O.mg Cable
shop.hak5.org
shop.hak5.org
https://www.ifixit.com/News/8448/apple-audio-adapter-teardow...
https://www.kenrockwell.com/apple/lightning-adapter-audio-qu...
That's why when you use the iPhone HDMI adapter, everything looks a little bit compressed. Because it is.
https://hackaday.com/2019/07/30/apple-lightning-video-adapto...
For regular home/app views, it does hardware compression of the iPad's screen, outputs that over lightning, then the adapter decompresses it to raw HDMI.
While for Netflix/etc. streams, it outputs the stream directly to the adapter to decompress, without quality loss. (And at full size as well, rather than double-letterboxed.)
I still haven't figured out the magic of how apps like Netflix are able to do overlays of subtitles on top of the compressed video stream. Best I can tell, there must be a separate API for that, that gets sent in parallel.
And I'll even leave aside the issue of running a whole OS just to decode video.
But this is dealing with 1080p output. That's not very intensive. A lightning port has two high speed data pairs. You don't even need USB 3 speeds to transmit HDMI over one of those data pairs, and then put in like a $2 redriver.
If you set up double-sided output I think you could even have a passive lightning to HDMI adapter. But that's a side issue, my main point is the bandwidth available that makes these tradeoffs unnecessary.
Yes. (Well technically you need 3.20 or 3.33 for 1080p60, and HDMI 1.0 supports 3.96)
> Lightning is 480 Mbps. The bandwidth isn't there according to how lightning was designed.
Not true. Lightning has two differential data pairs. The port can do much more than 480 Mbps.
If your response to that is "oh, but it's only connected to pins that do 480", they would have to reconnect it to video pins anyway to do HDMI out. And nothing else in the lightning ecosystem would limit it, because this is a directly-attached adapter.
Also some of the iPad Pros have actual usb 3 support on their lightning ports.
Thanks for the comment. Had no idea. Mind blown.
I can't find a link referencing it, sadly.
Hey! That's my Windows 10 product key!
(not really, but felt like it could be).
The film Enemy of the State (1998) was science fiction except with the parts where the techy operators were just normal nerds like us. That what was most scary part of the film not the (at the time fantastic) surveillance.
If most people are weak enough to become matrix-like slaves to the machine, so be it. I don't believe in free will and I don't think we need to preserve human life in a certain way (e.g. the way our ancestors lived).
Sure, a lot of people will fail this test, or maybe they prefer to live their life like that. I don't care, that's on them, that's their choice - or, better, the way DNA and the environment shaped this human shell.
If instead you wiretap my device, you're attacking my privacy and I don't have a way to defend myself. You are committing violence.
Please forgive my ramblings. I may have been reading Daniel Dennett too much, most likely with too little understanding.
It is specious to look at entropic consequences, when you should look at the existent will being exercised to predict those consequences.
You can't predict unless you have the will to perform a prediction. Having such a will to act, is free will.
As another example - You are able to freely exercise your will to comment or not to comment.
I’m fairly certain fish can predict the course of future events, to a fairly high degree of accuracy, in relation to seasonal changes in water temp, food density, etc… e.g. spawning salmon
It is not clear at all your claim is true in the general case, which is the point. Humans differ from fish not in kind, but only in degree, a few hundred million years of evolutionary divergence as the biologists would have it. Unless of course special factors such as a ‘soul’ are assigned to humans and so on.
That is a general claim that you wrote that I have shown is not correct unless you have an interpretation of the word ‘will’ that is so broad as to render your other statements somewhat meaningless.
In fact you are the one creating the strawman since you dodged addressing the question. I have made no separate claims about my personal free will, or lack thereof.
It is now obvious you have no point other than wanting to debate words and are being intentionally obtuse. This is not a high school debate class, and I will no longer engage in your foolishness, since you have stated that you are not actually commenting on the subject of the conversation.
I’m not exactly sure why you think I would care so much about your opinions to be ‘the arbiter of truth’ for any topic. You’ve made claims that are clearly erroneous and I’ve been pointing them out to the passing reader, so they are not waylaid. I won’t comment on the correct interpretation of ‘free will’ since I myself don’t know, and decline to pretend to know.
Of course. And education.
A lot of what they look for is consistency in accounts of previous behaviors between you and any references / interviews they undertake, trying to assess if you're currently honest.
Another big thing they are trying to decide is if you are blackmailable.
(throwaway because I have the sort of clearance you are not supposed to advertise that you have)
(clearly decades ago, and he's less than reliable, but fun nonetheless!)
It's a problem if you do drugs and are hiding it from someone (say, family). Then you can be blackmailed.
Facebook and Google need the user to use their services and they say (despite the message being in legalese) what they're going to track. There is consent involved in these organisations, it's a voluntary transaction.
The government can (and did) just intrude on everything without consent or penalties.
From a moral point of view, I would be open to work for BigTech, but I wouldn't work for a state actor.
And, also, both Google and Facebook eagerly cooperate with state actors in censorship and other aspects - likely surveillance too. So there's not much difference in that aspect whether you work for the government directly or for somebody who takes marching orders from the government while being formally independent.
A more accessible idea which is quite different but allows some truth to shine in similarly is to consider how many of us are utterly dependent on advertising in our careers but we all adblock personally.
Some of us don't agree with the intelligence gathering behaviors of our governments, but they certainly might not view it as an issue.
I remember "Spot the Fed" at DEF CON where I thought it was reflecting this deep and kind of intractable antagonism between the hackers and the government. It turned out that the government was regularly recruiting people there and at other hacker conferences, fairly successfully, and still does. (First I thought that all computer nerds would be at least somewhat anti-military or anti-surveillance, and then I thought that at least those who actively associate themselves with computer culture and counterculture would be, and now I don't really think either of those.)
