FBI is warning people against using public phone-charging stations
schneier.com
schneier.com
Perhaps here on HN. Most people will plug their smartphone into any accepting receptacle. trains, airplanes, NYC SmartLink, or ask the bartender if they can plug it in behind the bar.
I still carry a DIY Altoids charger that takes a 9V battery (pulled down to proper volts for iPhone). In a battery emergency, my phone is simply on life support and I don't have to look for outlets that might also include a zero-day.
I'm with you, this might fall under "safe". Then again, from threads posted here and elsewhere, and through personal investigation...the infotainment systems on airplanes are an absolute disaster with regards to security and software design. They're often part of the same system as the provided USB ports. While the risk is small, there's nothing stopping 1 person from running a script that exploits some flaw in the outdated Linux distro the airline is using to manage their in-flight entertainment.
There's also a chance I'm paranoid and spend too much time here, but I'm gonna stick with my Altoids.
Sometimes I just want to charge my phone from my laptop without triggering all kinds of finder and iTunes and photos interactions.
Same with a car - just power, please.
(Though, yeah, I'd avoid a lot of "normal" activities if I ever attended BlackHat.)
[autorun]
open=you_didnt_read_the_brochure_right.exe
icon=setup.exe,0
label=My install CDLeaving USB sticks lying around with some sort of callback to see who plugs them in is a really clever idea. We could probably catch the serial number range in Defender ATP.
In all seriousness though - 128gb usb 3.0 drives can be picked up for $10 on sale all day long. Absolutely no reason to trust some $0.25 random 4gb that a stranger gave you aside from running R-studio on it for fun or something.
I wonder whether you‘d take similar precautions on a site named Hacker News
perhaps hacker news is merely a conversation prompt aggregator
So you can’t trust any site for power.
—-
Although teleporting power Via quantum entanglement has been demonstrated as possible given a line of communication.
So crazily, “power over data” may happen one day.
Perhaps, we can all look forward to hackers draining our last 1% of battery power as a reward for not using end-to-end power encryption.
I know I largely do, but perhaps that’s unwise, especially given the site’s stated target audience
Wait till someone reprograms that arduino plugged into your USB via webUSB to be a HID device to do their bidding !
This is the solution to that problem:
https://www.amazon.com/PortaPow-3rd-Data-Blocker-Pack/dp/B00...
https://www.amazon.com/PortaPow-NA-USB-C-Data-Blocker/dp/B08...
https://www.amazon.com/PortaPow-Data-Blocker-USB-C-Converter...
I charged me phone, fully aware of these sorts of issues. I just went with my gut instinct that, in that environment, it's highly unlikely that the cables have been "trojanized".
The FBI can warn about it, but what can you really do? You just have to trust your judgement as to what you feel are safe charging stations, and which may not be.
Get a USB condom, for instance, practice safer charging. :)
https://www.zdnet.com/article/protect-your-data-with-a-usb-c...
https://lifehacker.com/use-a-usb-condom-to-protect-your-devi...
[1] https://needgap.com/problems/73-usb-type-c-condom-usb-cybers...
Oh, I didn't know that! So what is the solution for USB-C? How do the new USB condoms work?
I think its possible to disable the USB 'protocol' in Linux, but it would require advanced permissions on android, which probably doesn't work out of the box, with IOS who knows or cares.
Yes, exactly. There are some comments here in the thread that discuss this in detail.
I bought like 5 of these, threw them in my bags and luggage, and I don't worry about charging like ever. And my devices charge fast.
If I'm doing long flights, I generally bring a single power brick.
Maybe with USB you could get away by using a cable without data pins, but I'm not sure whether that may influence charging speed given USB-C is pretty flexible.
I’d like to just rely on my device to protect me by asking if I want to trust the device.
I'll never be able to bring up this risk with USB to those guys.
Edit: IoC typo -> IoT
Though apparently the "Internet of Cows" is something.
Do we know of a single real-world use of this hypothetical exploit? Do we know that iOS's (and presumably Android's) protection against untrusted device access isn't enough?
So, is it plausible a malicious charging station could gain root and sideload something nefarious on an iPhone? Absolutely. Particularly for non-tech-savvy folks desperate to get a charge before their connecting flight...
