It's like the constant battle with our IT department to get and keep admin privileges on our machines. Yes, this can cause a problem but we need admin rights to do our job.
If you are not absolutely sure it's OK, then it's not. Pack your own chargers, use a "USB condom" or a power-only cable. If the charger has a cable that can't be removed, use it to charge a trusted battery, then charge your phone from it. Don't trust any smart battery, BTW.
Journalist covering summits like this are not regular guys and should receive opsec training before any such assignment.
When working on the Brazilian electronic ballot, I had two computers: one that was connected to the corporate network where I could read and write e-mails, and another I could manage (so I could run Visual Studio's debugger), that was on a completely different network, in front and behind some of the most aggressive firewalls I've ever seen.
More info: http://www.usb.org/developers/powerdelivery/
Right now, USB-C is only just starting to get past the “which cables will physically harm my device with a given charger even though they plug in correctly” phase.
I use a "USB Condom". My current USB Condom is this one:
https://www.amazon.com/PortaPow-Data-Blocker-Adaptor-SmartCh...
In fact, I sometimes even use it with my own, trusted, devices. For instance, I don't want my macbook itunes to know about my iphone so when I charge from my own laptop, I use the "condom".
I'm sure these exist for USB-C...
Of course this would require cryptography to do properly so it'll never, ever happen.
Either that or a tiny switch beside each port to enable/disable the neutering feature.
Why would anyone assume otherwise?
After all, when was the last time your power drill caught a virus from your extension cord?
I worked in various security positions at one of the US's biggest ISPs and routinely brought these sorts of things up to family members. I am embarrassed by the kinds of practices my family employs. The excuses vary but most of them fall along the lines of the same excuses smokers give when asked about lung cancer risks: "It Won't Happen to Me(tm)".
Even within our industry, bad practices exist all over the place. An example I often point to is Code Signing certificates[2] -- I went through the trouble of generating a CSR offline using a Linux live CD, backed up the private key to an encrypted thumb drive and placed the result on a Yubikey to protect it when I need to sign something. The best part was sorting out how to actually give the CSR to the CA I used to purchase the key from. They offer all kinds of convenient, (IE and Firefox-only) in-browser mechanisms which result in generating the key online in a potentially already-compromised machine, but I ended up having to go through several steps using phone support to get my CSR to the CA. The way they did things encourages people to not think about protecting the private key; simply leaving it on an unencrypted volume with (likely) no other encryption used to protect the key.
[0] https://thenextweb.com/insider/2011/06/28/us-govt-plant-usb-... And these are specifically the kinds of people that should expect to be targets of an attack like this.
[1] https://digitalguardian.com/blog/uncovering-password-habits-...
[2] I mention this kind of certificate because its credentials are such that an individual or company is named -- it's meant to identify a person or a legal entity, not a domain name -- and things signed with it result in that legal entity or person's legal name being displayed on launch in operating systems like Windows. It's something that you really wouldn't want to have fall into the wrong hands lest your name end up being prominently displayed prior to the installation of malware.