USB Type-C to Become More Secure with Authentication Standard
eweek.com
eweek.com
The "authentication" that would actually help is to default to only allowing charging through ports (and allow charging without authentication - who cares where I get 65 W of power from? are there malicious electrons?), and show a little "new device" authentication screen with a Bluetooth-style pairing process when I connect something new. Then either burn an asymmetric key onto the device or generate a random symmetric key (and leave the CAs out of it), and on the host, bind the key to the current function of the device, as displayed on the pairing screen. If I clicked "Trust this keyboard," don't let it turn into a CD drive. If I clicked "Trust these headphones," don't let it turn into a keyboard. And so forth.
https://www.amazon.com/gp/product/B01NAWYSVK
UPDATE: actually, no, the displays is upside down on one of my devices! Duh! A cheap gyroscope would help, or another OLED screen on the back but in the opposite direction (as USBC-cables are reversible)
wait I don't get it. It's USB-C, just flip it over?
It is a simple USB-C design oversight from Pluggable that a simple gyroscope or extra screen would have fixed easily.
This one is going back to Amazon.
I figure the authentication will happen largely in the host software as well, so if you're running a real operating system you'll be able to install your own keys.
(Besides, how do you see this working? Are you manufacturing your own USB devices?)
I do (depending on your definition of "manufacturing". I buy USB controller chips to add to my projects), although not USB C.
Now that you bring it up, I do wonder if this authentication scheme will mean that hobbyists won't be able to use it.
The real problem on public outlets is with data attacks, not power. If I can set my phone to ignore all the data at the first hardware level, and it is a simple enough level that no attack is viable (that second one being a large "if"), then there is no large problem anymore.
I also don't believe any OSes offer a mode where they negotiate power delivery and not data, though I'd love to be wrong - that would be 90% of my proposal. It wouldn't let you authenticate individual devices, but it would let you go back to having a single port that's just a charging port.
It depends on which "USB protocol" you're talking about. With USB-C, there are five separate data buses on the plug, each running its own protocol. There is the traditional USB 2.0 bus (half-duplex differential pair), a pair of differential dual simplex buses (normally USB 3.0/3.1/3.2, can also be used for alternate protocols like DisplayPort), a pair of sideband wires (used only by alternate protocols), and the Configuration Channel. All configuration of the other data buses and of the main power bus is done through the Configuration Channel, in simple cases through resistor values, in more complex cases through the USB-PD protocol.
So yeah, you have to speak the "USB protocol" to switch to more than 5V or more than 3A, but the "USB protocol" you have to speak is not the traditional USB 2.0 or USB 3.x protocol, but instead the completely separate USB-PD protocol, which runs on its own dedicated set of wires. I doubt you can show up as a pen drive full of malware through the USB-PD protocol, but I don't doubt that cutting the other buses (keeping only the Configuration Channel/VCONN and the main power bus) will still work to deliver power, even at higher voltages and/or currents.
The reason this isn't standardized (as far as I know, a "charging-only" plug is only allowed as a captive cable on a non-charger) is for compatibility: if your device doesn't understand USB-PD, it might not charge at a full speed unless it sees a short on the USB 2.0 bus (Battery Charging specification), and doing that short on an adapter would allow a device to draw too much power from a non-charger.
If you want to verify the safety of 18 V: ever touch both poles of a 9V battery with your fingers? You can't feel anything. Go ahead and try two in series, you still won't feel it.
As kids (6-9y) we used to test the voltages of 3R12 (4.5v) by touching the poles with tongue, a sharp bites - the battery was good.
(Even those from manufacturers that try to lock this down using an EEPROM, e.g. Dell, still output their voltage like the others, but the laptop might not want to charge from an "unofficial" power source.)
And if there's a 10kV differential between your left and your right hand, sustained for longer than an instant... You're probably dead. But I've touched a 10kV power supply (not on purpose, this one), and...still here.
So! What gives?
Well. Place a 0.1 ohm resistor across that power supply. 18V across 0.1 ohms will produce a current of 180A. This will dissipate more than 3kW in the resistor, and it will very rapidly disassemble itself. But that doesn't happen!
Okay, now put a 10 megaohm resistor across that power supply. It's 5A, right? So 5A across 1 megaohm will produce a voltage of 5000kV. This will dissipate 25 megawatts, and destroy the resistor even faster. This also doesn't happen!
