The Google plasma globe affair of 2012
lcamtuf.coredump.cx
lcamtuf.coredump.cx
Reporting multiple keys down in the same packet is meant to be used for when the user actually has those keys down simultaneously, so it's not unusual that MacOS decided to act on them in order of scan code, because the expected effect would be the same.
Fixing it isn't trivial, but it's hardly insurmountable. The solution is fairly simple: Whenever a new keyboard is plugged in or types its first keystroke, lock the screen, and don't accept key input to places other than the login form from a new keyboard until that keyboard has typed the user's login password. (You also need to build a way to authorize legit-fake-keyboard devices like barcode scanners that type the barcodes they scan, but that's not to difficult.)
Given the high prevalence of USB devices with infectable firmwares, and the large number of USB cables of questionable provenance that no one pays much attention to, it doesn't seem okay to leave this vulnerability open.
RHEL7+ include USBGuard as part of the standard repo [0]
[0] https://access.redhat.com/documentation/en-us/red_hat_enterp...
I don't know the answer to this, so I'll ask. Can USB ports be programmed to only output voltage but not data? If so, this seems like a cool way to implement the above as you can have Deny, Access (power), Access (data) as options.
On Linux GNOME already has USBGuard support btw.
I was imagining this being in some advanced setting with a "here be dragons" warning. Or even a bit more relaxed like Firefox's strict or custom tracking protection. It comes with warnings and I feel pretty confident to say that most users don't touch these settings.
> On Linux GNOME already has USBGuard support btw.
Yeah I know there are plenty of hardening tools out there, but I was suggesting that they come pre-installed. There's so much bloatware on most systems these days that this seems minor. Or maybe someone could put together a bundling script to make adding all this (e.g. USBGuard + Fail2Ban + Faillock + Firejail + etc) easy to install and configure. I'm not aware of any such tool. But maybe even an Ansible script could go a long way.
That just leaves most users unprotected.
> I was suggesting that they come pre-installed
GNOME's support for USBGuard is installed by default, but USBGuard itself may not be depending on the distro. Agreed that it and other security/safety/robustness (for eg SMART disk warnings need to be supported) stuff (should be enabled by default. GNOME should use Flatpak-style sandboxing for natively installed apps too.
Aren't these users already unprotected? I don't think this is a security concern for most people and turning on by default would frustrate them more. It'd be like shipping Firefox or Chrome with NoScript on my default. Sure, more protection, but it would turn away more people than it would pull in. Better as optional.
Maybe require the user to type a random combination of keys shown on the screen before enabling a given input device, instead of their own password?
If you could type it on any device, and you could guarantee that the OS could remember that device, I could see that being workable.
I would also worry about:
Ensuring that the keys shown bit is properly accessible to screen readers/braile devices, etc.
Ensuring that automation could authorise a device, or disable the prompt requirements
Ensuring that the OS actually remembered it. Plugging into different docks at home/work/conference room and having it prompt you to re-authorise your keyboard would drive people up the wall. eg: because during USB Enumeration the port numbers on your dock got switched, or they plugged the dock into the other side of their computer, or the Wireless USB controller is slow at starting up.
How to handle an unauthorised device when there's no other usable input devices. eg I started up my HTPC, and a few seconds later the IR receiver wakes up and is now marked as unauthorised - the device may not have a keyboard but that receiver appears as one. Or maybe I'm trying to fix a laptop and the on-board keyboard is broken, so how do I plug in a USB keyboard to get at the data on it (Maybe I can't reboot)
Some of these things might conflict with having such a lockout.
The alternative methods looking at the time between keystrokes seems more reliable.
In an ideal world, vendors would actually populate the serial number field with a number that's at least semi-random.
On this computer, only the USB-C HDMI adapter and the fingerprint reader have a serial number that looks random :-(
(I kept triggering it by accident, and disabled it.)
1. If this is what a couple of smart guys can do as, essentially, a side project then I can only imagine what nation states with teams of people like this can accomplish.
2. I get why some orgs pour wax into the USB ports of their desktop machines.
However, I think the FAANG companies act somewhat more restricted. Three letter agencies don't have qualms about things like "chloroforming security guards" and such.
Also, use USB Data Blocker dongles where possible.
Citations:
https://apply.intelligencecareers.gov/job-description/119486...