Has it happened? ...No idea. I guess that's where the anecdotes come in...
My general point about how easy it can be to maliciously root someone's device stands, so I will leave my comment as-is.
Folks - don't plug your devices into untrusted USB ports...
And yes, in the past many iOS jailbreaks were shockingly simple. The website one in particular - you went to a URL and clicked a button... your phone rebooted and was jailbroken.
The popup really should be a toggle somewhere in the settings that forces a user to explicitly enable data - not a popup users are mostly self-trained into ignoring.
Additionally, real charging stations should not offer cables with data lines at all.
More details?
1. The station has to be using USB Ports / Charging cables that are data enabled, not just cables that carry power
2. The hacker would need some way of injecting the malware into the charging station ports without being seen, I doubt many charging stations are internet connected so you would have to be at the device.
3. You need to have an active exploit for iOS or Android (or both) that will compromise the device and steal it's data.
It just seems like alot of work for something that in all likelyhood would not work.
> 1. The station has to be using USB Ports / Charging cables that are data enabled, not just cables that carry power
Doesn't matter, because you're (unwittingly) plugging into the attacker's device, not the station's.
> 2. The hacker would need some way of injecting the malware into the charging station ports without being seen, I doubt many charging stations are internet connected so you would have to be at the device.
You don't need to "inject" anything; you just need to physically place it between the user and the actual port and disguise it enough that people not paying attention won't notice. Or even just put a fake "charging station" in a place that the station didn't have one.
> 3. You need to have an active exploit for iOS or Android (or both) that will compromise the device and steal it's data.
People are plugging in their phone so they can use it. They'll plug in the phone, unlock it, and browse the internet. What can't you do in that situation?
iOS devices (maybe Android too, idk) ask you if you want to allow new accessories to access your device. That's why they said you need an exploit.
Anyone who would believe a notice like that (or would click trust without thinking) is a prime target.
It’s like many scam/spam emails- they often intentionally look a bit dubious, poor grammar, typos etc as the attacker just wants to deal with low hanging fruit, not someone who may wise up quickly that something isn’t right.
Even better, here's [2] a direct example of this attack using an O.MG cable [3].
[1] https://youtu.be/COndab_rQkE?t=76
If not an exploit, you need the victim to do something a lot more obviously (though the absolute obviousness of course remains debatable) dumb/risky than merely plug in.
Using your own power adapter and own power cable you will be fine.
Unless someone has tampered with either of them while you were distracted momentarily but that’s too high risk/inconvenient for an attacker for you to worry about.
I have never heard about a non-government sponsored attacker doing that kind of thing. If this is relevant or not to you, it's a matter of your threat model. If I were a journalist, I would be very weary. Personally, I don't plug my phone on random outlets and don't plug random devices on my computers, but it's clearly an overreaction.
(And no, I've never been to DEFCON. It really became famous.)
I suppose the difference is that people may be using the cable to connect to a device where that prompt is expected, in contrast to the "charging port in an airport" scenario where it would seem appropriately alarming.
I think the risk is insanely low for your average person because you'd have to use an unpatched bug on a well-supported system, you'd have to put bug a USB port in a popular place, and you'd need a reason to do all that.
But at the same time, this is well in the wheelhouse and capability of some bored teen with a lot of time who wants to screw with people FWIW. You could also have fun and write a worm that infects everyone that connect to your USB port and have it DDoS a website or something. The first worms were created by bored people.
Most devices are charge-only by default, most users have USB debugging disabled, and those who know how to enable it, won't allow the adb server to connect to the phone (you have to explicitly give it permission).
Physical security is also a consideration, I wouldn't really suggest that people leave their phones plugged into the wall in a public or semi-public place.
It turns out several generations of USB controllers did "undefined" things when presented with "undefined" behavior on the data pins. Sometimes "undefined" was "just doesn't work", sometimes it was "put data in physical memory, bypassing the MMU and it's data protection features."
I've never seen it myself, but I worry someone out there has figured out how to do the same thing over the power lines.