In fact, what will happen in the first case is that 5A, not 180A flows (assuming the PSU doesn't detect the apparent short and shut down entirely.). But Ohm's law says that if 18V is placed across a 0.1 ohm resistor, 180A must flow!
Ah, but 18V isn't placed across the resistor. Instead, as current draw approaches the 5A limit, the power supply starts dropping the voltage. No more than 5A will flow, even if that means the voltage must be decreased.
And 5A won't flow through the 1 megaohm resistor, either. Instead, no more than 18V will be placed across the load, even if that means the current must decrease.
So, the power supply won't kill you UNLESS your skin resistance is low enough that 18V causes a lethal (very roughly roughly 1A) current to flow through you. Luckily, humans have a fairly high skin resistance, at least when we're dry, and 18V is fine.
It's not the volts that kill you, it's the amps which the volts are directly related to. 10kV across your body, sustained for a bit, will kill you dead, modulo some sort of miracle. 10kV at 1mA across your body ... is impossible. If you touch a 10kV, 1mA supply- the voltage will drop so that only 1mA flows.
It's not the voltage limit on the power supply that kills you. It's not the current limit on the power supply that kills you. Both need to be high enough to do you in.
I would like to peruse your electronic skills for another quite unrelated question that has been hovering my head for quite a while.
I know that normal USB (1,2) devices charge using the provided 5V rail off the USB connection. And I've read somewhere else that coming from a PC motherboard or other regulated (standardized) USB outlet, the port will provide about 500mA.
What would happen if i took a ATX PSU and rigged usb ports directly (at the correct power pins) to the psu's 5V rails?
Would I fry any devices plugged in? Or..
Would any plugged devices limit their intake and I'd be left with a 'super quick charger' which can charge any device at the maximum amount of power that the device can receive power? those 5V rails usually output at 30A+ and stuff.
thank you again, and hope you can shed some light into this long doubt of mine (I always 'dreamed' of creating some atx-frankstein psu which i could use for electronic experiments but also fit some usb ports in it).
o/
1. Assuming you hooked the 5V to the USB 5V and the GND to the USB GND pins, nothing bad would happen.
2. Nothing would get fried
3. Plugged in devices would respond according to how they're designed. Most cell phones will limit current and only draw 500mA if they don't have any other signalling to test otherwise. Some will slowly ramp current until their own internal limits if voltage drop isn't too bad. Some 'dumb' devices will pull as much current as they 'want' or need. You won't be able to push 30A into any device because there are almost no USB devices that 'want' that much current. Even really poor behaving devices (outside of outright broken ones) will probably only draw 3-5A max. Technically this is non-compliant, since there are defined USB specifications for how USB ports should be connected.
If you wanted to make a 5V 'mega USB' charger, here's all you'd need to do: Take your 5V, many amp power supply and connect all USB-A ports you want to it, with a constraint that number of USB ports should be total amperage divided by 2.5. E.g. if you had a 10A supply, only use 4 USB ports. Short the D+ and D- pins together on the connector. 5V should be connected to your large 5V rail, GND should be connected to ground.
That's it. You've just made a 'DCP' (Dedicated charging port) device. By USB standards any device connected can pull up to 1.5A; in practice they'll usually pull 2.1A or more if they can.
knowing shit about electronics, i was worried there would be 'too much current' and that i could fry something :-)
have a good one, man o/
If you lick them it'd be quite unpleasant but that's that.
Voltage below (roughly) 36 are safe.
This is much easier said than done (in the US at least.)
First, you'd be looking at at least a year of going back and forth in small claims court and by the end of it still have no guarantee of winning. Even if you did win, there's no guarantee the judge would award you the full amount to pay for your fried device.
It almost certainly would not pay your time at the courthouse though; you can ask the judge for punitive but you cannot include legal expenses in small claims court demands.
In the end you would still be out hundreds or thousands of dollars and numerous hours of your time. That's why to me the tiny benefit of using a public USB outlet is just not remotely worth the risk of such a nightmarish hassle.
Then again if things were really bad or malicious you could end up losing your life like Sheryl Aldeguer.
My old no-name Android phone (not USB C) has such an option, and searching around it seems to be a reasonably common feature, although not present on all devices. It looks similar to this (mine has the same typo, "USB fuctions"):
https://farm8.staticflickr.com/7485/16035739946_51d110ea40.j...
