FBI Warns Against Using Public USB Ports Due to Malware Risk
macrumors.com
macrumors.com
What are even the chances of this security "strategy" being successful?
I'd like to suggest a mental exercise here: Just imagine that every discipline (mechanical, medical, legal, electrical, ...) comes up with new rules to follow every month that interfere with everyday tasks that you have to perform (such as handling your bank account), but you only know about these rules when you actively research them and if you break a single rule, you are in danger of your possessions being taken away from you.
Affordability, convenience, security. Choose two.
It's not patronizing, it's how the consumer electronics market works and how consumers vote with their wallet.
Consumer device are sold with USB cables that pass data and power lines for cost and convenience, so they can also transfer data while also charging their device with the same cable that came in the box and not have them go out and buy another cable.
Can you imagine being sold a phone who's cable only passed power lines and not data, "for your own security"? The consumer confusion and outrage would be massive.
If your threat model seama it, the solution is buying a USB condom which only passe through the power lines, not the data ones.
Just like the internet and TCP-IP, USB was designed from the start to be as cheap and convenient as possible, before anything else, to get market traction, which it did. Security concerns came much later.
The reason why there's no physical hard disconnect available in settings comes back to what I said earlier, cost and convenience from the manufactures' perspective.
They don't want to spend 2 cents on some mosfets for HW disconnects, and they don't want to nag the user every time they plug in the phone to charge as that would hurt the UX. They want the device to sync up automagically to whatever device you're pugging it into. That's what USB was designed for, convenience.
Plus, if you nag the user every single time they plug in the USB with a security prompt, they will just get desensitized and instinctively click 'YES' all the time.
This whole thread is bizarre. A whole lot of fretting over an attack that nobody bothered to describe.
Which keystrokes are you talking about and on which OS does that attack work? I can't think of anything that would work on my iPhone.
I can imagine a phone sold with a readily accessible and highly visible physical toggle switch for power-only mode, giving consumers a discoverable built-in USB condom.
USB-condoms are a thing you know; average (and below) users know exactly what those do and can figure out how to use them in a few seconds. I bet if Apple's genius marketeers would come up with a catchy name (like the i-Safe, but cooler) those would easily sell at 3,000% the production cost. But they never will because they tarnish the brand, and make the users think their devices are not safe by default.
But then, if the device are indeed not safe by default... are we talking about criminal charges here? Would it be fraud, or what is the name of the crime where you knowingly sell hazardous stuff to the public?
But that fallback to 5 watts is still valuable in a hostile environment (which is, sadly, everywhere these days).
The cables are pervasive and most people won't consider their charging or data cables to be attack vectors.
$100 a pop.
> Transparent casing and zero electronic components inside so you can be sure the blocker itself is secure .. Since the pure data blocker has a zero-chip design principle, it doesn’t have the SmartCharge chip featured in our 3rd Gen design. This means charging speed may be slower with some combinations of device and charger. The blocker is not compatible with extra fast charging technologies such as ‘Qualcomm Quick Charge’ or ‘Samsung adaptive fast charge’ as these require data transfer to be enabled. Public USB chargers do not support these standards either so your device will charge as normal.
[1] https://www.kickstarter.com/projects/224386777/syncstop-prev... [2] https://twitter.com/SyncStop
Try charging a lithium battery without a microcontroller. Keep a fire extinguisher handy.
Anker GaN Prime Powercore if anyone’s curious.
Though, why not just use a 'USB condom'?
Fundamentally it’s just a USB-> USB connector with only the charging pin. Not a complicated device.
(Or carry a powerbank)
But seriously, connecting to arbitrary USB ports is very stupid on the list of stupid things to be doing. Just don't and find a regular power socket or bring your own power bank/laptop to charge from.
Not everything has to be grievous disagreements, aside from disagreeing with whoever first thought random USB ports in walls was a good idea.
(Why do USB cables last so poorly? I’ve never had an A to Micro-B cable last even a quarter of the spec’s minimum rated lifetime (10,000 insertion/removal cycles) before the Micro-B connector is uselessly unreliable, whether cheap or expensive—quite apart from the just-as-frequent failures at the clip/cable junction, like the ones I’m talking of here.)
> On Twitter, the Denver FBI office (via CNBC) said that public charging stations in hotels, airports, and shopping centers can be a malware attack vector.
Those might also qualify to some extent as "public USB port", although strange USB devices are obviously a well known security risk at this point (I hope).