plausible deniability. selling devices specifically for committing crimes is illegal. that's why all the bong shops say it's "for tobacco use only".
Unless you're in a state that's legalized it.
My second question is that if bongs and water pipes are the same thing, why does the law distinguish their purpose by their name? It seems like given "I want to buy a water pipe for smoking the marijuana" and "I want a bong to smoke tobacco", the second should be legal to request, not both.
if you intend to use that power tool or crowbar to break into a house it’s “possession of burgular tools” and a felony, if you’re a contractor there to install some drywall it’s not.
Why would that be necessary?
Jackhammers are tools to destroy pavement. But nobody sells jackhammers as "ground strength testing tools".
These are tools to destroy computers. Both are completely legal as long as you are not destroying someone else's property without permission.
While I'm not aware if anybody has ever been convicted for weirdly defined laws like that we for example have a "hacking paragraph" in Germany that outlaws software for the sole purpose of computer crimes. I'd imagine the UK has similar legal areas in lieu of their recent "kitchen knives are dangerous weapons, sometimes" controversy. It's not that hard to imagine somebody going after the manufacturer of such hardware and that blurb (or the ever famous "for educational purposes only") give them something to reasonably distance themselves from a user's actions.
Is there any device that is supposed to survive this?
In other news, throwing your computer in a fire also reveals a serious vulnerability.
[0] https://github.com/usbkill/community/wiki/Consumer-Laptop-Ha...
The problem is: optoisolators are very slow. Building one which goes faster than 12Mbps would be nontrivial; I do not think such a thing existed in 2014 (which usbkill is claiming). This implies that Apple has alien technology.
I think it's something else.
The problem is: optoisolators are very slow.
Many are but they don't have to be - an optoisolator is just a zero-length fiber optic cable. Ain't much higher bandwidth than a fiber optic cable.Not saying apple laptops ever had optoisolated USB though.
12Mbps/1.5Mbps is easy. ADI has an integrated magnetic isolator chip. For hobbyist use you can get this assembled on a board ready to use as an ebay special.
The 5Gbit of USB3 is two unidirectional links and so is also easy (monoprice and elsewhere sell optical USB3 cables).
And lest you think you'll isolate at 5Gbit and then use a hub to translate to 480, USB3 doesn't work that way - the backwards compatibility is provided by a complete USB 2 bus in parallel.
For general isolating (say an electronics workbench), it's easiest to consider the USB host floating (eg a dedicated bench computer), and rely on ethernet (T or SX) for the isolation.
And you'd still have to deal with the big spikes coming in on the USB power pins.
Ethernet is designed this way because the differential pair can apparently pick up a bit of a DC bias when laid next to cables in the ceiling/wall. While researching this post, I found that the spec requires the transformer/inductor to work correctly with a 30mA bias current. I am too lazy to go measure what the DC resistance is, though, so I don't know whether or not 200V is close to that.
When I was in high school, I wired up a cat 5 cable such that each pair was connected to one phase of the mains. I then plugged it directly into my iMac. There was no damage to the computer and the Ethernet port worked fine afterwards as well. (The integrated monitor went crazy; this was in the CRT days and presumably the Ethernet transceiver's magnetics make a good degaussing coil).
The fact that Ethernet functions the same with a voltage bias across the leads is exploited for PoE — power over Ethernet.
Because I was 15 and bored.
(On the plus side, this made up for sleeping through that physics class where my professor did the exploding wires demo.)
There used to be...
As a boy - and this is many, many years ago - I once, ehm, accidentally connected the external speaker-plug on an old vacuum tube household radio to the 220V mains.
A very loud bang, and the house went dark. The radio, however, was fine, although with an interesting new tonal slant to everything.
I repair & build vacuum tube equipment as a hobby.
This device that is designed to destroy computers is perfectly safe to use ... I don't know what to say to that.
That's much harder though because power lines tend to have big-ish capacitors on them.
https://www.ebay.com/itm/DC-3V-5V-Arc-Generator-High-Voltage...
You also want to use the gas dispenser from a Paslode impact gun, an air mattress inflator and a Zodiac check valve for the air purge.
Explosives will destroy, but recognizable parts will survive. Your safest bet probably is burning your computer, fast and thoroughly.
I think white phosphorous is a popular choice for this kind of thing because it’s relatively easy and safe to transport, store, and deploy (compared to, say, strong acids such as aqua regia)
Search for "and that's how I lost my other eye" from defcon23. Probably available on YouTube.