In charge-only mode it doesn't even enumerate as a USB device when plugged into a computer with an active USB controller, so I suspect no attacks (besides physical ones like overvolting as others here have mentioned) are possible in this mode --- the USB controller on the device is completely disabled.
If my Moto G5+ is locked then it seems that plugging in a keyboard behaves pretty much like plugging a keyboard into a desktop or laptop computer except that it doesn't respond to c-a-del.
I can unlock from the external keyboard by pressing the windows key and then typing my pin number but the multimedia keys and print screen on the keyboard work even with the screen locked.
I would rather that it didn't do any of that until I give permission on the mobile itself.
> My old no-name Android phone (not USB C) has such an option, and searching around it seems to be a reasonably common feature, although not present on all devices.
I use one of these. The nice thing about the newer versions is that you can verify the impossibility of a data connection through easy physical inspection.
https://www.amazon.com/PortaPow-3rd-Data-Blocker-Pack/dp/B00...
In particular, people seem to use untrusted AC power outlets all the time without their devices being fried. The motivations of an attacker who wants to fry devices (mere lulz) and the motivation of an attacker who wants to break into working devices silently are very different; it makes sense to expect more of the latter, and to define the latter and not the former as within your threat model.
That works well to solve all the issues with public power ports.
That is true, but not something that I'm overly fussed about. I'd much rather have my USB port fried than to suffer an intrusion.
This crypto-signature approach is already used by the Apple MFi program, which has made it difficult-to-impossible to sell counterfeit and/or unsafe Lightning devices.
You're worried, I think, about poor-quality devices that aren't malicious, just incompetent - or poor-quality cables. (I'm already willing to carry my own cable - I already carry a USB-A data blocker around, but USB-C data blockers don't seem to exist.) I think that can be solved without cryptographic authentication, with the standard approach of having a certification organization like UL or the USB-IF themselves investigate cable/charger production and test them. It seems the major problem here is with Amazon listing cables without showing whether they have certifications (or checking whether certifications are forged), and that's a general Amazon problem with poor-quality hardware and counterfeits.
This article is talking about autorun, Stuxnet, etc. so I think they're focusing on the latter. If the USB-IF wanted to use digital signatures to authenticate cables I'd be more on board, but if they do that, they should just be authenticating cables, not devices. (A cable, I believe, can be engineered to just cut the circuits if a device tries to pass too much voltage, or is wired backwards, or something.)
They do -- I carry one one of my employees made in our lab. Search for "usb-c condom" or "usb-c data blocker" and you will find several offered for sale.
Incompetence is scarier than malicious actors imo, and expecting users to carry USB condoms around seems like a bad idea.
Apparently not according to the Chinese, who made the first clone (based on an 8051 microcontroller IIRC) within months of the official release. They're still in an ongoing cat-and-mouse game with Apple.
By controlling issuance of permission to use the connector, Apple is able to prohibit non-compliant products from becoming widespread worldwide. (And even China just last month declared their intent to make IP enforcement viable, which further strengthens Apple’s position with respect to MFi.)
The USB folks appear to believe that if they introduce a similar licensing arrangement for USB, they’ll be able to refuse licenses to unsafe implementations to deny them access to the worldwide USB market. MFi still works today, so I certainly don’t blame them for trying.
No idea if that's what this system does, though. Ultimately it has to be the computer itself that knows to protect itself. If insecure USB-C also exists, having the possibility of security may not be good enough.
It’s one of those things that makes USB-C really dumb. Any negligent Chinese manufacturer can drop a cable on Amazon that is a hazard.
In solving all problems, USB-C is a problem.
I find a wonky cable a higher risk than shitty charging equipment, especially as it may work fine for low power needs.
It would still allow someone to bypass the authentication if they know the VID and PID of something already authorized with the desired HID class, but that seems reasonable and is significantly better than what we have today.
Are there any systems that work like this today, and if not, is there a reason?
[1] https://en.m.wikipedia.org/wiki/USB_human_interface_device_c...
One of the primary drivers for this is the power delivery - imagine a scenario where you have authentic power brick and laptop and buy a counterfeit USB-PD cable, power brick sends 100W over it and it results in the cable melting since it was really a $5 knock-off and you end up with a fried USB-C port in your laptop and possibly a fire. I'm sure most people would wish that the power-brick/laptop checked that cable is genuine and build to handle the power.
