y agoOr you might fry your laptop.
- driverdan 12y agoIf I wanted to do something like this I'd create open WiFi access points called something like "DeadDrop". They wouldn't be connected to the internet. Instead they'd forward you to a locally hosted site that let you download and upload from local storage. WiFi has a lot of advantages. You eliminate the risk of USB attacks, physical damage to the device, and the actual location is unknown. The downside is that it would require power.
- admax88q 12y agoThe downside is that it has to be powered.
- p00b 12y agoRelevant: http://ldln.co/#howitworks http://ldln.co/#howitworks
- adventureloop 12y agoThe Pirate Box[1] firmware is the perfect thing for this. The problem is finding power to keep the box running, but with wifi, you can hide the box somewhere out of site. I have always thought it would be cool to set up a piratebox somewhere running from a solar panel. Then in daylight hours the dead drop would be there, but it would be gone at night. [1]: http://piratebox.cc/ http://piratebox.cc/
- adolph 12y agoI've often wondered about how much power it would take to run a wireless SD card (enough to be solar powered?) and how the software could be extended to allow uploads. http://www.monoprice.com/Product?c_id=117&cp_id=11709&cs_id=1170901&p_id=11444&seq=1&format=2 http://www.monoprice.com/Product?c_id=117&cp_id=11709&cs_id=... See previous commentary: https://news.ycombinator.com/item?id=6195627 https://news.ycombinator.com/item?id=6195627
- chewyfruitloop 12y agoi'm pretty sure this is an old concept from the early usb storage days... (found this on archive.org from 2010 https://archive.org/details/Net_At_Night_175 https://archive.org/details/Net_At_Night_175 ) wonder why its becoming a "thing" again
- jacobwcarlson 12y agoThe article explicitly states that this project started in 2010.
- chewyfruitloop 12y agofair cop....still wonder why its come back up again after so long
- haiman 12y ago。。。
- haiman 12y ago这样做好吗。。。太明显了吧??
- ende 12y agoSo its a USB glory hole?
- will_brown 12y agoThe article mentions USB attacks/exploits...but even more dangerous would be child pornography,at least in the US such a crime does not require intent (as automatic as it gets in a criminal context) simply being in possession or even constructive possession would lead to a conviction and a lifetime registration on the sexual offender list.
- speakeron 12y ago>The article mentions USB attacks/exploits I'm not sure that it does. The countermeasures mentioned are for protecting against good old file-based executable exploits. I don't think they even understand the concept of firmware exploits.
- freehunter 12y agoThis is a meta comment, but does it seem like this post is attracting a more-than-usual amount of new posters? Maybe the site in general is getting more popular, I don't know, but on ~30 comments, there are four useless comments from green accounts, and the submitter is a green account. Just seems to be more than average.
- cgtyoder 12y agotl;dr: Admire the ingenuity of it all for 10 sec; move along.
- sigzero 12y agoI'd take it. Free USB stick! /s
- dr4g0n 12y ago> If you spot a USB flash drive cemented into a wall or kerb, you may have stumbled across a Dead Drop, part of a global art project borrowing tricks from the world of espionage Or, you might have stumbled across 240VAC wired to a USB connector.
- pavel_lishin 12y agoI wonder if that would be worse than carefully crafted malware.
- vanderZwan 12y agoSince sharing USB flash drives is pretty much the equivalent of having digital unprotected sex anyway, I'm sure you'll get that soon enough. And it can get much, much worse than plain old viruses too: https://www.youtube.com/watch?v=nuruzFqMgIw https://www.youtube.com/watch?v=nuruzFqMgIw
- hamitron 12y agoI was really into this about a year ago, so I placed one in a brick wall near my apartment. The device probably made it three days before being completely covered in rust.
- naoru 12y agoOr you can raise suspicion, get caught on surveillance camera and have a talk with a police officer. Yeah, there might be ways to avoid that, but in case of failed attempt there will be one more thing to explain.
- JoeAltmaier 12y agoe-geocaching
- polymathist 12y agoSo I found one of these in my city. The Dead Drops homepage has a list of all known locations: https://deaddrops.com/ https://deaddrops.com/. Took a while to find the exact spot, and when I plugged in... nothing. The drive was completely exposed to the elements without much protection, so it was rusty and as far as I could tell useless. I have a hunch that most of them suffered similar fates.