FBI warns against using public USB charging ports
abcnews.go.com
abcnews.go.com
* The risk on any modern phone is close to nonexistent. By default they only charge. You'd need a zero day exploit in the charging function.
* There are no reports of such attacks ever having happened in the wild.
Stop worrying about fake security threats. There are enough real ones.
Are you saying that there are no unfixed exploits in the USB stack ?
Maybe this discussion is too nuanced for HN. Best we just tow the line, and agree that phishing and websploits is the biggest problem and other issues are not worth addressing even when we can.
What's going over there I wonder?
It's like this guy I used to work for. Anytime someone would ask him to make a pdf copy of a document he would print it out, scan it on the copier and email it to himself.
There has to be some of those types over there. This came from their desk.
What you scan is what you get (potentially some information about the scanner too)
That's a pragmatic strategy to ensure that sensitive information isn't leaked.
Other than potentially including useful vector formats of artwork such as seals, logos and signatures, the visibility and/or mask settings can easily hide sensitive information that is trivial to extract later with standard vector editing software.
The print+scan method ensures that the person sharing the file is fully aware of exactly what is being handed over. It also deals with redactions which were not implemented properly.
>Failed redaction reveals Paul Manafort's 'lies to FBI'
https://www.bbc.com/news/world-us-canada-46804127
Moving deeper into just redaction failures:
The American Bar Association even has a topic dedicated to redaction failures, where they list numerous examples of it (including the one above):
https://www.americanbar.org/groups/judicial/publications/jud...
Yet redaction failures are just one of many ways that a PDF can overshare, simply printing and scanning it solves a great many problems. I think it's a good approach for people who aren't tech savvy, especially with longer documents.
1) Print 2) Cut out the parts you want to leave out (blacking them with a market might leave an opening for revealing them via some contrast tweaking) 3) Scan
Easy to explain, easy to implement, easy to remember.
No ot wasn't, it was because he didn't know how to use computers.
Source: https://slate.com/technology/2023/04/free-public-phone-charg...
Edit: just checked - it's indeed possible with Android 14. Connecting a mouse doesn't require any confirmation. As long as the phone is unlocked, you can adjust the USB settings with that mouse.
It's probably safe enough to recharge your battery pack and charge the phone off that, even at the same time if supported.
If you already had it on, you could probably use it own the device pretty quick, but it's not enabled by default.
"""To connect a Bluetooth device:
1. Go to Settings > Accessibility, and select Touch.
2. Select AssistiveTouch > Devices, then select Bluetooth Devices.
3. Select your device from the list."""
Is this requirement a very recent change?
(I don't have my own iPad with me right now, but I don't recall enabling AssistiveTouch to get the Logitech keyboard+trackpad working.)
EDIT: I looked online and apparently prior to 13.4 AssistiveTouch was required to use a mouse. But now you don't need it if you only want basic mouse functionality.
My Fairphone 4 with vanilla Android 11 when connected to a USB C monitor will immediately mirror the screen without any sort of notification, so an evil charging port could at least record everything I do, no zero days required.
https://www.deccanchronicle.com/technology/in-other-news/120...
The fact that this hasn't been exploited in the wild much is good, but doesn't mean that the advice is wrong. Unless the vulnerabilities themselves are all patched it _will_ be exploited in the wild eventually.
Infection is now potentially higher due to increased OTG usage given the removal of MicroSD by many manufacturers. (The removal of the MicroSD has been a damn inconvenience irrespective of the OTG matter.)
The FBI disagree:
> Bad actors have figured out ways to use public USB ports to introduce malware and monitoring software onto devices. Carry your own charger and USB cord and use an electrical outlet instead.
I'd rather take advice from them than a random commenter here who has no insight into what's actually happening within the criminal world.
No it doesn't. The line you quoted says such an attack is theoretically possible, it doesn't say it has ever happened. And as another comment mentions, the tweet wasn't some update on things happening, they were parroting an old general practices guide.
I personally just prefer to charge a cheap USB battery so that I can use it for anything that needs a charge. Many of them now also have a flashlight like the phone.
as far as i know, any somewhat recent version of either android or iOS connect in a charge-only mode to any untrusted USB port. if you want to connect in a way that allows data to flow over the connection, you have to accept a prompt in the phone. should i be worried that this system has been compromised?
Personally, I never use public usb ports because I think it is more likely that some jerk has wired up the port to 120V. Circumventing the OS protection to grab my data feels seems less likely than chaotic destruction.
or at least, that's been my experience as an average looking white guy. it's probably not true for everyone.
I don't, because while that's unlikely, what is almost certain is that the port only does charging at the lowest default voltage/amperage, which for at least 5 years now is not enough to charge a smartphone on standby.
Are you sure it block HID as well?