Why not implement something like detecting voltage drop between charger and device? Short circuit detection, etc. You can do a lot if you can have both sides communicate with each other, and at that point it matters a whole lot less if your cable lies to you plus you catch a lot of other failure conditions.
The OTG device is required to limit the current it draws from the ACA such that VBUS_OTG remains above Vaca_opr min.
Not a USB engineer, but a quick peek at the BC 1.2 spec suggests the ball would have to be dropped on at least two additional fronts for the suggested failure mode to occur:
1.) The Charging Port device vendor for failing to implement any of the allowed shutdown measures suggested in BC1.2 §4.1.4; and
2.) the Downstream Port device vendor for failing to constrain current draw based on sensed Vaca_opr min = 4.1V (Table V) per ibid. §§6.2.2 and 6.3.1.
I can see how the knock-off cable would be toast, and depending on insulation rating, may potentially catch fire, but struggle to see how either the CP or DP USB-C ports would fry (considering they're both designed for a target power).
Having a charging-only-by-default port would be a 90% solution, but would be very annoying for people who need to reauthorize a device every time they plug it in, which is why I think pairing is better. And I'm not sure what devices you can reasonably trust other than pure power. HID is definitely out for fear of Rubber Ducky-style attacks. External video adapters can read your screen. Headphones can listen in on calls. Thumbdrives / PTP devices might be safe if handled carefully but are kind of the classic worry, so I'm not sure if people will want those. Maybe pure U2F devices, webcams, and audio input devices? Not sure how useful or user-friendly such a restriction would be.
If it tries to present another HID later, that would result in a new prompt, the same as a brand new device. If it changes HID while plugged in, that could even be a more severe message along the lines of "Hey, this keyboard just tried to become a video adapter and thumb drive, that's really suspicious and you should probably destroy it with fire".
Likewise, VID/PID changing without being unplugged/replugged in, changing too quickly, or even just after too many new VID/PIDs in a short time period should result in a temporary lockdown -- in the same way fail2ban blocks repeated login attempts from a given IP.
Very. ASN.1 vulnerabilities have been exploited multiple times in the wild, in mainstream libraries (like OpenSSL). Now imagine every hardware vendor writes their own shitty implementation and ships it as a blob to phone manufacturers. And that's all without going into the full blown X.509 PKI part of the spec, which adds yet another layer of complexity - all under control of chargers you plug into. Now imagine this is implemented by the kind of companies who wish to perform DRM on what charger you are allowed to use.
This spec is a recipe for disaster and implementing it will seriously reduce the security of devices.
2) Historically you never wrote ad hoc parsers. ASN.1 describes a grammar to be consumed by a compiler generator. The X.509 specification and extensions are almost entirely ASN.1 grammars with interspersed commentary. You can feed those grammars directly into the generator, and IIRC I've seen builds where the grammars were extracted directly from the RFCs. OpenSSL and other open source projects suffered from parsing exploits because historically all ASN.1 compiler generators were closed source, commercial products.
I don't disagree that it will likely be ugly. Open source options for properly working with ASN.1 are still poor, and these days even commercial vendors principally rely on open source toolchains. I've used the amazing asn1c which can be fed the official X.509 grammar and spit out a clean, strongly-typed BER, DER, or PER parser. But I've never seen it used by other open source projects. IIRC the mailing-list is mostly chatter from telecommunications contractors.
Bad ASN.1 support doesn't need to be the case. Hand rolling DER parsers is a choice. If we can write good generators for gRPC, we can write them for ASN.1. And from the perspective of C and C++ asn1c largely suffices.[1]
[1] My biggest grip with asn1c is that, IIRC, it still requires dynamic memory for grammars like X.509 with variably sized arrays and strings. It would be nice to see a compiler that supports generating statically sized fields and which simply errors out if an object doesn't fit within the field. Then you could use asn1c for really low-level, embedded firmware, and more importantly could greatly simplify application code traversing the data structures. ASN.1 supports specifying maximum sizes which could be used to size fields (and maybe are in asn1c) but that's a separate thing, and in any event X.509 doesn't make use of this (though I suppose it would be easy to amend the specification, formally or informally.)
That 65W of power on USB-C is coming in at 20V most likely. Many devices simply will not tolerate that high of a voltage. This is why authentication and negotiation are absolutely essential.
