I suppose some pen testers, or actual CIA type folks might have some need of this type of device... but is that a large enough market?
I suppose some pen testers, or actual CIA type folks might have some need of this type of device... but is that a large enough market?
"A hammer used maliciously can permanently damage to a third party's device. The USB Killer, used maliciously, can permanently damage a third party's device."
Contrary to this device a hammer can be used a useful tool too.
To prove that USB devices can be malicious.
It's probably most useful as an education tool, training staff not to plug random USB devices they find lying around the parking lot into their computers.
Nothing like some high-consequences IRL training!
Perhaps curricula for the Inspector Clouseau police academy?
Essentially that the logical extreme of dropping computer-destroying USBs to demonstrate that one shouldn't plug strange USBs in the first place is akin to destroying an office that you talked yourself into to prove that you shouldn't have been let in in the first place. Perhaps "shooting up" was a tad too far, but with charity it's a reasonable point nonetheless.
Using a computer-destroying USB stick as an example of physical security threats misunderstands the nature and motivations of attackers. Everyone past childhood (and some in childhood, sadly) understands that there are a few people in this world whose motivation is to cause destruction and hurt simply because they find destruction and hurt enjoyable in themselves. They also understand that such people are rare, and that their threat modeling (which everyone does, even if they don't call it that) should rationally respond to such people by almost ignoring them—otherwise you find yourself not leaving your house for fear that there's a gunman on your block.
The motivations of people who want to actually get something out of you are quite different. They're not interested in destruction, because that would harm their target. They're usually interested in being undetectable. A social engineer will pretend to be locked out, ask meekly to be let in, and behave like a normal employee until they get what they need and leave normally. Defenses like "don't let people tailgate" work for those people. A gunman will just shoot you, break the door, ignore the alarm, and keep shooting until the cops kill them.
Similarly, someone who's trying to attack your business with a malicious USB drive will give you a USB drive that appears to be a normal one, that maybe pops up a terminal window very briefly and then disappears. You likely won't notice that you made a mistake, and you'll probably see an actual drive pop up on screen. Someone who's trying to attack your business will generally not give you a USB drive that destroys your computer immediately. (For most businesses, computers are not worth much compared to the secrecy of the data they contain, anyway, which is why full-disk encryption is a reasonable defense; it assumes that a computer might be lost and that this is recoverable.)
So a good security training program should say "These are ways where people might try to subtly break in to gain access that you might not have thought of before," not "Sadistic sociopaths exist, wear plate armor at all time."
Hardware designers might want one to test out their mitigation circuit but once your design, why do you need a USBkill anymore?
This thing just seems like a destructive version of those annoyance toys like a TV-B-Gone.
> During the 2008 Consumer Electronics Show, an individual associated with Gizmodo brought a TV-B-Gone remote control and shut off many display monitors at booths and during demos affecting several companies. These actions caused the individual to be banned for life from future CES events.
foreach offcode in list_of_offcodes:
transmit(offcode)Exactly. That device has nothing to do with police or testing. The politically correct name is a way to avoid filters or to claim ignorance in case some customers do nasty thing with them. Not different from cellphone/gps jammers sold under the "signal/field generator" name.
"Even if it was their own device that they were retiring, it doesn't even wipe data, it just destroys the logic/motherboard."
And it's even very bad at it: most computers have internal usb hubs that would act as a (weak but sometimes successful) defense against these devices.
Likewise, the USBKill suppliers had shown confirmed clients from all large SV companies, and all major hardware manufacturers.
It definitely is a malicious device in the hands of someone malicious, no doubt... But it most definitely serves a purpose to government and LEA apparently ..
"I wouldn't be so sure." is not the right test to pick. Yes it might destroy the SSD, but more likely just burns out something on the motherboard.
When you are picking an emergency destruction method your test should be: "I'm reasonably certain that this irreparably destroys the data"