The tweet doesn't say that, it just says that "bad actors" have developed methods of using USB ports for nefarious purposes. Which has been known for over a decade now, but I don't think there's ever been a recorded case of it being done in the wild.
It doesn't seem like the kind of attack that would be easy to hide either, unless accompanied by some zero day that bypasses the accept data transfer prompt.
I admit that the percentage of people that would do that is low, but even at like .1% that's one in a thousand which a public charge station could see hundreds to thousands of users per week. If these were around they'd be spotted.
Many devices do not request data access for an input accessory like a mouse-- and if you gain input you can dismiss the popup instantly in your exploit.
Also, many people might not pay attention to that popup.
Also, 0days exist.
Have you read the thread? Plenty of people are saying this risk is overblown and not to worry. The top 3 comments all express this sentiment.
>and if you gain input you can dismiss the popup instantly in your exploit.
Do you think using a mouse on an unlocked phone would go unnoticed? There's also a fair amount of disagreement over whether a mouse will work without input.
We've had security researchers notice USB device attacks on computers, the same sort of attack except it will likely only hit one person. This kind of large scale attack where thousands have the chance to notice would be observed.
> Do you think using a mouse on an unlocked phone would go unnoticed?
Certainly, it only takes a millisecond.
> There's also a fair amount of disagreement over whether a mouse will work without input.
0days exist.
> the same sort of attack except it will likely only hit one person
Stuxnet alone is known to infect hundreds of thousands for a start, but as usual keep in mind the successful attacks are generally not found out :)
If your concern is zero days, nothing you do with your phone is safe. Making a big deal about this one thing seems silly. A similar thing if your concern is nation states, like in the Stuxnet attack.
safeR. There are no absolutes in security. And not using public chargers totally will.
> A similar thing if your concern is nation states
If you live in the middle of USA you are probably OK but many people live in or near nation states that could totally install juice jackers centrally.
You're also safer if you leave your phone in airplane mode, or better yet off. Juice jacking is possible, but there's no evidence it's been deployed. A zeroclick attack seems like a much bigger threat, and I can't do much against that.
>If you live in the middle of USA you are probably OK but many people live in or near nation states that could totally install juice jackers centrally.
You're missing the point. If your adversary is a nation state, you're already screwed. They have better methods of attack than hoping you need to battery is low in some specific location.
edit let's assume I run a criminal organization and want to effectively use juice jacking. My first step would be to purchase several expensive zero days, and then develop some kind of software to launch it and to assure only phones susceptible to them get targeted, otherwise people will quickly notice something's wrong.
Then I need to get access to real estate in a high traffic area, where I'll need to buy electricity and run some kind of data server. Then I'll need to get people to sift through the resulting data, and the "payoff" is what, banking details or credit cards? Attacking an ATM seems way easier.
The goal is not to eliminate phone use but to use it safer.
> You're missing the point. If your adversary is a nation state, you're already screwed. They have better methods of attack than hoping you need to battery is low in some specific location.
Being individually targeted you'd have to do a lot more, lockdown mode and all that. Juice jacking from a charging device in a public place is a mass attack, and the measure is very simple-- don't use public USB ports.
> edit let's assume I run a criminal organization and want to effectively use juice jacking.
If your criminal organization is also the government then it's a bit easier than what you describe.
> assure only phones susceptible to them get targeted, otherwise people will quickly notice something's wrong
The attacker simply disconnects data if exploit doesn't work right away. Not many people would notice a split second of a popup.
The real estate part is, the rest isn't.
And without the financial incentive the benefit becomes unclear. Presumably spying, but you're either hoping to randomly get a high profile target or needing to trawl through a truly massive amount of data for some unknown potential benefit.
There are better methods of individual targeting and mass surveillance available to the state.
They also make guaranteed data-blocking cables cables, but getting the blocker as a dongle means I can carry it plus a data cable for my phone, and not have to carry 2 cables.
(When I do find an unmarked USB cable that appears to be charging-only, like that came with a used phone and a firestarter wallwart, I destroy it.)
No need to buy these, just take any usb cable and snip the correct 2 wires
I think it's funny how one thinks that damaging the cable sheath just to cut two cables makes one end up with a proper charging-only cable which one would actually like to carry around.
I've seen enough Apple Lightning cables which are damaged near the connector where I always think: what kind of people are these who are okay with this?
I do cut USB cables, but it's for tinkering and not for normal use.
If someone managed to install something like this in a wall plate in an airport, they could be doing far worse things to the airport infrastructure. Homeland Security should be looking for these things, with people plugging testers into USB power outlets. If they talk on the data lines at all, there's something funny going on.
Not quite a physical attack anymore if you pwn these remotely.
Granted if the situation in the US is still the same as Europe's rather than China's, it's a nonissue. Last I checked few people there ever used these.