You can fry a regular AC-powered device by giving it 240 V power instead of 120 V, or 50 Hz instead of 60 Hz, or whatever. But we don't need authentication of power outlets. What makes USB different?
This authentication is supposed to prove that the cables claims have been tested.
It will undoubtedly help safety and compatibility, at the cost of an open ecosystem and pushing prices up.
But I like your suggestions for pairing.
USB-C inconsistency on the hardware side of things has been a meme by itself. With this addition sometimes when you plug a device in it might not work despite being the exact right device/port combination (which would be a miracle on it's own even in the current environment.)
I don't know. Maybe in 5 years when we've glued on all the stuff we want from this connector things will be okay. In the meantime though it's chaos. Committee approved chaos.
I connect my desktop to different phones via USB-C, my phone to my headphones, laptop to monitor, my headphones using my car charger, etc. and it all works. The charging bricks and cables are cheap on sale -- $30 for bricks that can charge laptops and about $4 a cable. We're a 100% USB-C household and will only buy electronics with USB-C or USB. I'm waiting for everything else to go USB-C: come on projectors, razors, speakers, and musical instruments.
Source: USB-C household with a 9 year old and a new switch.
Was it a cheap USB A -> USB C Cable without a resistor? Those a well known to be dangerous [1]
[1] https://www.howtogeek.com/353410/3-problems-with-usb-c-you-n...
The only unofficial thing I used was the cable itself. Once I bought their cable, the switch charges on everything I connect it to now.
Not quite the same issue as burning up my switch (as of now), but issues nonetheless.
I'd send you the correspondence between Nintendo and myself but I feel as if I've wasted enough time on you already.
[0]: https://www.reddit.com/r/NintendoSwitch/comments/87vmud/the_...
I suppose my biggest gripe is that things that aren't USB are able to use the USB-C form factor. For instance thunderbolt. My dock at work connects with thunderbolt over USB-C, and everything works fine minus the display port pass through. It's kinda cool that it works at all to be honest. Oddly enough the Ethernet jack and Dock sound card are run over USB so those work fine.
To be fair, OSX warned me something was drawing too much voltage, and I still tried it like 5 times after that, but the screen did flicker on a few times and work for a sec before it all went kaput.
USB-C enthusiasts are (from my experience) people who haven't really used it much and think that they will be able to get around with a single cable and a single connector standard.
People who actually tried to use it for a number of things quickly realize that USB-C is just the name of the physical connector, which has nothing to do with what the device supports, which in turn has nothing to do with what the (unlabeled!) cable supports. There are no standards for labeling devices or cables, so you quickly end up in a world where you have a bunch of cables and devices all using a single plug, but you have no idea which device will work with what. I daresay this is a worse situation than having multiple types of plugs and cables, because at least then you could set reasonable expectations.
Add to this the fact that there are no reliable hubs for USB-C connectors, so you're basically stuck with what your laptop/computer offers, unless you want to live in a world of crappy unreliable hardware (I don't).
Text labeling could work, but could get out of control, especially at the rate that the standard is changing. Would it need to list the specific features the cable supports? Or can I assume that a cable labeled with 'Thunderbolt' will be compatible with all future iterations of Thunderbolt?
Maybe we can do something like resistor color codes with colored bands to make a rainbowed venn diagram of cable features. Surely that's a good idea which will only decrease complexity :P
Well, it's clearly less complex than letting the cables unlabeled...
Not everyone! Personally, I couldn't care less what color my cables are (unless the color is telling me something important about the cable).
Well, I'm using it for my monitors, soundcard, power, iPhone/iPad charging, Sony headphones, and external hard disks.
What exactly am I missing from the whole issue, since I don't seem to be having any problems?
Can it be fixed by not buying crappy cables?
Dude, you're using a pair of headphones that cost more than most people's cellphones and laptops. Normals use years-old Android devices, out-of-date Windows 7 laptops and the absolute cheapest peripherals from the drug store.
Of course that stuff is going to be buggy.
Even the Nintendo Switch, due to its hardware, uses the highly unusual "myDP" USB-C display standard instead of conventional alternate mode.
Unfortunately that isn't enough yet, as there is no "universal" cable, and may never be. You can have an excellent cable that nonetheless fails for what you plugged it into, or (potentially worse) falls back to something that kind of works (e.g. a slow data transfer through a port that supports PCI-e).