The social distance between people working for spy agencies and people who vocally criticize and oppose the spy agencies is tiny. I worked at EFF and I've known socially, or kind-of-socially, four people I can immediately think of who worked directly for NSA at some point in their careers, and those are, of course, just the ones who chose to mention it. I've also seen someone unsuccessfully try to recruit someone for NSA face-to-face right in front of me, and had a boss whose next job was alongside an NSA alum.
I also think that NSA alums are more likely to mention it because they're less likely to have worked under false pretenses in other countries (compared to, say, CIA alums).
I had a relative who was a super-huge computer nerd (the biggest computer nerd in my whole family, possibly more than myself, and taught me a lot of my early Unix knowledge) who had previously held a clearance and worked in aerospace engineering (I think on radars or something). He didn't work for a spy agency, but did work on military projects. And nobody could hold a candle to his Unix expertise.
It's pretty striking how diverse in our beliefs we all are (not just about surveillance and espionage, but kind of on every issue and question). Maybe we don't notice it because of social pressures to act like we agree more than we do. Being fascinated with surveillance and secrecy is a common trait in our circles, but it seems that might translate into trying to fight it, or into trying to do it.
That sort of makes sense to me? The average member of the public doesn't generally think about what spy agencies do. If you assume that recruitment is based more on topical proximity than positive/negative opinion, that's what you'd expect to see.
Couldn't be me: the private sector pays me waaaaaaaay more.
Also, you can't work for the feds if you ever touch the ganja, which is ridiculous. Everyone I personally know in infosec leads a very... alternative west-coast lifestyle which is not conducive to career progression in an east-coast, button-down-shirt environment.
I entertained the idea of working in the public sector a while ago, for a brief time, until I learned that pot is fine in my past, but not in my present. "How the heck do you expect me to get the code written?"
Also, I've been told that getting a clearance is more burden than blessing. You have restrictions that an "ordinary person" doesn't have, along with criminal penalties for violating them. Whereas, without a clearance, if they really need you for something, they'll bring you in anyway.
Anyone who thinks differently is arguing for a shadow gov, i.e. unelected bureaucrats who answer to no one and can make decisions unilaterally without consequence... not exactly democracy.
I also never said he had access to everything. Nobody has access to everything. Not arguing for a shadow government--it's already a fact. It happened when classification rules went from "what would harm national security" to "what would cause problems if American citizens found out we were doing this."
The only thing he does not have unrestricted access to is Justice department stuff (e.g. FBI), although there'd better be a damn good reason to deny it to POTUS if he asks, and legislative branch secrets which really infrequently comes into play. That's due to the whole separation-of-powers, checks-and-balances thing. But security clearances for everything in the executive branch stem FROM the president. If he wants to reveal some state secret, he can just tweet it with no consequences, or blurt it out while on the phone with foreign states. As Trump did on multiple occasions.
That said, of course there is a significant deep state bureaucracy which attempts at times to keep certain things hidden, even from the current president. But if the president were to ask about it, they have to tell him.
Lots of countries have an establishment "civil service" comprised of those "unelected bureaucrats" that you mention, and it actually works out quite well for them.
That said, they aren't unaccountable: they answer to departmental heads, MPs, committees, etc. A big advantage of the system is to prevent mad-swings in policy just because the head-of-government changed.
For example: https://en.wikipedia.org/wiki/Civil_Service_(United_Kingdom)
You can frame this another way: it prevents meaningful change even if the electorate demands it.
Sorry, I watched too much Yes Minister to think this is a good thing x)
I recognize I'm basically describing a utopia.
Does that include regular old things like ADHD meds?
For him it's been a minor nuisance at worst. He has strong restrictions on travel. I think he needs approval to travel abroad. He has relatives in other countries and visits them often, so it can't be too much of a nuisance.
I believe he told me that he does have to report details of where he went in each country and who he interacted with upon his return. Not sure about the details.
Official website: https://www.dm.usda.gov/ohsec/TravelResource.htm
Yes it definitely can be, but depends on your personality and stage of life. You are always cognizant of having a clearance and the need to maintain it, and so you consider that in your every day life. You also have to open your life up in uncomfortable ways, even if your only objection is in principal.
You probably don't sweat it too much later in life since you generally are a more 'boring' person, but I had mine in my mid 20's so was a lot more active in terms of social life. One time I was in downtown SF with a buddy hitting up bars etc and eventually had to cut out early because things were getting more drug oriented. I also used to play a lot of cards before getting a clearance and had contacts who were in some shady stuff. I basically excommunicated them from my life to avoid the clearance hassle.
I believe it is possible to get security clearance after cessation of drugs for multiple years, even drugs like Heroin. I found the full rules[0] while reading an AMA on /r/SecurityClearance.
[0] https://www.dni.gov/files/NCSC/documents/Regulations/SEAD-4-...
Calling it 'ridiculous' removes the debate concerning the pros and cons on such rule. If you consider someone can become vulnerable if they're addicted (to anything, really) then it makes sense to be wary of a drugs addiction. Especially if the resource the person is addicted to is illegal.
That being said, I'd find it reasonable if they OK'ed medical marihuana usage. I hope my gov (NL) does.
Obviously if someone is _addicted_ to either, that is a security risk. But the extent to which they reject people for recreational marijuana use is laughable.
The unofficial advice I’ve heard is to not even bother with SC if you use weed. Generally, it will be found out. I looked into this as needing an SC was a possibility with my current job.
Like caffeine ?
I'm almost sure they have coffee machines in there.
If you ask any project team to come up with a project name they will probably pick ‘Project Phoenix’.
Someone should do a study...
...Telstra in Australia called the transition from its 3G network to 4G "Next-G".
Why is this suddenly so depressing lol ._.
https://en.wikipedia.org/wiki/Rainbow_Code
See this from the article:
"During WWII, British intelligence was able to glean details of new German technologies simply by considering their code names. For instance, when they began hearing of a new system known as Wotan, Reginald Victor Jones asked around and found that Wotan was a one-eyed god. Based on this, he guessed it was a radio navigation system using a single radio beam. This proved correct, and the Royal Air Force was able to quickly render it useless through jamming."
Read R.V. Jones book "Most secret* war" if this kind of war-engineering interests you.
* Pay attention to "most secret" rather than the ghastly Americanism "top secret"!
Yes, Cottonmouth is correct.
See all the Sandisk U3 drive based badusb payloads that people could cleverly hide into all sorts of form factors.
The NSA implant was a passive retroreflector implant, which when illuminated by powerful radio waves, broadcasted back what was being typed, or what was visible on screen.
This seems to be more of a tiny chip that captures and stores keystrokes etc.
It has a complex codebase and firmware update methods to migrate to new USB specs. Cheap cables don't even support signing so go to town tampering with stock cables if you are so inclined.
Also an Attiny85 can fit inside just about anything.
My favorite BadUSB hello world is using the Arduino HID library to make a Digispark toggle caps lock randomly with maybe 10 lines of code. Drives people nuts.
Only some of the Type-C cables. Normal 3A ones don't have anything like this.
I don't know, but I do know that back in 2013 you could get an ARM computer running linux and a webserver with wifi and 16Gb storage in a space the size of an SD card. That is still a bit too big to fit inside a USB plug without being obvious, but not by much. https://hackaday.com/2013/08/12/hacking-transcend-wifi-sd-ca...
Fitting the electronics inside the usb plug itself has been used for years in slimline usb memory sticks and in tiny readers for micro-sd too.
I expect that this has been possible for nearly 10 years, but maybe just not commercially viable for consumers for most of that.
those readers usually heat up like crazy for any significant length transfers. good in a pinch, though.
Chips have been small for decades. What’s changed over the years is that it’s gotten cheaper and cheaper.
Like 20 years ago? 32 bit micros were actually not that far behind low end CPUs until they start to fall off dramatically in the 90, and post-90nm age because perf was good enough.
After nineties, CPU improvements were guided as much by software getting worse, slower, and more shoddily written, than genuine need for more raw computing power.
C-to-C charger cables with Bluetooth remote activated dual payloads: https://sneaktechnology.com/product/usbninja-custom-type-c-t...
I easily modified mine to mimmic Apple Keyboard USB IDs to avoid notifications. Works great!
Cellular GPS tracking car charger: https://www.amazon.com/Charger-Locator-Professional-Listenin...
Cellular GPS tracking USB charger cable: https://www.ebay.com/itm/223990414124
I have been making, collecting, and testing toys like this for more than a decade.
It is a race to the bottom on price now.
Your best defense for USB code execution attacks is use Linux with USBGuard or QubesOS with the default USB quarantine VM.
Windows and Mac users are currently easy targets. I don't know of any good defenses there.
Then we moved on to attacking the firmware in each others keyboards.
I am pretty decent at lockpicking but I can't pick a Medeco or better in any practical amount of time and very few in the world can.
Little bit more money vastly reduces your attack surface.
Aren't medeco padlocks like $100, whereas master lock padlocks are less than $20?
I then taught kids to pick them.
If the case was locked in a cage I wouldn’t notice until I needed to put access the tower to plug in a usb, which might not be for weeks these days.
but check out this one instead: https://youtu.be/sES_Hbj92BQ - ~2h to open fully (though the author of the video claims impressioning could speed up the thing; anyway, reportedly attacking the door is just easier in this case)
Not only does it take a couple hours to pick for an expert but you have to make a custom set of tools that only work on that one particular lock.
If a lock keeps someone out for several hours it is a great lock.
Also worth noting, Bosnian Bill (a more recognized name) also attempted this lock here https://www.youtube.com/watch?v=tLeiPmfm-2s
LPL covers most locks in the wild which are bad, but locks like the Protec2 are quite strong and while it is implied one person in the world can beat it with custom tools (huxleypig)... even then not quickly.
I frequently use FF-L-2740 spec locks, which is the spec locks need to hit for use in classified government work, military contractors etc. They are very good locks I can't begin to defeat in any practical amount of time and don't know anyone who can. Particularly since they have timed brute force lockouts.
Problem is not a single vendor is allowed to sell locks of that spec to civilians by contract so you have to jump through lots of hoops to get them.
I have had doors kicked in, so these days I want the lock to be the weakest, not strongest, part of the door. So when it is kicked in it is a cheap lock that is destroyed not an expensive hardwood door (I like hardwood doors...)
If a door is broken then a lock did its job. It let you know you were broken into.
Who is going to pick a lock that is cheap and easy to break?
Mēh. I have dogs.
Probably a criminal who is trying to be quiet, so they can enter your house.
For your home, a high security pin tumbler with security pins are fine too. It takes very high skill to defeat these.
You can say that again.
I was once proud of myself for having thoroughly researched the market and I thought EVVA MCS was a safe bet[1].
Then someone showed me a YouTube video (published a year after I bought the locks) of someone picking it (not LPL, another YouTuber). Given the cost of EVVA MCS I was not a happy bunny.
[1] https://www.evva.com/int-en/products/mechanical-locking-syst...
You can buy locks that don’t have easy bypasses, and can’t be easily drilled, and can’t be picked by beginners.
To keep people like me out for a while buy a Medeco. Pins not only need to be at the right height, but also the right rotation. They are a real pain in the ass to pick. I don't even know any locksmiths that can pick them. Good security for the money.
Bosnian Bill and LPL... Okay they can pick them, but they are like the 0.0001% in skill.
Still even then pay an extra $100 for really high quality disk detainer lock like a Protec 2 and you will keep even them out for quite a while.
That is what I use on my luggage. TSA has to call me to unlock them with my consent every time. The way I like it. Great tip I picked up from Deviant Ollam.
No - no they don’t.
Anything locked with a non-TSA compliant lock is fair game for the bolt cutters, and frankly probably draws a lot of extra attention.
All you’re doing is asking for extra screening…
[1] https://www.tsa.gov/blog/2014/02/18/tsa-travel-tips-tuesday-...
I've been wondering the most sophisticated/effective/secure locks regular consumers have access to.
In other words, which locks does the Lock Picking Lawyer himself use in his house to protect his family?
The Lock Picking Lawyer chronicled very nicely a technique for turning a KW1-keyed Kwikset core (extremely common here in the US) into something that is tamper evident. See the YouTube video linked herein.
https://www.youtube.com/watch?v=7JlgKCUqzA0
This kind of thing thwarts covert attack attempts and serves as a good way to trigger an audit on the trust of the asset behind that lock.
If you don't fear your front door will be clandestinely accessed, I feel it's perfectly valid not to worry about doing this to the lock there.
Not being you, that isn't my call to make.
The term for what you want is a "seal", not a lock.
You'd be driven mad trying to find what the intrusion was on your system.
>Then we moved on to attacking the firmware in each others keyboards.
In what world is hacking keyboard firmware easier than lockpicking?
And there were two - one on each side. What's more, it was a tubular lock, so if you were single-pin picking you'd have to pick it 5 times per rotation.
Nothing that would stand up to a battery powered angle grinder, of course.
$40 for tools designed to pick all pins at once and make a "key" with some quick impressioning motions.
Some do have spool pins. In those cases you will need manual fiddling to pick it once then you have a key to keep spinning.
Still, sounds like an interesting design. Link?
I looked for a picture of the case but couldn't find one. I was in that college CAD lab... quite a long time ago.
I taught everyone else involved to lockpick in the first place and chose locks well beyond any of our skill levels to pick.
One such effort features locks made by Stuff Made Here sent to Lock Picking Lawyer. According to LPL the locks are theoretically sound and he did not attempt to pick them, but these particular implementations had a couple (easily fixable) bypasses. Made for interesting videos on both sides:
Stuff Made Here describes the design in detail: TWO Unpickable (?) Locks for Lock Picking Lawyer! - https://www.youtube.com/watch?v=2A2NY29iQdI
Lock Picking Lawyer reviews them and performs some bypasses: [1299] Unpickable Locks From Stuff Made Here - https://www.youtube.com/watch?v=Ecy1FBdCRbQ
What the school did was run a steel cable behind the desks, then put a loop of the mouse chord through a steel washer and ran the security cable through all the loops. If you secure both ends you can’t get the cables separated even with slack.
The trick is that the hole in the washer had to be smaller than the connector so you couldn’t fish it back through no matter how much slack you get. That could still work for USB-A, but these days the connectors are getting smaller than the diameter of curvature of the cable, so you’d break it trying to do this. And on many peripherals you could destroy the chord without reducing the value of the device. One could cut the cable and install this Trojan one on many devices these days, the only telltale would be that the cable isn’t routed properly, which might be harder to notice immediately.
You can get a female/male versions of this connector placed on either side of an attiny85 for a quick solderless implant no one will ever see.
Then just undo 2 screws, plug your implant inside the mouse/keyboard, screw it back.
To make this harder intentionally strip the screws with a drill, understanding you will never be able to repair that unit again.
Or, y'know, open it up and solder the connecter together (or remove the connector and solder the cable wires directly).
But they’re right, these days when you crack open things you often find a connector soldered to the motherboard and the cable is merely plugged in. I think it’s just easier to manufacture. Pick and place, bulk solder and then a machine to plug in the cable, fast as you like, maybe with a loop in it as a poor man’s strain protector.
Well, if you're stealing them, you only need parts from one mouse: cut the cable close to the mouse, untangle it from whatever crap it's locked to, take mouse and cable home with you, disassemble mouse, feed cable back though (I think it's called) grommet, strip cable, pick out wires, solder wires to approriate mouse internals, reassemble mouse, done. You have a working mouse with only slightly shorter cable than before.
The point of using soldered cables for security is that setting up a soldering iron near a computer is conspicuous, so you get caught if try to install a attiny85 inside the mouse that way. You can still steal stuff just fine.
That's evil...
(Or do you know some way to strip the thread itself).
Or just epoxy the whole thing together.
That said I did make transparent and easily auditable USB type C condoms for one client that really wanted to use USB type C laptops.
Systems with security as a strong priority like the Librem 14 use barrel jacks for good reason.
I am in fact implying those that allow use of macbooks at coffee shops to directly access production systems at FAANG and fintech companies are taking a very inappropriate risk :-P
A tampered USB C to C cable on a conference room table can compromise people all day long.
If the USB C charge ports cut the data pins entirely then great, but I have not seen that be the case on any laptops yet.
It's crazy to me that this is true. Does the government pay Microsoft and Apple to keep it this way, or are they just negligent?
Keeping a whitelist of known keyboards and mice is really the only defence even on Linux, and unless you work in a data centre that’s probably way overkill.
With a home PC that doesn’t really work though, because in order to authenticate your mouse without some kind of central mouse log on a server you probably need to click a button, which you can’t do without authenticating your mouse.
As an attacker I just have the bootloaders of my malicious devices advertize the USB IDs of whitelisted devices like Apple Keyboards.
The computer has no way of knowing it is not authentic. There is no signing or certification for USB devices.
The only solution is a kernel that can place all newly attached USB devices in a queue for manual approval.
This is what USBGuard and QubesOS both do. The Linux kernel and udev have native support to hook USB devices early making this easy.
It means no one can drive by plug something in when your computer is locked. You will get a popup asking if you want to give some device other than the keyboard you booted with access to behave as a keyboard .
Also the majority of attacks I have seen in the wild attacking production systems were via endpoint compromises.
If your laptop has remote access to said high value datacenter, then your laptop is a high value target.
Note though that laptops have a nice advantage for this threat model as most have built in PS/2 trackpad and mouse which can let you approve external keyboards/mice etc.
Makes me think, what would happen if I plugged this cable, unplugged the keyboard, and power-cycled the computer? Or do a hard power down, then the switcheroo, and then power up? Would USBGuard/QubesOS block the new device, even though it's the one it just booted with?
(I think finding your computer rebooted would fly under the radar of most of the users - they'd blame it on automatic updates or intermittent power failure.)
On that note, I wonder how small you could go with a MITM device to attach between victim's peripheral and their computer. Could you pack enough useful features in a dongle that would not be immediately noticeable by most users?
It won't go unnoticed.
If your computer can reboot itself for updates that should be a cause for concern as it means your FDE is being cached somewhere that can use it unattended. I don't allow such things personally.
You do have to check for any untrusted USB devices at boot on a desktop. No getting around that one as you need to be able to use input devices at boot. Best bet is a PS/2 keyboard but those are getting harder to find.
For a laptop you have a better story as you can trust the internal PS/2 keyboard/mouse then use that to approve USB things fresh as needed and dictate what applications they get access to.
I connect my USB webcam to the one VM that needs it on demand, for instance.
Of course the reboot itself will be noticed when the user gets back - whether it's the login prompt, or boot prompt, or just all applications being closed. I meant it might not be noticed as something unusual, warranting further investigation. Typical user, even tech-savvy one, will just think, "must have been a power glitch", or "damn, those updates forced a reboot again".
The latter is something Windows users are conditioned for. Coming back from the toilet to be faced by a fresh login prompt is common enough even in the age of Windows 10 - and especially when the laptop is controlled by your employer, as IT tends to force a stricter schedule on updates[0]. In my case, this happens 1-2 times a week. While I'm working from home this doesn't matter, but if I were back in the office and came back from lunch to a rebooted computer, I would've assumed it was updates again.
> You do have to check for any untrusted USB devices at boot on a desktop. No getting around that one as you need to be able to use input devices at boot.
Makes sense, thanks for clarifying. I was assuming at least some of these solutions are trying to eliminate this requirement, but ultimately it may not be possible.
(Or perhaps it would be, if USB had something like HDCP so that you couldn't construct a dongle that could be transparently inserted between the computer and the peripheral.)
> For a laptop you have a better story
Right. Also, in case of attacker forcing reboot, they can't rely on users assuming it was a power glitch because laptops have batteries.
> I connect my USB webcam to the one VM that needs it on demand, for instance.
I need to read more about such setups, where you compartmentalize your system with VMs. Is there any good primer you could recommend?
--
[0] - I'm increasingly convinced Windows 10 update system is evil, and does this on purpose. It just so happens that it always forces an update and reboot on my work machine whenever I step away from it for more than 10 minutes. It's like it was monitoring idle time, and thinking "ooh, the user is away, let's reboot the machine and lose all the state". I also recently had to switch Lenovo updater malware to manual, because it kept choosing the exact middle of our weekly team meeting as the time to forcibly update video drivers, blanking my screen for anywhere between 2 and 20 minutes.
(Did I mention I hate automatic updates?)
Would it recognize the newly attached one, if you do the swap while the computer is turned off and they have the same HW ID?
Because if not, then it's not much better than what Windows lets you do with group policies. Although on Windows you could do this swap even while the OS is running.
https://www.amazon.com/PortaPow-3rd-Data-Blocker-Pack/dp/B00...
But it's a pain in the neck to always use them and difficult to enforce use in an enterprise setting.
I co-designed some transparent USB C ones for a client that are easy to audit.
Hope to take them to market some day.
There's much less discontent among the rank-and-file at Microsoft, so this sort of thing happens less with them.
[1] https://www.apple.com/business/docs/site/AAW_Platform_Securi...
I've got a couple of the units and can say they are working well and very easy to interface with.
Here’s a pic of the note card plugged into their Raspberry Pi note carrier. That’s a standard 40 pin 0.1” spacing connector on the left, so it’s 2” plus the mounting holes in that dimension. 65x57mm and about 20mm tall for the stackable 40 pin socket+pins.
Iceland: https://blues.io/blog/vacation-gps-asset-tracker/
Full Asset Tracking Project: https://www.hackster.io/paige-niedringhaus/low-code-gps-asse...
Adapting this for a car would be straightforward.
(Assuming even car thieves use iPhones there's some poetic justice to be served in their own smartphones bringing them down...)
what the hell?
Ah yes. This statement is more terrifying than Apples half-assed PR fireball a few days ago.
The same folks who bought iphones because its has better "privacy" than Android...
...are using iphones to track their kids whereabouts. It's like a dystopian punchline masked in the Friends laugh track.
I guess there are going to be scenarios where tracking could help and maybe even allow the kids freedom to roam within a large zone - the back paddock of a farm say - while still allowing parents to find them.
But I still like capability and trust more.
Professionals put the trackers in the kids' teeth, a la Spy Kids.
Says a guy who’s never had a friend or family member who’s been stalked.
Which is usually quite easy to check. It's not a guarantee, but with someone sophisticated enough to crack a modern car there's a good possibility they know to check the OBDII slot.
If they are sophisticated and have time to take the whole car apart then you are SOL anyway as they will find any transmitters with an SDR.
I have experience trying to get the cops to help in Oakland and San Jose and they really didn't want to.
A friend of mine got a motorcycle back by watching its movements via the gps tracking, and killing the engine while the guy was riding in a safe-ish and high visibility place, so the thief just parked it and walked away.
They don't work for you. They know they don't work for you.
The car got recovered by an asset management crew though and it went smoothly AFAIK.
Odd, this got me wondering, and I can’t find any reliable statistics that show a rise in car thefts. Everything I see shows a pretty steady decline over the past 30 years in spite of an increasing the number of cars on the road.
If you want to trust them I would have as much redundancy as you are comfortable paying for i.e. the software in these products is often dogshit so one failure or bug shouldn't let your car end in a scrap merchant.
- Keylogging
- Manipulate USB Power negotiation to cook your hardware
- Sniff traffic from other USB devices on the same internal hub.
- Log your location
- Log screen lock/unlock times/habits via voltage draw and permitted device type enumeration
- Install malware via keyboard emulation
- Sound exfiltration by emulating USB speakers
- Screenshot by emulating a USB/thunderbolt external monitor
- Mouse movement/click injection to prevent screen locking
- Exfiltrate data to hidden internal flash memory
There is also an editor and parser for Duckyscript – the scripting language used by the Rubber Ducky offensive USB drive – which acts as a virtual keyboard and launches keystroke injection attacks. That alone opens up a wide array of custom payloads for the O.MG cable. There also appear to be attack payloads for Windows and Ubuntu systems.
In April 2019, when the video was released, MG and the team of hackers working on the embedded cable were also developing extra functions such as detecting user activity/inactivity. According to the Hak5 listing, they also appear to have cracked another key problem: USB enumeration.
https://nakedsecurity.sophos.com/2019/10/02/omg-evil-lightni...
https://security.stackexchange.com/questions/118854/attacks-...
So spy tools that spy on the spys.
It is sketchy as all hell and should not be sold.
That said this stuff pops up everywhere.
I just cite it as examples.
Not true, at least for iPhone / iPad users:
- 1. Download Apple Configurator (free to anyone)
- 2. Create new config profile
- 3. Setup your device in "supervised" mode and apply said profile (the reason for this step is that the "best" config profile options are only available in supervised mode).
Config profile items of interest include, but may not be limited to: - "Allow USB accessories while device is locked"
- "Allow pairing with non-configurator hosts"
- "Allow putting into recovery mode from an unpaired device"You either ban USB devices entirely or you make users approve on every connection with no white listing.
> Screen Crab: This covert inline screen grabber sits between HDMI devices - like a computer and monitor, or console and television - to quietly capture screenshots. Perfect for sysadmins, pentesters and anyone wanting to record what's on a screen.
> Shark Jack: This portable network attack tool is a pentesters best friend optimized for social engineering engagements and opportunistic wired network auditing. Out-of-the-box it's armed with an ultra fast nmap payload, providing quick and easy network reconnaissance.
> Key Croc: The Key Croc by Hak5 is a keylogger armed with pentest tools, remote access and payloads that trigger multi-vector attacks when chosen keywords are typed. It's the ultimate key-logging pentest implant.
They say "pentesters." What prevents a malicious actor from buying and using these tools?
I think I am missing something here.
* enthusiasts
* professional security people (blue team, pentesters)
* criminals
in the last 2 cases, they buy them because it's cheaper than making it themself.
> What prevents a malicious actor from buying and using these tools?
Nothing.
What prevents any actor from buying <insert any items here> and using it maliciously? A significantly deeper question. I rather promote this.
I do not think there is a simple answer, but there is one out there...
When you can pick every lock around you it changes your worldview forever.
Kids should not avoid something wrong because they are physically stopped by a lock.
They should avoid it because it is wrong.
Better they learn these skills from someone that will teach the ethics to go with them.
I am surprised that selling tools which potentially "enable murder" hasn't triggered some overzealous regulator in DC yet. It seems like low-hanging fruit. /s
Pro-authoritarian sentiment keeps going strong. Why is it so normalized these days?
If you asked a reasonable person off the streets why bioweapons (like anthrax) should not be easily purchasable, they would completely agree and hence the legislature has made such things illegal.
But if you asked that same reasonable person off the street about miniature computers and electronic devices, they would probably not imagine that such uses are possible, nor would they deem it dangerous. They might even consider it useful! So legislation on such things cannot be set by societal expectations.
Cause nothing stopping you from buying any of that, at what looks like very reasonable rates.
It's not that most people want to hurt others. It's just that most people care only for themselves. Source: reality.
Now, we could quibble about whether people are more like to help you or victimize you and we could both be right. Or, we could observe that I'm correct about society functioning mostly because people don't mess with other people very much, you could chalk it up to friction and the lack of interest in others, and I will chalk it up to general back-ground good will.
As an example: a bowl of candy on Halloween with a “take 2 pieces only please” sign on it. Most people will only take 2. A few people will grab a handful. And one person will come along and take the whole bowl.
Therefore, the parent poster's argument is actually true, even if the median person believes themselves to be empathetic.
Edit: ever been at a long line for the bathroom at a big concert or sporting event? Or driven on the roads? There's always someone cheating, often making it more dangerous or painful to be that median person.
Without products like this you have criminals, a small amount of enthusiasts/researchers, and government sponsored actors exploiting vulnerabilities. If you put it out in the open, much like open source software, everyone can do it, but there's more pressure to fix blatant vulnerabilities.
I can’t protect myself from someone with a RubberDucky with a RubberDucky of my own. However, knowing that these tools exist and how easy they are to acquire and the ability to try one out for yourself might actually make you think twice about plugging that random cable or USB drive into your box.
It, for example, hasn’t resulted in accessible bulletproof vehicles for all.
In technology, vulnerabilities found push companies to develop and deploy protections for them.
The difference is most people know about those other things and don't know about the things that hak5 sells. They don't even know it's possible, let alone it exists and is usable.
Recently the lock picking lawyer got a USB drive lock in the mail and while he picked the lock, he refused the plug in the drive. People mocked him saying that he was silly for not simply plugging in the drive into a VM or special purpose computer. The next time around he brought out a USB Killer. https://www.youtube.com/watch?v=ctByXhte_-A ex: https://usbkill.com/ .
If you don't know a random cable or USB drive can be dangerous, you're likely to be the person who picks one up off the ground and uses it. Or worse, see one sitting unattended in a coffee shop or airport and decide you need a quick boost.
What's being sold is educational just as it is dangerous. Terrible people are going to find a way to do terrible things. The least you can do is educate yourself to make it harder for them.
I also make my own stuff like this from time to time. A lot of it is pretty easy. I could teach a class of people to make a badusb device from scratch, code and all, in an hour. Any USB capable microcontroller will do. Should we ban those too?
Bad actors have had more sophisticated hardware at their disposal for decades.
Just look at teardowns of credit card skimmers.
Hak5 is not helping those people. They are helping white hats catch up and helping spread awareness how easy this stuff is.
While your mind is adjusting to this, I encourage you to put "crown vic fleet keys" in Amazon and buy yourself keys to the police cars in your area.
The global state of security is a joke and we need people helping onboard whitehats to help teach people to do better.
edit: this was a joke and it got appropriately downvoted. I regret nothing.
Edit: wording.
Regardless, I'm not suggesting this at all. My point is that there are likely ways to get something worth so little without risking significant jail time.
https://crosscut.com/2019/10/whats-seattle-doing-solve-its-s...
About half blame not prosecuting crime.
But no one wonders. Everyone "knows".
- Dirty Mike & The Boys
Obligatory reference to the Seinfeld "The Smelly Car" episode (one of the few I've actually seen). [0]
Thankfully they didn't wreck the car or anything. Just laid the seat back.
"Then, in November, Boudin did something no San Francisco DA had done before: He charged a police officer with homicide, for the killing of an unarmed Black man in 2017"
so maybe you're going off a little half-cocked
Hilariously he actually got the stuff back eventually
I have a very messy car. Not rotting food messy, just a lot of clothes and things, often a lot of workout clothes, backup winter clothes, a couple blankets.
Thieves like clean cars. See target, break in, grab, leave. Messy cars are slow, annoying, and induce too much cognitive load.
If I lived in San Fran right now, I would have a shitty car with a lot of clothing in it just for the purposes of covering up things I don't want stolen and being annoying to thieves.
They stole:
* cheap sunglasses
* tire pressure gauge
* box of bandaids
* my car's USER MANUAL, ffs
* charging cable
They left:
* small envelope with $80 cash tucked under the removable console coin holder.
* all the coins.
So very confused.
All the stuff you mentioned was immediately visible (so no complex problem solving to find it) and would probably look "definitely probably valuable" to a hyped up 5 year old.
Aaaaand thennnn whoever did the stealing probably just sold it all to someone else in _exactly the same condition_ (high on whatever) who also considered it valuable enough to make a fair trade to swap it all for $amount of $thing.
I'm not sure what the balance is, but it's part-hilarious and part-sad that, if this theory is correct, there's an utterly illogical commodity market being sustained by tweaked-out squirrels with half the attention span of a goldfish, leaves people scratching their heads in its wake, and is so confusingly successful people just don't park in certain places.
I've been trying to build web/single page applications using new ES modules and no build tool, so all dependencies are pulled from their creator/CDN rather than bundled locally. Would this set off flags for a no-script user?
It was surreal to see them and even though I probably acted all nervous around them (still kinda had a crush on Shannon even after all these years) they were beyond nice and friendly.
They were super busy selling their kits (these OMG cables were being sold unofficially as well lol) but they took the time to chat about the history of Hak5(TechTV in the case of Patrick) and to take pics. All around a superb bunch of folks.
Its crazy to think they have been doing Hak5 for like what 15-16 years now?! So many great memories all thanks to their hard work.
Seems like they get a big chunk of their yearly revenue from Defcon sales. Makes sense as I bet a lot of hackers might just want to do an in person transaction and this is the perfect opportunity to do so.
chrome is now showing me a new "you added this to your cart" feature on my new tab page. it says i have added that product to my "cart".
that page is obviously doing something but i can't say anything evil.
For lack of a better use (just a hobby for me), i use a Screen Crap (https://shop.hak5.org/collections/sale/products/screen-crab) along with a Key Croc (https://shop.hak5.org/collections/sale/products/key-croc) for a poor mans KVM to my headless server :)
I don't know about the omg.lol page :)
I couldn't find much for parallel port hax (in 5 min googling), but I'm sure it's been done. Probably too old to be documented on the shallow web.
https://www.quora.com/Can-a-computer-be-hacked-through-a-PS-...
In the 1980's I worked with CAD/CAM software that required hardware dongles on parallel ports as an anti-piracy measure. That probably could have been exploitable: e.g., instead of returning the security response, cram a ton of data and cause buffer overrun on their 80286 + DOS5 application and smash the stack. It would be fun to go back in time and see just how vulnerable that software was.
I’m simultaneously impressed, curious and disturbed.
I also use my phone as my computers webcam. It's way better wired than the wifi for me (which honestly shouldn't be true, but).
I almost never use wireless charging, because it takes longer to charge, is everyday inefficient, and most people don't own wireless chargers. And even if they do, it's never in as many places as normal chargers. On an old phone, I ruined the port and had to only use wireless charging, and it was so annoying.
And app development is so much nicer when you have a USB connection. When I lost the ability to do so, coding was a good amount more work
I do wonder how thoroughly they vet their customers, and what silly things I could get up to with one.
https://stackoverflow.com/questions/2181476/bandwidth-from-h...
[1] DOWN THE RABBIT HOLE AND BACK OUT AGAIN: SERIAL OVER HEADPHONE JACK https://hackaday.com/2016/10/21/down-the-rabbit-hole-and-bac...
[2] A better audio jack console cable for Google Nexus devices http://www.pabr.org/consolejack/consolejack.en.html
"But the case is locked!" Are the peripherals? Even if the case connectors are locked away behind a bird-box/knockout, if someone left one of these dangling unplugged off of the keyboard, do you think your field technician won't unlock the box and plug it right back in?
Maybe this is on their todo list.
Man in the middle is hard to prevent when you need to be compatible with incredibly broken insecure legacy protocols.
Apple could maybe go the route that all new Apple keyboards only work with new Macs and iOS devices, but that would mean that they can't work with any existing Apple hardware or third party systems.
How much are you willing to bet that there's not a private exploit against newer iPhones? Not in terms of dollars, but in terms of private data that Apple's iPhone that you're renting from them has access to.
You could also do some passive/active data gathering. On Windows when you plug in an iOS device, if the device trusts the computer it will allow it to access all the photos and videos on the device. The cable it self could then start grabbing those images and sending them over the WiFi link. I don't know if these cables support that, but the concept is valid.
Its kind of cool to see someone I've been following for years and seeing the whole dev cycle of this product.
His exploding USB drive was pretty cool and came before this idea:
I have tried to make a cable like that in the past be the best I got was to hide the electronics in what looked like a bead. Unfortunately, this only really works with USB-B devices where users are already used to having beads on the cable which for practical purposes limits attacks to printers and older scanners.
Nowadays, with 2FA and all the big companies doing extra security check up when they see something wrong with the login patterns ... I don't see the use of keyloggers anymore.
Maybe in a couple more decades they will have begun to use basic defenses already available.
You know the content of all the emails this user writes. You know the websites they visit. Based on the 2FA auth key they use, you may find out what kind of system it is.
A great start for social engineering. The target user writes an email to someone and the day afterwards you can fake call them and pretend to be the recipient of the email (you have all the information). If you're lucky they wrote an email to management and now you can pass orders in this call.
One thing I've heard other comments mention here is a USB condom (USB data blocker). It's just a male to female adapter with only the power lines patched through, not data lines.
Not only do they allow safe use of Arbitrary power ports but they also allow me to charge my phone from my laptop without syncing for updating things…
Got any links for those?
I very obviously meant concrete brands and models that people would recommend.
I'm touched that you think I can't search for stuff on the net. :D
Synctstop and Int3.cc seem to be popular. The latter is recommended by Bruce Schneier here: https://www.schneier.com/blog/archives/2018/12/bad_consumer_...
0: https://www.alibaba.com/product-detail/3-in-1-cable-led-ligh...
I don't care much about quick charging when in a hotel room though. I just want to make sure my phone isn't being probed while I'm sleeping.
And when I need quick charging, I have the right cables and a strong external battery.
https://panic.com/blog/the-lightning-digital-av-adapter-surp...
To exfiltrate data by WiFi, there is a neat way to get data out... Just have the esp32 connect to all unencrypted WiFi networks in turn and send the data out via a DNS tunnel.
Then the attacker can provide their own WiFi network, but it will also work with airplane WiFi, cafe WiFi, guest networks, etc.
And obviously with DNS tunnelling it works against WiFi networks that require a 'sign in' after connection, even without signing in.
Unfortunately the only real legit use for it is boring security work.
The best way to use this while avoiding big legal trouble would be to stalk a single target that would never have any idea they are being stalked and doesn’t have much resources to come after you legally. Maybe an ex-girlfriend or something.
I remember in the early days of the web getting a copy of the Anarchist Cookbook. One idea was to glue the phosphorus material from a match stick to the spinning portion of a floppy disk. Of course that was a n00b level hack.
We've come a long way since then...
Couldn't find this information. If yes, you can just switch someones cable in his bag and attack him with that. We need to be very careful in the future with our cables...
Can someone explain what this is? Is it a hardware keylogger?
Simply a Male to Female USB adaptor with the data wires not passed through.
I did look into designing one a few years ago. The PD negotiation is quite complicated (and is done through the signaling lines, so you have to manipulate them yet block all other uses).
That was early days for USB C -- there may be better chip support for doing that today.
A decent USB-C condom would also have to cut not just the USB2 D+/D- line, but also the USB3 SS and SBU lines... the really interesting thing is the CC wires, since without these you can't have reversible connectors, but not cutting them leaves an avenue for attackers (e.g. putting an USB-C port into JTAG mode). And on top of that USB-C PD 1 used the Vbus line with an overlaid HF signal.
That means a decent USB-C condom will need:
- a low-pass on the Vbus line to block PD1
- cut D+/D-, SS, SBU
- cut CC1/CC2 and insert an as-dumb-as-possible controller chip to handle plug orientation
Power negotiation is also not a big problem. Just use a correct resistor on the CC pin and you can make the phone use up to 5V/3A, which is plenty for any smartphone. You'd have to make sure to use a 5V/15W capable power source, though.
... which precisely is something I cannot make sure on a device where I'm tempted to use a USB condom, and it won't be useful at all for laptops.
Security is inconvenient.
Had an entirely different image in mind.
I would also assume they are not paying enough attention to even notice, there is no regulation against them so there is no reason to even train to notice differences in USB cables.
> They probably see thousands of cables and it'd be pretty easy to spot the difference.
If anything seeing thousands of cables will make them less likely to notice anything, change blindness is a real problem in jobs like that.
The sheer volume of bags that get run through those x-ray machines in a shift, and the time given to look at each one precludes too much fine grained inspection, especially for something as minor as cables.
Airport security is pretty dismal at detecting actual weapons or contraband, why should they be any better at noticing a slightly different cable?
I don't think transport security people would care about any small tech stuff until something happens inflight because of it.
Such a classic tech podcast. So cool to see them still around.
This page pulls stuff off 44 domains!