Okay, but tell me how it can be done if you want me to take the threat seriously. You could also say “always store your phone in a sound-isolating container because attackers can hack your phone with ultrasonics.”
That is not a precautionary attitude. I don't know how a candle left unattended in the middle of my granite counter island could light anything on fire, there aren't any drapes near it, but I'm not going to leave it unattended so I can find out.
Ask that your average parent using an Android 6 from a decade ago, not being able to update because the manufacturer decided to not support their devices anymore after a year.
There is no such thing as an updateable Android, because something will always be outdated. Even lineageOS builds are using decades old kernels and kernel mods that have never been backported or upstreamed.
Android has a huge update problem. I'd probably bet that stagefright or, say, the pegasus zeroday for whatsapp works still on a large percentage of devices even though it was leaked more than 5 years ago.
"Can't install this shady pirated software you got from a malware-adjacent site? Try disabling your antivirus!"
See also: the Bonobo JTAG/SWD debugging cable over Lightning. https://shop.lambdaconcept.com/home/37-bonobo-debug-cable.ht...
(While this 'technically' requires extra device flags, it's still the fact that Lightning has lots of hidden modes underneath its multiplexer.)
Back when I used android, it was much more common that runaway apps would drain my phone in 2 hours. But now? Doing a anker battery would be lugging around a bunch of dead weight.
Basically, the phone’s battery life depends on disabling hardware components, or running them in a low power mode, as much as possible.
Modern GPS chips only need around 25mW apparently - older chips can pull 100mW though. Scanning needs a bit more power than tracking.
On phones I think the problem mainly is that the GPS needs to wake up an app that need to handle the GPS data and then do some calculations. You can easily get data ten times a second that is alot of wake up from sleep, and probably draws lots of CPU.
I think most of the drain comes from that rather than the GPS unit itself. But people might say "using my phone's GPS uses a lot of battery."
If you want data safety, you must skip the data pins.
If you want current safety, you must skip public chargers.
USB is a very intelligent protocol, with a microcontrollor on both ends. The controller has access to at least the driver's state, which is usually in the kernel and potentially has access to system memory.
How does your Android phone even know that data is an option to switch into when you plug it into a USB port? It has already negotiated itself to be a device on the USB bus. Your phone will probably show up in lsusb on Linux even in charging mode. (Mine does.) When you switch the phone to data mode, it changes its USB device profile, and becomes a more sophisticated attached device, from the host's perspective.
Many (most?) phones made in recent years can be USB hosts, too. This lets you connect a USB mouse and keyboard to a tablet, for example. That would open you up to all kinds of pretty simple but often quite effective attacks, like simulating a virtual keyboard and mouse and just manipulating the UI that way.
I don't know if any of these particular attacks are possible with Android right now, but many variations on these themes have been shown over the years on many platforms. USB wasn't really designed with adversarial peripherals in mind.
Not "sharing data" doesn't really mean not sharing data.
The sibling comment above is an excellent example of why you might specifically target public infrastructure if you only really care about one person.
Many people would use them, assuming they were just mis-shipped or ordered by their spouse.
If I were on the standards committee, I would have made every pin interchangeable - ie. any pin can be gnd, any pin can be Vbus, any pin for data, etc. When plugged in, the device on the end would test every pin, and then decide which to use for data and which to use for power.
That way, when a cable gets a bit old and 3 out of 30 pins are shorted or dirty or otherwise bad, the cable works but simply delivers 90% of the power it used to.
The absolute cheapest cables could have just 2 pins, and would be slow and low power, but still fully 'working'.
This wouldn't have added much cost to most devices either - most devices have a dedicated IC for USB functionality, and that IC can deal with muxing signals and power. On devices which only take power, a simple array of diodes can take power from any pin. Data signals could be capacitively coupled, meaning the muxing could be done on a single chip without needing special high voltage silicon processes (the cost of a chip goes up a lot as soon as you want it to deal with high voltages on any pin).
You can buy stamps from a vending machine with cash.
That’s all assuming the bad port wouldn’t have been removed, and video might just show regular “maintenance.”
Yeah, it’s all above and beyond, but I think it’s in the realm of possibility for a high level target (see: stuxnet et al)
Sure, you would be leaving evidence, but if your plan works, that evidence won't be sought out anyway.
