Windows Hello bypassed using infrared image
therecord.media
therecord.media
What I'd really like is the system to consider every new USB device untrusted, and require specific approval before it's added as a device. This should apply to its capabilities too (eg: if a "keyboard" suddenly is presenting itself as storage, that causes a prompt). Think along the lines of "Acme WebCam XYZ wants to add a Camera and Microphone. Allow?"
And while the computer is locked this should absolutely be impossible.
I went looking for some commercial stuff, and there seems to be products aimed at businesses -- but seems these are centrally-managed, work by whitelisting specific devices ahead of time, and are more focused on data exfiltration than preventing a rogue keyboard, badusb or rubber ducky. Is there something that does this?
You probably could add some kind of fingerprint that allow identifying the legit prompts, but since it is not done with login screens...
Never played with one, but I just assumed it was a macro playback engine, not surprising, I suppose it would do more.
I'm not clear on how you would know it was the keyboard changing identities and not just a new device. Does the USB protocol provide anything where you would know, assuming devices can change Base Class, VID, PID, and so on?
For that matter, I don't think it needs to change. It can just emulate a hub and present both.
It seems like maybe Microsoft should have required something like this for Windows Hello cameras, if they intended for people to use the hardware as a single factor authenticator.
i.e. the camera generates internal crypto keys and tells Windows about them when you set up Windows Hello, then Windows does a challenge/response to make sure it's getting an image from the authentic camera during login attempts.
Apple did something like this with the fingerprint reader home buttons on iPhones, which is why you had to replace the motherboard + home button as a single unit on damaged devices. They could have provided a reprovisioning tool, but it's Apple, so they didn't.
They did
"A private key used by one Authentication Responder shall not be used by any other Authentication Responders. For example, one instance of a USB PD power supply cannot have the same private key as another instance of the USB PD power supply, even if they are otherwise identical model."
[1] https://usb.org/document-library/usb-authentication-specific...
You'd have to also detect PID/VID brute force attacks. Short of a cryptographic key (as gruez talked about), a device being able to guess a valid class+PID+VID combo would be bad, so this would have to be treated similar to a password brute-force attack: too many "new" devices in a short time (especially unplugged without clicking the authorization UI) would cause the system to stop accepting new devices for a time.
Ideally you can also detect something else -- eg: serial number -- but I think that starts getting into manufacturer/device-specific implementations. (If only there was a company with billions of dollars and huge facilities and relationships with USB vendors and the capability to test tons of devices..)
Yes, I understood that. What I'm saying that USB wouldn't give you any context for that. A device changing would be indistinguishable from one being removed and a new one going in. Or future "rubby duckies" could emulate a hub, and add multiple devices, all operating simultaneuously.
> A device changing would be indistinguishable from one being removed and a new one going in. Or future "rubby duckies" could emulate a hub, and add multiple devices, all operating simultaneuously.
In all of these cases, the system should show a prompt asking the user for authorization. Hopefully in a way that makes it clear if they didn't just physically attach a new keyboard, they should be extremely suspicious about what's currently connected to their USB ports.
It would be rare to see multiple devices at once -- eg: the very first boot, or plugging in a new complex device like a dock -- but the experience of this hinges on having the right UI. Having a series of pop-ups like "Do you accept Generic USB Hub 06 (connected to Root USB Hub 2)?" is going to cause them all to be ignored, but, for example, showing a tree of devices and making it easy to accept all at once would probably be ok. And hubs in particular may be a special case, where you don't bother to prompt, but I don't know if that opens an attack vector.
Maybe if you’re NSA you could roll your own USB xHCI and a USB A receptacle that could characterize and identify individual units down to a machine in China used to assemble it, but that will be lightyears ahead of commercial USB host controllers.
QubesOS does this by quarantining your USB controllers in a dedicated virtual machine.
https://www.qubes-os.org/doc/usb-qubes/
Usb-guard for Linux also uses kernel features to accomplish similar.
I dont know of any methods to do this on MacOS or Windows though.
There's USBGuard on Linux that seems to do some of this. Can't vouch for it, as I've never used it, though.
These kinds of things of 'security'* features can't be considered protection for the valuable data on your computer, or the e-commerce account you're currently signed in on.
This stuff is for preventing Steven from making a funny Facebook post in your name (he'll find a way anyways).
*roughly the same level of 'security' a "beware fluffy the furry menace" sign on your garden fence provides.
In marketing sense. You leave your fingerprints all over the keyboard, and I can record your face freely.
It's completely outrageous that MS thought it was acceptable to do facial recognition using a basic webcam.
(also: if it's semi secure then being able to build trust based on that means the other part is PR I guess, outrageous as well?)
Apple's Face ID takes a 2-dimensional infrared image of your face as well as projects 30,000 IR dots to form a 3D depth map of the face. It feeds this into a NN in a separate Secure Enclave processor to determine whether the face is attentive and authorised. I believe they also implement specific NNs just to perform anti-spoofing, both physical and digital.
This is contrasted to Samsung and Microsoft's solutions which take a picture and try to match it.
Apple's Platform Security Guide on Face & Touch ID [0] is an interesting read.
[0]: https://support.apple.com/en-gb/guide/security/sec067eb0c9e/...
Still nowhere near as secure as they make out though
Also the younger you are the less likely it is to differentiate.
https://docs.microsoft.com/en-us/windows-hardware/design/dev...
Very few companies actually care about security over flashy marketing features.
There is certainly some resemblance, particularly what I looked like when I was 6, but not a huge one.