The biggest botch the committee made was not mandating connector labeling. I'd have gone with colors, but not everyone can see them. If the cable had resistor-style stripes to indicate what it supported, and if the ports on the host devices did likewise we'd be in much better shape. Even some licensed logos would have helped though the connectors are so tiny.
Then again the names the USB committee has come up with in the past (high speed, SuperSpeed, 3.0, 3.1 etc) have uniformly been confusing rather than elucidating.
In my case I agree: I have had nothing but success with Type C, and it has simplified my life (except for the lack of high power chargers). But I had to learn more than most people would or should have to in order to get there.
What is missing that they aren't universal? Is there some kind of tradeoff between full power load and full data transmission capacity or something?
Things like charging your phone can be done with USB C.
Things like external hard drive are generally done with Thunderbolt
Things like External GPU's have to be done with a Thunderbolt cable that is less than 1m
All of that said, I am not 100% sure of all of that, because it is all so confusing.
If you ignore Thunderbolt, can you always rely on the latest USB-C cables Apple and Google sell working for everything? Or are there still issues?
Dating back to the early days of Apple, they have been hyper conformant with the spec (e.g. no drivers needed to connect to conforming devices). They still are.
I answered your question about which cables above.
This affects everyone.
[0] https://en.wikipedia.org/wiki/Thunderbolt_(interface)#Thunde...
Why? External USB drives are much more common.
TL;DR: USB drives are really really slow.
625 MB/s is 5Gb/s; the switch from bits to bytes seems to be a way to exaggerate the difference from Thunderbolt speeds quoted in GB/s; at any rate, USB 3.1 Gen 2 (equivalent to USB 3.2 Gen 2×1) 10 GB/s cables and device support isn't hard to find; I don't know that anyone had USB 3.2 hardware (controllers, or cables supporting the new 2×2, 20Gb/s, mode) yet.
As far as I know a universal cable is not possible. My reading of the spec says that it should be but I am not a USB implementor and some of my friends who are tell me it's not possible. In any case nobody ships such a thing.
The charging cables provided with devices are likely to be power-only. With the 87W charger, Apple ships ones that can carry about 100W (the maximum per USB spec -- 20V@5A) which requires thicker conductors; my understanding is that those cables don't carry data (i.e. they can safely be plugged into any third party brick without you worrying that the remote device will attack your computer). You want a power-only cable for this purpose. I am not sure of they have the same cable with the smaller adaptors.
The very high speed cables only work over short distances unless you go to optical (which I'm not sure anybody has deployed).
The most standard cables carry "USB 3.1" which is just another name for USB 3.0 carried over Type C connectors. The higher frequency and higher power cables are more expensive to design and build so will cost the customer more. That's one reason you have to specifically look for cables for DP, PCI-e/Thunderbolt etc.
No, it's not; USB 3.1 adds the new SuperSpeed+ mode over all supported connector types (and USB 3.2 adds two additional SuperSpeed+ modes for Type-C connectors.)
USB Type-C connector spec is a separate spec issued after USB 3.1, USB 3.1 isn't USB 3.0 over Type-C connectors.
Overall, I think a quick glance at the whole discussion under my comment proves my point quite well.
Currently there are four common speeds/specs for the high-speed lanes: none, USB 3.0 at 5GHz, USB 3.1 at 10GHz, Thunderbolt 3 at 20GHz.
Cables that can support the higher speeds without signal loss issues tend to also be increasingly short. That's another issue getting in the way of an ideal cable; it's hard to carry such high frequencies to the same distances.
There's no tradeoff between speed and 100W support, but most cables do lack 100W support for whatever reason.
A lot of cables (even from Apple and Google) pick the "none" option for high speed lanes. Such a cable can only run at USB 2.0 speed and is often called a "charging-only" cable. (True charging-only cables are significantly more rare. They also probably violate the spec.)
But it's enough to just read the cable reviews to learn that things are not always fine.
Also, one thing which cannot be blamed on "crappy cables" is that the presence of a USB-C port on a computer does not mean much at all, because in general one has no idea what can be connected to it.
It used to be the case that anything of the same connection type would - at worst - not work if it wasn't designed for that piece of equipment. But now you have a situation where things "kinda" work together so consumers are encouraged to mix and match yet some of the time it could literally break your hardware.
