PoisonTap, a $5 tool that invades password-protected computers
arstechnica.com
arstechnica.com
USB devices should not accept any incoming connection when the computer is locked. The only use of USB ports when a computer is locked should be for charging devices (current out, no data in). We also need to ensure that devices that were connected before the computer was locked continue to function.
Now obviously, the issue with this would be about external devices that are connected after the device has been locked (drives, keyboards etc. - say for example, keyboard stopped working so you switched it out) but in my opinion, that's an edge case and should not cause too much inconvenience.
Good idea, but...
(hypothetical helpdesk ticket) Oh crap! I knocked my coffee on my keyboard and ruined it as I was sitting down at my locked computer. I connected another keyboard, but the lock screen is not accepting my password!
Allow HID class devices to be connected when locked, and that should be OK.
Scan your badge to helpdesk or contact local IT to do it for you. Proof of identity is required.
Social networking is another thing itself which should be guarded against in any environment, simply suggesting all you have to do is make a helpdesk ticket requires your access already be breached to be done electronically or poor protocols in IT.
If you have your clients locked up like Fort Knox and working in that environment makes your developers feel like they're in hell that is going to be used as a data point when you are compared and contrasted to the competition's work environment. People tell their friends from their other gigs when they find something better.
Also worth emphasizing that smart local IT people aren't universal or consistent. It's a mixed bag. Even when they are smart they are incentivized to do one thing: solve your problem as quickly as possible. Upon discovering that your friendly local IT person is meeting their SLA by cutting security corners the immediate response is to add more processes and controls with little thought to the environment that created those perverse incentives in the first place. People care about what you pressure them to care about and the pressure they get every day is their SLA/count/turnaround because there's no dashboard for how securely they do their job.
It's things like unbounded security controls, business processes and rubber-stamp approvals that take a company from a creative place to work full of smart people getting stuff done to corporate hell. It never happens overnight because it's a slow death by a thousand cuts and you realize you've finally arrived in the pit because the execs are running internal hackathons to boost innovation and creativity where the participants can't install anything on their computers or get some throwaway VMs without 9 approvals and a business justification. The things that steal our momentum and sap our creativity should have a corresponding immune system that is always trying to remove them by enforcing a justification for them, reassessing the risk, the value and whether or not they're even needed.
I got off on a bit of a rant there, sorry.
Sammy had an older video [0] which showed a device that was not a keyboard acting like a keyboard & mouse. While that required an unlocked computer to function, I feel like adding exceptions to a rule would just make it worse.
Another solution would be to sign USB devices (for example, Apple keyboards etc.) and only those signed devices would work when the computer was locked.
Are you proposing DRM for input devices? How would this fix the problem of "Oops, messed up my keyboard, now I have to plug in a new, 'unknown' device"
I really dislike this trend of making the link text have little to nothing to do with where the link goes.
Edit: for research, I don't plan on using this against someone.
But he has a history of intentionally withholding instructions on how to run it just to avoid script kiddies from using this not for research.
Interesting approach. Although looking at the Github it seems pretty straight forward (not being a script kiddie I can't speak for if it would be straight forward to them).
At the minimum, the host(victim) is establishing a websocket with Samy, so his server is aware who is being compromised or researched on.
That's quite a severe sentencing for a "Guestbook Signing" XSS exploit. I wonder if the sentence was reduced.
I'd notice a new usb plugged in, but I wouldn't easily notice this.
This is the reason why keyboard/mouse connectors should look different to USB connectors, so we can tell the difference.
Say you go in for a job interview at a company and the interviewer leaves for a minute with their computer locked but still on their desk. Most traditional methods would require you to move to the other side of the desk or pull the computer to you which is risky, but with this you can just reach over for a few seconds.
Not to mention many traditional attacks require rebooting the computer to a bootable CD which will be suspicious if the user has an active login system and all the sudden all their apps are closed.
Or say you are at a doctor's office and there is no CD drive and rebooting the computer would be suspicious. I'm left unattended in exam rooms with computers all the time.
I also imagine it could be fairly easily modified to act like a USB hub and be inserted between the computer and a legitimate device.
Edit: Think of how less dramatic the scenes will be in Mr. Robot and the like if the "hacker" doesn't have to rush to get back to their seat just in-time for the target to get back to their desk.
This is such a defeatist attitude, and it has also proven to be (mostly) false by Apple and its iPhones. If we stopped saying that every time there is a hack like this, perhaps companies would actually give a damn to make sure it doesn't happen anymore, or not nearly as easily.
It's one thing to pay from tens of thousands of dollars to a million for modification of a chip in a factory or with highly-advanced equipment, and it's quite another to just insert a USB stick into a random PC and hack it.
Has it?
https://www.washingtonpost.com/world/national-security/fbi-p...
No, just no. It's long, LONG past time to retire this bit of ancient lore, which came out of a completely different time and place in computing. These days for most users not always having physical control is by far the norm, not the exception. And there are absolutely ways to make to mitigate security issues from physical access, that is after all the entire point of technologies like full disk encryption. FDE is completely pointless if physical security can be taken for granted, it exists entirely because physical security cannot be taken for granted. I presume you don't spend your days advocating nobody bother "because it's pointless anyway."
Technologies like specific CPU/SoC/chipset level hardware security zones, HSMs, use of IOMMUs and the like to prevent DMA from ports, etc. are all there in part to help prevent or mitigate certain physical attacks. For that matter, simple locks and/or sealing of computer units aids with both making attacks more difficult, slower (another key part of threat mitigation) and, just as importantly, making them noticeable. The final fallback of a good security system is to at least try to let the owner know that it broke if all else fails. There is a certain amount of disgruntlement amongst some tech people at highly sealed devices, but they do make it significantly more challenging to perform certain physical attacks quickly or undetectably.
So yes, anything which unexpected speeds up physical attacks, renders them less/unnoticeable, or both, is a legitimate issue. Normal users of portable systems should be able to expect that, under normal circumstances, they can warm lock it (screen lock, put it to sleep), leave for a few minutes, and have a low likelihood of a low energy persistent evil maid attack being pulled off in the mean time. Treating modern security like it only needs to consider servers stashed in a secured room/data center is wrong.
> The primary motivation is to demonstrate that even on a
> password-protected computer running off of a WPA2 Wi-Fi,
> your system and network can still be attacked quickly
> and easily.
Oh no! > [... with physical access.]
Oh. Has this ever been disputed?However, something like this would make insider threats a bit more dangerous. Leaving your laptop at your desk when you go to a meeting or to the bathroom is perfectly normal, and if a coworker can sneak in and break into your machine while you're not looking, that's a game changer.
I like the attack for how it combines different methods. I just had a hard time understanding the risk from that article.
def1 -- Use this flag to override the default gateway by using 0.0.0.0/1 and 128.0.0.0/1 rather than 0.0.0.0/0. This has the benefit of overriding but not wiping out the original default gateway.
This works because routing tables prioritize "tighter" routes. I do think that 128.0.0.0/1 would only map to 1/2 of the address space. I cannot find the isc-dhcp server config files in the source code to verify. :disappointed: