There are a ton of different payloads that can be run on these, for everything from simple keylogging, to root access, to network backdoors. I've only recently gotten into pentesting but with something like this there's no real limit to the damage that could be done with only a few seconds of physical access.
Honestly, as a Systems/DevOps engineer it's always been well know that if you have physical access, you have zero chance of security. Sure it might take more time if precautions were followed, but you will be owned eventually, that's guaranteed.
This is one of our most frustrating fights I have with our security design reviewers. Effectively functionless mitigations that create extra obstacles for our service reps to deal with during troubleshooting. One example is our equipment is installed in access restricted areas, in a locked rack. We don’t need to disable unused Ethernet ports on our networking equipment that exists in a locked cabinet and it will take away our ability to repatch equipment to a different switch in the system to assist in troubleshooting.
C-to-C is even worse because Usb-C requires a chip in the connector, and you never know what that chip is capable of. Usb-A would only have a chip in it if it's been tampered with.
The MSPM0C1104 is a 24 MHz Arm Cortex-M0+ based device with up to 16 KB of flash and 1 KB of SRAM. It has a 12-bit ADC with three channels, six GPIO pins, and typical communication interfaces like UART, SPI, and I²C. It is an ultra-low-power 32-bit MCU well suited for compact battery-powered designs.
Whilst this wouldn't work for this specific application we're discussing (no USB support, no wireless), it's an amazing example of just how little a microcontroller can be nowadays.
Maybe, might also be that since tech literacy has degraded since his leak. Which means that they don't care because they are overwhelmed with the information that they don't understand. Hell, I imagine that a lot of the press that where sent the information didn't fully understand.
The average person likely defaulted to what they always do, and just assumed that the leak meant the feds had to stop and treat it like any other historic reveal (example being stuff like COINTELPRO and believing that it was bad but isn't done anymore). Hell, a shocking amount of libs honestly thought that Biden was going to bring Medicare for All (even though he said he wasn't) just because he said "the Democratic Party is the party of healthcare" a few times.
I'm sure it's a spectrum, and some people may legitimately not be aware, but its been 13 years. As a society, we've had ample time to get literate and develop knowledge. Instead we've had three presidents from both major parties hold the line that Snowden was a criminal for blowing the whistle on rampant illegal surveillance, and all 3 of them just stepped on the gas.
Voters don't even see the irony in the pedophiles' ramping up the surveillance apparatus in the name of protecting the children.
I wouldn't include Assange in that list honestly. He was just out for himself in the end as he did muddy the waters in the 2016 election and was easily cajoled by the FSB to leak falsified documents and misinformation.
Chelsea however was a fucking patriot who was pillaried by the state to be made example of. She literally did her patriotic duty and was imprisoned for it.
Pro Tip: Leave a unique mark somewhere on the cable so if someone switches it, you can tell it apart. Always check for the mark before you use the cable, every time.
If you're really paranoid you should buy all your stuff in a brick and mortar store. You'd have to be high up on a list for it to even be worth someone's time, but intercepting a package and swapping the contents is pretty easy to do, typical Tuesday multi-agency gun ring bust for some postal inspectors
My older brother is abusive, and I need precautions to be safe.
That's my threat model.
I actually would rather run a phone with stock OS with verified boot, rather than LineageOS but with bootloader unlocked. Evil Maid from someone you know wanting fuck around with you is more scary to me than government tbh
(I don't have a pixel for graphene)
Edit: Also these cables cost like $200 online from HAK5. My brother definitely can pull some shit if he tried. He's in Computer Science in college.
Only with a few rare phones... most phones just gets bricked if you attempt to lock it under a custom os because they don't support custom keys.
Pixel supports it, but I don't have a pixel. (If I did I would just use Graphene lol)
New is expensive
and I really distrust the used market... feels very sketchy and it could have hidden damage that doesn't manifest itself until the return window is already passed (if they even allow a return at all), also I have a paranoia about getting an IMEI that a criminal have used and then cops come knocking thinking its ME doing the illegal activity (cuz you know they do the "oops wrong address" thing often and they've shot people to death over it )
This is pretty much the reason I exclusively use dollar store cables and/or dedicated chargers. Saw a yt video about these things at an airport. The more I learn about tech, the more it makes me wanna uncle Ted the fuck out.
I do call center work in a health care environment. We get lots of scams. Most of them are bad and obvious but someone recently did the math and figured out the don’t need to be good to work.
