The $5 PoisonTap quickly, completely hijacks even a locked computer’s internet
techcrunch.com
techcrunch.com
Some suggestions:
* When the GUI is locked, activating new USB devices or even activating a connection via a cable to the ethernet port should be delayed until it is unlocked and (optionally) the user confirms that it's ok.
* New unknown network devices should require confirmation
* A network interface that announces a subnet larger than /24 or /16 (for IPv4) should require a confirmation by the user.
What scripts and hooks are being called whenever there is a change to USB and networking? That would be the place to start. Can there be a /etc/udev/rules.d/ rule that matches all devices?
> * New unknown network devices should require confirmation
These two are the most confusing behavior from current OSes for me - I understand why there is network activity happening while machines are locked for some processes, but I am not entirely sure I understand loading new hardware devices when in a locked state and/or without user interaction of some sort. This suggests an oversight in my mind, and my feeble mind can't think of good reasons why it is this way.
The same issue with new network interfaces - it seems like it's a very intentional action that should be done by the user and not something that should happen automatically, and especially not in a locked state.
Would the same behavior happen on a least privilege account or even a restricted privilege account like something with parental controls enabled? I know that software changes are controlled via this, but hardware changes being allowed seems unusual.
I think udev is a bit to low level for this. NetworkManager & co. would be the right place IMO. Maybe this could even be considered a security bug with them.
The whole "left behind USB stick" attack is already somewhat known and may catch attention.
None of these technologies are remotely new. This has been sitting under everyone's noses for a long, long time. I wonder how long this basic idea has existed in secret.
It's doubly surprising that the reporter doesn't recognize that USB is used for wired networking, since Macbook Airs always use USB for that!
If you connected this to a Qubes computer nothing would happen, except a popup behind the lock screen asking for permission. But you could also generally forbid USB network controllers, for example.
IPv6 is another story though, it seems like IPv6 RA (which can also contain DNS configuration) are accepted by default by all OSes. My observation so far suggested that these overrule DHCPv6 as well.
Also it will be not immediately obvious that your device got hacked while you left for a minute because it will not have been rebooted.
It sounds like this is the default response to any HTTP request, so I'm guessing these top million iframes are stored locally on the device. The TechCrunch photo shows a 32GB card - how many iframes could that store, alongside a tiny Linux-based OS?
And it's not that attacks can only happen while the PoisonTap is connected - it's that connecting the PoisonTap for just 60 seconds or so will likely have it install itself and respond to at least 1 request, seeding the laptop, desktop, or server with 1 million backdoor'd iframes, likely in some background AJAX process that you don't even know is happening in your browser, or when some process like Windows Update or Chrome or Firefox or Safari or Spotify or Skype or Hangouts or Dropbox tries to phone home. Or anywhere.
Then, once the PoisonTap is disconnected, those 1 million iframes are free to route through the same wifi or other connection the device used prior to the attack, to the general internet, for whatever secondary steps the attackers choose to perform.
What may be even more worrisome would be something like this, but with wifi capabilities. It could pose as a free wifi hotspot, possibly even bridging other free / easily hackable / commonly-known wifi hotspots - while replacing ad banners with the same malicious barrage. Or even filtering ads completely, for a "Knight in Shining Armor" solution.
Something like this: http://www.glennklockwood.com/sysadmin-howtos/rpi-wifi-islan...
There may be some caveats, such as an otherwise secure site using https, except for using regular-http redirects (which the PosionTap device could intercept) without using strict transport security with preloading.
Poisoning the DNS subsystem of your computer is not safe. At the very least it could record which requests you made indefinitely. This does need to be fixed.
I'm assuming that if a domain used DNSSEC this would protect the user against this type of attack?
There really is no substitute for end-to-end crypto in networking.
Here is a detailed post: https://blog.obdev.at/automatic-profile-switching/
It's often a valid strategy, but the PoisonTap covers different scenarios (and vice versa)