Do we know of a single real-world use of this hypothetical exploit? Do we know that iOS's (and presumably Android's) protection against untrusted device access isn't enough?
Do we know of a single real-world use of this hypothetical exploit? Do we know that iOS's (and presumably Android's) protection against untrusted device access isn't enough?
So, is it plausible a malicious charging station could gain root and sideload something nefarious on an iPhone? Absolutely. Particularly for non-tech-savvy folks desperate to get a charge before their connecting flight...
Has it happened? ...No idea. I guess that's where the anecdotes come in...
My general point about how easy it can be to maliciously root someone's device stands, so I will leave my comment as-is.
Folks - don't plug your devices into untrusted USB ports...
And yes, in the past many iOS jailbreaks were shockingly simple. The website one in particular - you went to a URL and clicked a button... your phone rebooted and was jailbroken.
The popup really should be a toggle somewhere in the settings that forces a user to explicitly enable data - not a popup users are mostly self-trained into ignoring.
Additionally, real charging stations should not offer cables with data lines at all.
More details?
1. The station has to be using USB Ports / Charging cables that are data enabled, not just cables that carry power
2. The hacker would need some way of injecting the malware into the charging station ports without being seen, I doubt many charging stations are internet connected so you would have to be at the device.
3. You need to have an active exploit for iOS or Android (or both) that will compromise the device and steal it's data.
It just seems like alot of work for something that in all likelyhood would not work.
> 1. The station has to be using USB Ports / Charging cables that are data enabled, not just cables that carry power
Doesn't matter, because you're (unwittingly) plugging into the attacker's device, not the station's.
> 2. The hacker would need some way of injecting the malware into the charging station ports without being seen, I doubt many charging stations are internet connected so you would have to be at the device.
You don't need to "inject" anything; you just need to physically place it between the user and the actual port and disguise it enough that people not paying attention won't notice. Or even just put a fake "charging station" in a place that the station didn't have one.
> 3. You need to have an active exploit for iOS or Android (or both) that will compromise the device and steal it's data.
People are plugging in their phone so they can use it. They'll plug in the phone, unlock it, and browse the internet. What can't you do in that situation?
iOS devices (maybe Android too, idk) ask you if you want to allow new accessories to access your device. That's why they said you need an exploit.
Anyone who would believe a notice like that (or would click trust without thinking) is a prime target.
It’s like many scam/spam emails- they often intentionally look a bit dubious, poor grammar, typos etc as the attacker just wants to deal with low hanging fruit, not someone who may wise up quickly that something isn’t right.
Even better, here's [2] a direct example of this attack using an O.MG cable [3].
[1] https://youtu.be/COndab_rQkE?t=76
If not an exploit, you need the victim to do something a lot more obviously (though the absolute obviousness of course remains debatable) dumb/risky than merely plug in.
Using your own power adapter and own power cable you will be fine.
Unless someone has tampered with either of them while you were distracted momentarily but that’s too high risk/inconvenient for an attacker for you to worry about.
I have never heard about a non-government sponsored attacker doing that kind of thing. If this is relevant or not to you, it's a matter of your threat model. If I were a journalist, I would be very weary. Personally, I don't plug my phone on random outlets and don't plug random devices on my computers, but it's clearly an overreaction.
(And no, I've never been to DEFCON. It really became famous.)
I think the risk is insanely low for your average person because you'd have to use an unpatched bug on a well-supported system, you'd have to put bug a USB port in a popular place, and you'd need a reason to do all that.
But at the same time, this is well in the wheelhouse and capability of some bored teen with a lot of time who wants to screw with people FWIW. You could also have fun and write a worm that infects everyone that connect to your USB port and have it DDoS a website or something. The first worms were created by bored people.
I suppose the difference is that people may be using the cable to connect to a device where that prompt is expected, in contrast to the "charging port in an airport" scenario where it would seem appropriately alarming.