Elsevier knows this is an attack. They published a book titled "Seven Deadliest USB Attacks", by Brian Anderson. So they can't claim this wasn't done knowingly.
Has anybody found out what the attack does?
[1] http://www.elsevier.com/books/seven-deadliest-usb-attacks/an...
If the user's expectation when handed a thumb drive looking USB device from a big company is that it will display files, and instead it just pretends to be him and controls his computer interface, for me it is at least a gray area regarding computer abuse. But I am not a lawyer.
Say you'd post a persistent XSS to a forum, but only use it include Fartscroll.js, is that an attack or not? Cause I consider that to be pretty much the same category as the "surprise" automatic typing USB thing.
This weekend actually I used a USB device where this was in fact the intended behaviour: a barcode scanner. It registers as a keyboard and just types the numbers (or string) of whatever it scans. Very clever idea because it makes it very easy to write apps for, you don't need a driver or anything. Except I had momentarily forgotten that was how it works, so it surprised me anyway. Fortunately the numbers didn't do much in the program I had focused but still, that feeling of something else unexpectedly typing on my computer! Yeah if it had sent global keyboard shortcuts in order to make my computer start applications and load webpages, I'd be pretty pissed.
What exactly makes this an attack? I don't see it doing anything malicious. And in any case, how is plugging in a keyboard to your computer not authorizing it to send keypresses?
It appears to be a keyboard emulator that simply types winkey+R http://[some URL]
It's (sadly) a well-known fact that all unknown USB devices should be considered malicious unless proven otherwise. This is why there are so many things like http://www.umbrellausb.com/