So now we have a situation where some people are too scared to mix and match which breaks the entire point of a standard connection type - and on the flip-side you have other people who are left with bricked hardware because they were unlucky enough to plug the wrong charger with the wrong device (for example).
I have a few modular power supplies around from different vendors, and I made the mistake of using one cable in a different vendors supply.
The supply side had the same connections; so I thought that I could just mix-and-match.
Turns out, that even though the connections are standardized, I ended up putting ground on a 5v pin, 12v on the 5v, 3.3v on the 3.3v (magically) and 5v on the 12v pin on a standard SATA connector.
As a result, I fried several hard drives, because the output of the supplies wasn't standardized for the connector type. I can't even imagine an end-user using a volt-meter to check which are compatible with which vendor.
This was a problem before USB-C.
TL;DL: Check your modular supply cables, and don't use other vendors cables.
USB-C on the other hand is a standard.
That kind of brings me to my next point: proliferation of cables and dongles. Whenever I travel now, I need to have the same USB-A to micro-B cables I was already using, plus some pure USB-C, plus USB-A to USB-C. Not uncommonly, USB-C to micro-B gets thrown into the mix. And the variance across all those is even greater than the pure USB-C stuff. Good luck keeping track of voltage, directionality, data vs. power-only, and all the other variables. For now at least, the addition of USB-C has made things far worse.
I for one would be happier if USB-C were only for laptops and tablets, and all the people making the zillions of smaller devices would FFS stick with micro-B like they were already starting to. Then I'd only need one power adapter, two kinds of cables, and no dongles, instead of this mess.
I've had generally good experiences with Type-C and IMHO is an improvement over buying video out dongles for every device and being able to use a single cable for charging.
If it was designed to have a single connector for charging cables, they were designing to solve a solved problem.
Also let's not forget that USB-C is two-fold rotationally-symmetrical in contrast to micro-B.
And I didn't forget the laptop. I just don't take it with me much. And I prefer the mag trick of older Macs.
So, congrats, you have a connector that everyone can standardize on. Now, once literally everyone else moves of the old standard, we'll be there.
No, not "literally everyone", as laptops weren't using micro-B for charging.
So, my headphones, my bike computer, my bike lights (front and back), my spare batteries, and my other tablets.
Also, I confess, yes. I was being rhetorical. :)
Seriously look at my list of things I have. I suspect my phones and hopefully the spare batteries I buy in the coming years will be USB C. However, my bike gear and other hobby equipment won't any time soon. Even my laptop and tablets are going to be years before I update them to one that supports USB C.
So again, outside of laptops, the world had standardized on a connector. That my laptop was different is as relevant to me as knowing that my drier isn't USB C any time soon. That I'm now going to have to deal with a ridiculously slow transition from the de facto standard everyone else was following to USB C is just obnoxious.
Edge case? Probably, but only because most people don't consciously factor this into their purchase decisions. It's clear that USB-C is the way forward for phones, and once that happens on the low-mid market segment, everything else will follow.
This isn't an insult. Just pointing out that most of the electronics world had standardised. To pretend otherwise is just odd.
It sounds like USB-C is that, but worse.
(If there's any way to tell what cable is a data cable, I'd love for someone to enlighten me.)
This is also true with USB A, B mini-A and mini-B, mini-AB, micro-A and micro-B, and micro-AB; also A, B, and micro-B actually have two versions each of the connectors, with compatibility in one direction, so you don't even always know that physical connectors are compatible from the connector name without also the USB version.
There is an upside to that terrible timeline though: an opportunity to have the new name be USB-C++
You're probably right that because USB-C is a newish standard, manufacturers might make idiotic newbie mistakes like the ones Surjtech made with that cable. That would argue in favor of waiting... though I'd estimate that you're more likely to be struck by lightning than encounter a retail USB-C cable with power and ground reversed.
Now we're to trust the same bottom scraping hardware/software makers with an already overly complex serial port.
Not a great situation.
edit: Keep in mind that a charger meant for a phone is unlikely to provide anywhere enough power for the Switch. You likely need a charger that implements at least USB-C PD.
In short, the Switch does not properly implement the USB-PD standard.
I've heard that third-party chargers work. I could be wrong though.
(Of course, it's always done "for your security"...)
The issues people have had with it seem to be that the Switch dock requests exactly 15V from the power supply when plugged into a TV, and many USB-C power supplies don't support this voltage. The MacBook pro charger supports 9 and 20V (I think), and most others use 9, 12, or 20.
The problem is that there's no indication of what failed unless you're sniffing the power delivery handshake.
"hey this is a Samsung USB-C cable, you can't use it. Go buy an LG's one. They are exactly the same except of authentication but we can't trust if otherwise, it's for your safety!"
Than I'll wait for a crying herd of fanboys that proudly try to justify it well pushed by marketing sheepdogs in disguise...
Not exactly top notch reporting here. It is the OSs responsibility to lock down access to I/O resources. Stuxnet was caused by the insecurity of Windows Autorun, not USB.
Also, unless literally every “trusted” USB-C device has its key and its core functionality on a secure chip, the bad guys will just compromise a signed device and make it malicious. As far as I know, many, many USB devices can have their firmware replaced with no authentication whatsoever.
I welcome the world where machines trust my CA and someone who wants a USB device just comes to me, signs the paperwork, and leaves with a signed device that suddenly just works.
I mean pushing the security boundary to "someone with the knowledge to flash USB firmware without corrupting the certificate" is pretty darn good.
Digicert surely welcomes this world! I personally don’t expect Digicert to have any real controls at all.
Also, right now, to put malware on a USB stick, you can just write malware to it. To create a USB stick that has malicious firmware to attack the host drivers, you need a USB stick that doesn’t protect its firmware or you need to build your own. In the new world, this changes to, drumroll please, a USB stick that neither protects its firmware nor wipes its key when new firmware is uploaded. Or you can build your own and pay Digicert, or you can attack a machine that doesn’t bother validating the signature because it wants to retain compatibility with the billions of existing unauthenticated USB sticks.
Also, if devices need per-device keys, then I suspect that firmware upload won’t wipe the key, since otherwise firmware upload mostly breaks the security model unless some rather complicated checks on the firmware upload process are done.
USB-C devices are cheap, and they’re made by tons of vendors, many of whom know about voltage conversion but not security. Heck, most of these vendors, even big names like Nintendo, can’t even be bothered to speak the protocol correctly.
EDIT: Yea, I know I'l probably cause some amount of damage in the process.
No it's not! Badly designed cables and chargers have been damaging devices via power-only ports for decades.
I guess another question is, why did we need "secured" x509 USB? whos pushing this standard?
For example, the Porsche 911 comes with single lug wheels...theyre exotic enough to take their own special wrench, at four hundred dollars, for no real reason other than 'racecar.' youll never race it at speeds where this F1 class hardware matters, but hey, racecar.
This will mostly be a deterrent for opportunistic thieves, the same reason you lock the door of your home. Even locked, it is still easy to open with the appropriate tools.
I don't know about the particulars of this standard though, maybe it's just some DRM thing and soon you'll have to buy expensive dell mice for dell laptops or something like it's already the case with gamepads and consoles.
[1]: https://srlabs.de/wp-content/uploads/2014/07/SRLabs-BadUSB-B...
I was curious so I looked it up, here's their very expensive torque wrench [0]. Here's some pictures of guys holding it [1].
It seems weird to me to complaint about requiring specialty tools for a specialty car. It's not like there aren't a ton of car options to chose from.
[0] https://www.tooltopia.com/precision-instruments-c4d600f36h.a...
[1] https://www.thextremexperience.com/blog/insane-torque-wrench...
The 'I trust this device' system allows confirming that you trust the device. This crypto confirms that the USB-IF trust the device (and presumably all they are asserting is that the device conforms to standard).
It's an interesting idea, and not a bad one. That's assuming the certificate system is sound which I remain sceptical of until I know more, given the normal issues with managing a single unrevocable private certificate.
Seems... low, esp for an offline device that you can get hands on both sides of. How many chargers are going to use as cheap a micro as possible for this?
Also, adding an encryption layer and further fragmenting - does have the benefit that Apple may make iPhones with TypeC connectors... so, hooray?
Why did they have to go down the 'trust' rather than 'distrust' route? It is a completely different universe from the principle of least privilege.
Just like Spectre/Meltdown: half of all people will just shrug, completely unsurprised, when the inevitable zero day drops. And the split between those that find the sky falling, will be the clueless and the plants. Whatever.