(Though, yeah, I'd avoid a lot of "normal" activities if I ever attended BlackHat.)
[autorun]
open=you_didnt_read_the_brochure_right.exe
icon=setup.exe,0
label=My install CDLeaving USB sticks lying around with some sort of callback to see who plugs them in is a really clever idea. We could probably catch the serial number range in Defender ATP.
In all seriousness though - 128gb usb 3.0 drives can be picked up for $10 on sale all day long. Absolutely no reason to trust some $0.25 random 4gb that a stranger gave you aside from running R-studio on it for fun or something.
I wonder whether you‘d take similar precautions on a site named Hacker News
perhaps hacker news is merely a conversation prompt aggregator
So you can’t trust any site for power.
—-
Although teleporting power Via quantum entanglement has been demonstrated as possible given a line of communication.
So crazily, “power over data” may happen one day.
Perhaps, we can all look forward to hackers draining our last 1% of battery power as a reward for not using end-to-end power encryption.
I know I largely do, but perhaps that’s unwise, especially given the site’s stated target audience
Wait till someone reprograms that arduino plugged into your USB via webUSB to be a HID device to do their bidding !
This is the solution to that problem:
https://www.amazon.com/PortaPow-3rd-Data-Blocker-Pack/dp/B00...
https://www.amazon.com/PortaPow-NA-USB-C-Data-Blocker/dp/B08...
https://www.amazon.com/PortaPow-Data-Blocker-USB-C-Converter...
I charged me phone, fully aware of these sorts of issues. I just went with my gut instinct that, in that environment, it's highly unlikely that the cables have been "trojanized".
The FBI can warn about it, but what can you really do? You just have to trust your judgement as to what you feel are safe charging stations, and which may not be.
Get a USB condom, for instance, practice safer charging. :)
https://www.zdnet.com/article/protect-your-data-with-a-usb-c...
https://lifehacker.com/use-a-usb-condom-to-protect-your-devi...
[1] https://needgap.com/problems/73-usb-type-c-condom-usb-cybers...
Oh, I didn't know that! So what is the solution for USB-C? How do the new USB condoms work?
I think its possible to disable the USB 'protocol' in Linux, but it would require advanced permissions on android, which probably doesn't work out of the box, with IOS who knows or cares.
Yes, exactly. There are some comments here in the thread that discuss this in detail.
I bought like 5 of these, threw them in my bags and luggage, and I don't worry about charging like ever. And my devices charge fast.
If I'm doing long flights, I generally bring a single power brick.
Maybe with USB you could get away by using a cable without data pins, but I'm not sure whether that may influence charging speed given USB-C is pretty flexible.
Perhaps here on HN. Most people will plug their smartphone into any accepting receptacle. trains, airplanes, NYC SmartLink, or ask the bartender if they can plug it in behind the bar.
I still carry a DIY Altoids charger that takes a 9V battery (pulled down to proper volts for iPhone). In a battery emergency, my phone is simply on life support and I don't have to look for outlets that might also include a zero-day.
I'm with you, this might fall under "safe". Then again, from threads posted here and elsewhere, and through personal investigation...the infotainment systems on airplanes are an absolute disaster with regards to security and software design. They're often part of the same system as the provided USB ports. While the risk is small, there's nothing stopping 1 person from running a script that exploits some flaw in the outdated Linux distro the airline is using to manage their in-flight entertainment.
There's also a chance I'm paranoid and spend too much time here, but I'm gonna stick with my Altoids.
Sometimes I just want to charge my phone from my laptop without triggering all kinds of finder and iTunes and photos interactions.
Same with a car - just power, please.
I’d like to just rely on my device to protect me by asking if I want to trust the device.
I'll never be able to bring up this risk with USB to those guys.
Edit: IoC typo -> IoT
Though apparently the "Internet of Cows" is something.