I suppose some pen testers, or actual CIA type folks might have some need of this type of device... but is that a large enough market?
"A hammer used maliciously can permanently damage to a third party's device. The USB Killer, used maliciously, can permanently damage a third party's device."
Contrary to this device a hammer can be used a useful tool too.
To prove that USB devices can be malicious.
It's probably most useful as an education tool, training staff not to plug random USB devices they find lying around the parking lot into their computers.
Nothing like some high-consequences IRL training!
Perhaps curricula for the Inspector Clouseau police academy?
Essentially that the logical extreme of dropping computer-destroying USBs to demonstrate that one shouldn't plug strange USBs in the first place is akin to destroying an office that you talked yourself into to prove that you shouldn't have been let in in the first place. Perhaps "shooting up" was a tad too far, but with charity it's a reasonable point nonetheless.
Using a computer-destroying USB stick as an example of physical security threats misunderstands the nature and motivations of attackers. Everyone past childhood (and some in childhood, sadly) understands that there are a few people in this world whose motivation is to cause destruction and hurt simply because they find destruction and hurt enjoyable in themselves. They also understand that such people are rare, and that their threat modeling (which everyone does, even if they don't call it that) should rationally respond to such people by almost ignoring them—otherwise you find yourself not leaving your house for fear that there's a gunman on your block.
The motivations of people who want to actually get something out of you are quite different. They're not interested in destruction, because that would harm their target. They're usually interested in being undetectable. A social engineer will pretend to be locked out, ask meekly to be let in, and behave like a normal employee until they get what they need and leave normally. Defenses like "don't let people tailgate" work for those people. A gunman will just shoot you, break the door, ignore the alarm, and keep shooting until the cops kill them.
Similarly, someone who's trying to attack your business with a malicious USB drive will give you a USB drive that appears to be a normal one, that maybe pops up a terminal window very briefly and then disappears. You likely won't notice that you made a mistake, and you'll probably see an actual drive pop up on screen. Someone who's trying to attack your business will generally not give you a USB drive that destroys your computer immediately. (For most businesses, computers are not worth much compared to the secrecy of the data they contain, anyway, which is why full-disk encryption is a reasonable defense; it assumes that a computer might be lost and that this is recoverable.)
So a good security training program should say "These are ways where people might try to subtly break in to gain access that you might not have thought of before," not "Sadistic sociopaths exist, wear plate armor at all time."
Hardware designers might want one to test out their mitigation circuit but once your design, why do you need a USBkill anymore?
This thing just seems like a destructive version of those annoyance toys like a TV-B-Gone.
> During the 2008 Consumer Electronics Show, an individual associated with Gizmodo brought a TV-B-Gone remote control and shut off many display monitors at booths and during demos affecting several companies. These actions caused the individual to be banned for life from future CES events.
foreach offcode in list_of_offcodes:
transmit(offcode)Exactly. That device has nothing to do with police or testing. The politically correct name is a way to avoid filters or to claim ignorance in case some customers do nasty thing with them. Not different from cellphone/gps jammers sold under the "signal/field generator" name.
"Even if it was their own device that they were retiring, it doesn't even wipe data, it just destroys the logic/motherboard."
And it's even very bad at it: most computers have internal usb hubs that would act as a (weak but sometimes successful) defense against these devices.
Likewise, the USBKill suppliers had shown confirmed clients from all large SV companies, and all major hardware manufacturers.
It definitely is a malicious device in the hands of someone malicious, no doubt... But it most definitely serves a purpose to government and LEA apparently ..
"I wouldn't be so sure." is not the right test to pick. Yes it might destroy the SSD, but more likely just burns out something on the motherboard.
When you are picking an emergency destruction method your test should be: "I'm reasonably certain that this irreparably destroys the data"
To elaborate: surge/ESD protection components work on the basis of thermally dissipating incoming energy that exceeds voltage threshold. They're specifically designed to clamp single, short, high-energy pulses - not repeated pulses or constant voltage. A TVS or MOV will overheat & explode if you subject it to DC higher than its breakdown voltage, or if you subject it to repetitive load - they're simply not designed & rated for that because it's not what happens in the real world. You just don't get repetitive lightning strikes or repetitive ESD discharges in real life, and they don't protect against that.
TL;DR: With enough voltage & current you can fry anything and that's what the device does.
>Does not require batteries, can be be used an unlimited number of times.
So how does it work? How can it recharge all those capacitors?