If you sent a mysterious package, it wouldn't be strange or out-of-character for someone to investigate that package intentionally: which presents a significant attack surface for the discovery of your ruse.
You're a decently high-capacity Chinese factory that makes custom USB outlets. You make a "special" line with a zero-day chip or firmware inline with a cable. The cable only needs to be a little fatter to accommodate some unobtrusive electronics. They are slid under the insulation and there is no dedicated PCB that may attract scrutiny.
You wait until the order comes in for the site(s) you wish to target, and you ship them off.
The countermove to this, of course, is that the installer does a fuzz test of the charging station with a few common devices, trying to tickle the bug, and also a protocol analyzer that will inspect the USB data stream for anything out of the ordinary.
My armchair quarterback mind says that the above security testing should be fairly effective if you are dealing with a low-level adversary. A state-sponsored one with sufficiently large enough state would not be hindered by puny countermeasures like that, and would be able to target more accurately.
Here's another countermeasure on the consumer level: optocoupling. This is good to mitigate voltage and amperage damage, even accidental or unintentional types. I suppose it would prevent charging too, but there's got to be something useful about it.
https://www.eff.org/deeplinks/2019/09/watering-holes-and-mil...
(It still infected untargeted PCs, and might have caused them to misbehave, but not intentionally. Stuxnet was designed for stealth, not for mass exploitation. You the average PC owner has very little to fear from such targeted attacks, you're not worth the 0days.)
If you're just passively collecting data and hoping to land 'a' executive or someone else in business with access to power and/or money, or can be used to pivot to someone else, I think it'd be an effective tool.
MSB would define 2 connectors: a data connector and a power connector.
MSB would also specify that if you have both data and power connectors they should be physically laid out in data/power pairs and would define the spacing/positioning (e.g., the power connector should be parallel to the data connector 2 mm apart with the power connector above the data connector).
The idea behind the layout specification is that for applications that need both the power and data connectors you could make cables that include both, with the housing at the ends holding the two connectors fixed so they can treated as a unit when it comes to plugging into things.
The power port would include data line, but they are just used for power negotiation.
The data port would include power, but just a fixed voltage and max current, comparable to pre-high power USB, so for low power peripherals you would just need to use a data port. I.e., for low power peripherals it is pretty much just like USB.
Anyway, the world will be worse place with just incremental incompatible tweaks to the so-called "universal" connectors so that they're never universal because of churn. Hopefully USB-C is the end of the line forever, whatever its flaws might be.
Why doesn't my device today have an option that allows me to set the USB port to "power only"?
That setting does not work the way you think it does.
That's a purely software issue, though, and actually easier to solve on phones (with built-in display+input) than on PCs (how to trust a keyboard/mouse without having keyboard/mouse to input approval with?).
I know, that's why I'm so annoyed! And Android is already half-way there; they've already acknowledged that I should be able to control how my phone interacts over USB with a PC, now all that's left is a proactive control that sets the mode for the USB port globally instead of asking my preference in reaction to a device being connected.
>and actually easier to solve on phones (with built-in display+input) than on PCs (how to trust a keyboard/mouse without having keyboard/mouse to input approval with?).
I feel like PCs are less of an issue; I'm not out with my PC at a coffee shop or bus station when suddenly I'm tempted to use the publicly available USB keyboard. At least to me phones and tablets seem like the problematic devices here since charging them (with a wire at least) necessitates connecting them via USB.
I don't have those; I just charge my portable battery first and then charge my devices from the battery.
An alternative is also a power only USB cable, just because I feel like I'm less likely to lose a whole cable than a "condom".
It's unclear to me what this means. I thought it works like this:
- Connect battery pack to USB port - USB port tries to hack the battery pack, but it's too dumb, so the attempt goes nowhere. The charge flows nicely, though. - Disconnect battery pack from USB port - Connect device to battery pack
Are you certain it is?
I, like you, charge a portable battery that can refill my phone 2-3x without issue.
