Because this makes USB an absolute NO in some environments (and for quite a while now).
It would be nice if we could use USB again at some point…
Because this makes USB an absolute NO in some environments (and for quite a while now).
It would be nice if we could use USB again at some point…
No, it will not be fixed. There is no vulnerability. We need to plug in keyboards, and if users are willing to plug random devices into the ports where their keyboards lie, those peripherals can inject keystrokes.
We can play whack-a-mole and blacklist the vendor/product IDs (like systemd does), but if this were a real attack and not a stupid marketing stunt, the device would just present itself as some popular cheap keyboard and there'd be no way for the computer to tell it apart from one.
There are many other ways you could attack USB or other connectors if you get a user to plug your hardware in there, most are more involved than this one. The only solution is to educate people to not plug hardware they don't trust into their machines.
“We just need to educate users about passwords” “We just need to educate users about how to verify SSL certificates” “We just need to educate users about how to install only software from trusted publishers” etc.
This reaction is understandable but it's a non-starter if we ever want to make meaningful progress on security. The underlying problem here is that everything local was assumed to be trustworthy and that's not true and, thanks to reflashable firmware, not even something which can be assumed to stay true even if it happens to be the case when you start.
Fixing problems like this will require changes – X-Istence mentioned OS prompting for new device classes, which would particularly effective on devices like laptops (i.e. the default for most users) which could require confirmation on the built-in hardware any time an external device tries to duplicate built-in functionality (keyboard, mouse, network, etc.), but we probably need more ambitious measures like adding a public-key exchange for certain device classes or a hardware switch which controls whether a port is allowed to control the computer or provide block storage but not both.
The one thing which is certain is that the .gov / .mil security people who seal ports with epoxy aren't looking as paranoid these days…
Hobbyists would have to run their system in an insecure mode, though and it's a whole new story if a certificate-based system would actually work in a market as volatile as USB peripherals.
So, I don't think there's one magic bullet but it's far too silent on that front!
A reasonable criticism is that this would likely result in several examples of customers being screwed when SmallCorp Inc. loses control of their signing key, it's used to sign malware, and the revocation takes out all of the legitimate users but that's arguably an unavoidable cost of the industry maturing.
You likely also would need a way to update the key or flash new firmware and, possibly, a way for the updater to detect whether the device it is talking to has been tampered with. That's expensive for low-margin products such as USB sticks and mice.
Also, the average user would not know how to update the firmware, and even if he knew, might not be able to because his keyboard and mouse are fried.
A lot of people seem to think that this was a device with hacked or other illegitimate firmware. It was not. It was a device called a WebKey, which is available from a number of vendors and is intended to do exactly what the author is describing.
Is it a dumb product? Yes. But this is not any kind of firmware exploit. It's just a keyboard that doesn't look like a keyboard, some as a YubiKey or one of several other sorts of non-keyboard devices that present as keyboards.
Signatures become relevant due to what will inevitably happen if those safeguards become common: right now someone is selling devices like this to marketing people. If Windows 11 breaks that with a permission check, the companies have the choice of either dropping that product or changing it to pretend to be a Microsoft USB keyboard on the whitelist. If it's some fly-by-night marketing services company in China, there's limited recurse to go after them unless you have a lever such as being able to revoke signing keys.
Basically a patch was offered that would lock a computer if a new device was plugged in. This to counter act police mouse wigglers etc.
But Poettering decided that no that was too heavy handed, lets instead black list the specific product id. Never mind that changing a product id is a firmware flash away (one could probably make a wiggler that randomize its id on each insertion).
What if the battery dies in my wireless keyboard, and I need to plug in another one temporarily? How could I possibly type in the password at a lock screen with one dead keyboard and all new keyboards forbidden?
I'm being cheeky but any good lock screen should have an onscreen keyboard button.
And it should only need to do it the first time you plug it in.
Solution to what problem? If the problem is "people keep getting hacked by plugging things into USB ports" then there are lots of other solutions. Filling in the USB ports with glue works well.
If the problem is "we need a way to plug in hardware easily without introducing security vulnerabilities" then educating people doesn't help at all.
Uh, even a prompt like "A new keyboard was added, do you wish to use it?" would work (after the system is up and there is already an input device). Yes you can come up with edge cases, but it should be easy enough to detect the difference between someone trying to get a keyboard working versus someone going about their day and a new USB device showing up as a keyboard.
----
USB device: hi computer i'm a new usb device, i can provide keystroke input
computer: that's a little weird, I already have a keyboard. hey user, do you really want two keyboards at once?
user: wtf no
computer: cool. sorry, usb device. no keystrokes from you.
----
USB device: hi computer I'm a new usb device, I can do keyboard input and provide mass storage
computer: that's a weird combination there buddy. hey user, does this sound cool?
user: weeeird, hmm, yeah how about mass storage so I can see what's on this thing, but no keyboard input.
computer: a pox upon your possibly-suspicious data, my hot-pluggable friend! but tell me about your filesystem.
USB device: hey here are some keystroke events anyway
computer: I'm not listeniiiiiing plus I just told on you to the user
USB device: curses, foiled again
----
USB device: hi computer I'm a new usb device, I can do keyboard input and provide mass storage
computer: that's a weird combination there buddy. plus i already have a keyboard plugged in. oh wait the user said you were okay and told me to never ask again.
USB device: cool
----
USB device: hi computer I'm a new usb device, I can do @$T%^&#R&ssnhf^23&298>>>
computer: that's a nice buffer overflow you have there, darling. take me, I'm yours!
USB device: p0n'd. here's a payload!
user: huh, that usb key I found in the parking lot of the nuclear plant doesn't work. Oh well. throws it away
payload: all yr base belong to us
----
Obviously "not plugging untrusted hardware into their machine" is still useful. And users often just say 'okay' to everything anyway. But "a weird thing is happening, are you cool with this?" would be a nice line of defense.
What we need is for the OS to ask the user what to do if an existing keyboard/mouse already exists, with a way to whitelist the new device so that we don't have to repeat the same steps each and every time we reboot our computers, or unplug/replug the device.
This way it will stop these sorts of attacks.
With a bit of refinement it could contribute to the overall solution.
The responses here are also interesting: https://news.ycombinator.com/item?id=10203913