Cyber Mitigations Analyst/System Vulnerability Analyst - Entry to Expert Level (Maryland)
Network Cyber Mitigations Engineers and System Vulnerability Analysts analyze vulnerabilities and develop mitigations to strengthen defenses. They produce formal and informal reports, briefings, and guidance to defend against attacks against network infrastructure devices or systems. NSA analysts' competencies run the gamut of data transport possibilities. They work with traditional wired networks, wireless transport, including Wi-Fi and cellular, collaborative platforms such as video teleconferencing, and the hardware and software that support it all.
Pay Plan: GG, Grade: 07/1 to 15/10
https://www.opm.gov/policy-data-oversight/pay-leave/salaries...
In a very high cost of living area, that means that entry level is $31K and the absolute top for expert level is $176,300.
Compare that to what FAMG are paying new college grads.
Or "I'm a covert foreign asset, so I DGAF what I get paid."
> The CTMS [Cybersecurity Talent Management System] salary range has an upper limit of the vice president's salary ($255,800 in 2021), plus an extended range for use in limited circumstances, which has an upper limit of $332,100 in 2021.
https://www.zdnet.com/article/the-us-government-just-launche...
To be honest, I liked hanging out with them more when they couldn't talk about work :)
But budget limited ingenuity is fun too!
First paragraph of the article:
> In episode #3, Daniel Fabian talks about the redteaming efforts - and in particular, about an exercise he and I ran together as a side project back in 2012:
But...this sort of hack is around two decades old and doesn't represent anything new in the field. There are at least a dozen toolkits one can use to implement this on a number of USB-friendly microcontrollers.
I would expect someone working for Google's red team to be able to bang this device out, from scratch, in one day.
Google probably spent more on the voice actor and graphics for the video.
A nefarious plasma globe could hide of lot of nasty stuff, you don’t even need to plug it in via USB to cause harm.
For the same reason, waiting a few minutes to pop up the shell, as the article says they did, actually seems counterproductive. It might have been better to pop up the window intentionally -- launch the browser to display an ad from the company that made the gadget, maybe, or a 'user's manual', or something like that. Something that would appear innocuous and expected, while providing cover for the payload.
However, if this happened on my Mac I would immediately be skeptical.
What does the software do? I assume it asks for permission and you decline? In a couple of decades of buying USB keyboards I have never let one install software and I have never noticed any problems.
I'm a bit put out that that worked, although I'm struggling to think of a solution that doesn't involve going full-crypto (including a proper PKI to let vendors sign devices) on all USB devices. But if anyone can set any vendor+product ID, it's not really a useful security measure.
Turned out I could click on controls before they were even drawn on the screen for super-human speed.
I’ve encountered some interesting situations where clicking and hitting a mouse’s scroll wheel would scroll the point of focus on the next screen…
Although it sounds much less exciting, this sounds like a much more serious exploit than a compromised USB plasma globe - embedded in an image and requiring minimal user interaction to execute. I wonder whether they identified a novel 0day in a common image parser or something.
I’m guessing the documentary just glossed over it for brevity.
Slowly populate a script with contents so that instead of writing a lot of characters that a user might see, just populate a few.
I guess it uses heuristics to determine if a device is evil, and that could cause a lot of false positives (which would create spurious bug reports and support cases for distro maintainers), so maybe having something like that installed and running by default isn't a great idea.
https://www.cdc.gov/vitalsigns/motor-vehicle-safety/index.ht...
But...it's not weird, it's part of Gogole marketing's altruistic spin on this as "we're protecting everyone!"
Did anyone else notice that they very quickly glossed over "our red team isn't allowed to go after any user data"?
That's like saying "don't worry, our bank's red team isn't allowed to try and go after money."
The red team is only intended to protect their corporate IP/trade secrets and dirty laundry.
We used to be able to make (I think you could buy it too) PS/2 keyboards or dongles/warts/mitm devices that did this. The attacker interface was a bit more cumbersome, but ultimately did the same thing.
That means an attacker would need to add a wait to risk losing half the payload to the launch animation or whatever causes the delay, and doing it invisibly would be entirely impossible.
The fact that they hit the MacOS keyboard wizard shows that apparently nobody on their team had experience with such a basic, ages-old technique.