I have one of these. I like that I can look in it and see that it has no data pins
> Wireless
I know you meant charging, but for data, with some of the spy cables out there with embedded chips and wireless access, it's ironic that wireless is in some ways more secure.
When people decided to use USB for everything, well, they had to make USB support every use case.
No. Not even close.
https://www.zdnet.com/article/protect-your-data-with-a-usb-c...
i distinctly remember making usb condoms a long time ago, anyway, and have never trusted public usb slots anyway.
Another fun toy is the USB Gadget Kernel module. I've been running yolo + mouse/keyboard emulation on a raspberry pi to make horrible aim bots.
And it seems to charge quick enough (albeit never timed it)...
The way the charger and the device agree on how much power the charger should supply involves the data lines.
Thus, if you simply drill out the data lines leaving just the power lines as the person a few comments up suggested a properly functioning high power charger will see your device as only supporting the original USB power spec.
I suspect that those things you linked to are active USB devices. The USB port on the charge side has the data lines connected and uses them to negotiate high power from the charger. The USB port on the device side similarly has the data lines connected and uses them to negotiate high power with the device.
It protects the device because the data lines on the charger side are not connected to the data lines on the device side.
or so we hope
A 24-pin “serial bus” might be getting a little crazy.
Also, you can just put the 'correct' data connections on the phone side (keeping data disconnected on the charger side) and pull up to 5V-3A, no problem assuming the charger can handle it.
But realistically, a battery bank seems like an even better solution than a dedicated "USB condom"; it'll even protect you from "USB killer" attacks that inject high voltage to the ports, by frying just the power bank not the real device.
It's more bulky than just a dedicated cable, though.
We know (I think?) attackers can apparently easily introduce MitM skimmers to credit card swipers (I _think_ that's how my CC number keeps getting stolen?), possibly even without cooperation of the proprietor? Why not a little invisible injector on a charging port, that seems if anything easier.
Or is the skepticism around something else, I guess? Motivation? Lack of consistency over time of attack vectors around software injection via USB making it hard to commodify the attack? Like, there are only temporary zero days now and then which get patched, so this isn't a "cheap" thing to deploy on a wide scale?
[edit no idea why i'm getting downvoted on this, perhaps I didn't write it right but I'm legit just curious to hear people's takes on this, what reasons he might have been thinking of to not worry about this...]
And immediately after he says he's unconvinced this is a concern, he states that he does, in fact, carry a tool with him that would protect him in these circumstances.
I'm not sure if "find suspicious" is a good heuristic here. Although of course we don't know what he bases his suspicion on.
https://www.amazon.com/Databloc-Charge-Only-Adapter-syncing-...
Most users, most of the time, will trade speed for security.
This is also assuming that your powerbank can’t be hacked. In which case, god save us all.
https://reincubate.com/support/how-to/pair-lock-supervise-ip...
Anytime I am on an public wifi or untrusted network (including the occaisonal time at my job with a personal device), i connect to that. Since its 443, its generally not blocked, even through the TLS connection is not "standard" because it uses a 2048 bit PSK to as a pre-cursor to start a connection, then a certificate based auth to establish the tunnel.
Its a full tunnel as well so all traffic runs through it. Google/Youtube will sometimes pitch fits and make me do captchas but otherwise its an easier way to shield from stuff like that.
All the wifi provider sees in that case is a single connection to my linode.
Admittedly this is a pretty technical solution though and requires some configuring. Mullvad would probably be an easier option with plenty of endpoints to jump through. Or you can run Tailscale and use SSH/socks proxies, though things like DNS leakage can still occur there.
I will use SSH tunnels and socks proxies for certain browsers that are configured to not store any data locally as well (ie: Firefox). I justify it easily in that I am constantly testing services and sometimes its best to rule out routing, BGP or other low level network issues and using ssh -D 12345 somethign@someplace allows me to do just that in isolated circumstances.
Point is, port 443 isn’t really the best way if you dont want to be blocked.
You may want to consider stunnel if this ever becomes a problem for you.
The issue is many will simply block UDP or the default port 1194 or basically anything other than a handful of outbound ports, of which 443 outbound is almost never actually blocked for obvious reasons. In fact I cant think of a single time I havent been able to use that VPN, even when my normal road-warrior profile to my house IS blocked.
Either way there are ways are ways to mask the fact that its clearly OpenVPN that if your issue is nation-states or things like the Great Firewall like Obfsproxy, but even then, something like Mullvad would be called for since you are likely going to need an array of endpoints.
Im just trying to ensure my traffic is running through a trusted source until the point that its supposed to him the open internet. Things like DNS filtering are getting more pervasive. For me that means I want to know the endpoint until I am ready for it to egress.
I have also had this setup for years at this point. Before tailscale or even hearing of things like mullvad. But I work in IT, so its one of those things that makes others that dont work in tech look at me funny if they see it.
sites are protected not only wity TLS but also HSTS and the list goes on.
Wi-Fi doesn't include sturdy security mecanisms anyway, so wifi is never safe.
Companies that are serious about network security are recommended to use a second factor, like a VPN, especially on their company network (because they always have ressources that lack protection)
For customers and individuals like us, sites are safe enough not to do that (unless you host your own services)
So the only thing PPL can do on public networks is maybe fingerprinting, and tracking the whereabouts of your devices accross the place (Especially in airports like Istanbul where you need to swipe your passport in a machine to get a wifi code)
But that doesn't prevent me from going to Discord and HN and do banking over public networks.
HSTS is just what says for the browser not even try HTTP connection, but directly HTTPS.
ie when a MITM is attempting to drop you back to insecure.
if HSTS is implemented properly, it won't just report an error, but it will also forbid any connection.
For example, on Firefox, you can't bypass an HSTS error. The browser won't let you add an exception to connect to the site. (you have to purge your data to connect again 'for the first time' on the site)
Yeah, people usually have the opposite problem. You just search for power-only cable.
> how can I verify
Plug it into your phone and your computer. None should see the other, but the phone should charge.
And then tag it, because having all kinds of cables exactly alike is the worst decision the USB designers ever made.
It's not charging - but maybe it was just a problem with that port on your laptop. Better try the charger in every one of your laptop's USB-C ports, just in case....
Meanwhile my downloads came with none of those warnings.
Though I always have a power bank on hand, not for security, but for convenience. Much more preferable to the physical limitations of a wall outlet.
real usage per second, per minute, not theoretical
can the charging stations resume data transfer if i unplug and replug at random times ?
i dunno, when i want to dump gb of data from my phone, it takes hours ... so yeah maybe i should stay at a random charging station for hours to ensure all data transfered :D
I don’t know much about USB, but I’d imagine that only the power delivery pins are connected to anything, right?
Second, I'm still waiting to see a QI charger than just pumps 100W of power straight through any piece of metal above it. Don't know what would happen, but I naively imagine forced induction would brick most devices.
A charger so good it's the last time you'll need to charge
USB requires an active action. Blaming the user is still wrong, it really should be safe to charge in a mall or get a file from your friends usb stick. But it's less obvious so here we are.
I am not sure how many places properly accept non authentified (no phone unlock nor biometrics) contactless transaction in the US, but it's a thing at least in Japan.
I'd also assume the non secure area is readable without any unlock either way, but might be wrong.
This advice has been standard in cybersecurity training for a long time now and frankly I'm surprised that this is the first time the FBI has felt the need to issue an advisory on the subject.
The design of CCS2 is actually quite nice. There are pins for singalling that, if broken, will immediately shut down power delivery. This means that you can just pull the cable out safely, without risking arcing or electrocuting yourself.
I've not seen this on AC, but when I looked into this previously I got the impression that there exists a digital signalling protocol established by modulating something ignored by older cars and chargers that can be optionally supported. If that's the case then there's potentially attack surface there, too.
but yeah, public charging stations *for phones* are terrible.
I used one of them once at a conference, with ADB enabled on my phone. I thought it would just feed me power, as not data collection was specified on the station.
but it enabled a data connection.
So I used a public station once, and I'll never do it again.
This is the Denver field office maximizing Twitter engagement by repeating themselves. (Maybe that is not a fair way to view it, maybe the FBI should repeat advisories often.)
[0]: https://www.fbi.gov/contact-us/field-offices/portland/news/p...