This line particularly caught my eye. I wonder what's the percentage of people (I'm presuming people working in security or those who are trying to avoid detection) go to this extreme?
Is is even extreme?
This line particularly caught my eye. I wonder what's the percentage of people (I'm presuming people working in security or those who are trying to avoid detection) go to this extreme?
Is is even extreme?
How exactly does this work? Is there a sort of software that runs automatically when you insert the stick, or did he have to click on it?
https://www.instructables.com/id/Autorun-anything-off-of-a-u...
Apparently, autorun from USB volumes was enabled for XP SP2:
https://support.microsoft.com/en-us/help/967715/how-to-disab...
>Before Windows XP SP2, AutoPlay was disabled by default on removable drives, such as the floppy disk drive (but not the CD drive), and on network drives. Starting with Windows XP SP2, AutoPlay is enabled for removable drives. This includes ZIP drives and some USB mass storage devices.
I know this isn't really very relevant for the specific combination of installers and physical media any more, since it's rare for anyone to be trying to install something off a CD/DVD/USB these days (other than a new OS, of course.)
But I could see the use case for physical media doing something other than running an installer (e.g. DRMed disks launching the equivalent of a FUSE server to mount the "rest" of the disk); or for non-physical media (e.g. macOS DMG disk images) being able to autorun their embedded installer. Either way, the code signing that the platforms are already doing would be enough to make these safe, no?
At best, Windows code signing lets you know who signed it and that that person was able to pay a CA some money, not that it's safe to run.
https://www.theregister.com/2011/02/08/microsoft_windows_aut...
You should try Windows 10! It's very good. At least give it a whirl so you can have accurate facts to what it does, and not spread FUD about it.
I type the above SO often every day, it should be on my gravestone. :D
Great bit of example code, but opens a world of possibilities for what you could do with, say, a HID + Mass Storage composite device.
For most common hardware this is just an 8051 variant that sets up the USB and DMA peripherals. It's easy enough to get something more powerful, but I am doubtful you'd want to reuse consumer hardware.
In this case any kind of MCU is making life harder than it needs to be.
For me an extreme measure would be to modify my motherboard in a way that I could connect RAM to my wrist and tear it away when necessary.
Bonus points if they cut it when the tackle you because they thought it was a deadman switch, like mentioned in the link.
A phone could work. An apparent car key would be better. Best would be a piece of clothing, like a belt.