Follow me for a moment.
Call comes in. It’s a recording. You know this recording. It’s a busy office environment. Paper rustling, typing, annoyed sigh exactly the same number of seconds in every call.
There is no response to your voice. But you have to say the same thing 3 times with no response before you can disconnect the call. So the recoding loops and you continue talking to the bot.
Why?
Well on my side, I know it’s dumb but I have to do it because metrics mean I can continue to almost afford to do things like eat food or masturbate in a warm house in the winter.
They do it because this bot lets them map out our IVR (whatever, it sucks now that it’s AI) and capture voice samples from people who are forbidden to hang up.
Now in years past this wouldn’t be all that useful. The samples are of reps saying basically the same damn thing. But we now live in the era of lifeless AI. So the bar has been lowered for what a legit interaction is. (Seriously, some places paid extra for a more “lifelike” AI that did everything the old EVA bot did but in an Indian accent with the sound of crumpling paper in the background and the occasional “um” thrown in.)
So those voice samples can be used to create a fake call center based on real employee voices. This is a known attack vector that is being used against us in health care right NOW.
But AI needs to profitable so nothing is done about it.
Seriously, they protect AI to such a ridiculous extent they know the scam is happening from the same phone number and they won’t block it or even issue it a challenge.
Bruh, real talk! I did some limited packet tracking. But going deep I learned about the occilation of the fan attack on air gapped machines a few years ago. I'm just done at this point. They gunna get your info regardless.
I've been using wireless chargers for years. I find it "more secure" in the sense that my phone's port is full of gunk and if I want to wake up with full batteries I can count on wireless a lot more.
I like wireless and magnetic mainly because fucking up the cable is like the most common thing I might do to a device. not saying I do it all the time but its the most likley break to happen.
My phone still requires auth to use plus there is no way for them to get what's on the screen. I'm also pretty sure that typing a pin requires the screen but I could be mistaken.
Even if there was a way to attack from USB, I still wouldn't be that worried. USB attacks typically are only used against targeted individuals not some rando. The reason why you see warnings about chargers is because it makes easy clickbait.
A human on a keyboard attached to a device while its unlocked can navigate to a webpage just bypressing keys, so malicious USB can just do what a person can do, but automatically.
It probably works much better on a computer after the user walks away, it's a bit harder on a phone since most people instinctively presses the power button to turn off the screen so it autolocks (since you usually put it away in your pocket, so its muscle memory), but for a computer, there are certain people that just walks away to the bathroom or something and leave their device unlocked... so a person with access to a keyboard connected to that computer can do stuff on it... same as a script on a chip that sends keystrokes to the computer...
and all the scary propaganda they used about HUWEI tech, yea sure the ccp is doing it, but they are likely not an immediate threat unlike the usa doing it.
73 Comments
Bad_Engineering@fedia.io · 148 pts · 179d
You can now buy one for yourself online. https://shop.hak5.org/products/omg-cable
SayJess@lemmy.blahaj.zone · 43 pts · 179d
That is amazing. The x-ray of it is kind of scary, honestly. That little chip could be all it would take to get into an air-gapped machine.
Rooskie91@discuss.online · 23 pts · 179d
Could?
Bad_Engineering@fedia.io · 17 pts · 179d
There are a ton of different payloads that can be run on these, for everything from simple keylogging, to root access, to network backdoors. I've only recently gotten into pentesting but with something like this there's no real limit to the damage that could be done with only a few seconds of physical access.
thejml@sh.itjust.works · 22 pts · 179d
Honestly, as a Systems/DevOps engineer it's always been well know that if you have physical access, you have zero chance of security. Sure it might take more time if precautions were followed, but you will be owned eventually, that's guaranteed.
Dubiousx99@lemmy.world · 10 pts · 179d
This is one of our most frustrating fights I have with our security design reviewers. Effectively functionless mitigations that create extra obstacles for our service reps to deal with during troubleshooting. One example is our equipment is installed in access restricted areas, in a locked rack. We don’t need to disable unused Ethernet ports on our networking equipment that exists in a locked cabinet and it will take away our ability to repatch equipment to a different switch in the system to assist in troubleshooting.
flowers_galore2@lemmynsfw.com · 3 pts · 179d
Let me guess, they do allow ai traffic from everyone and their mum for the sake of uhh… innovation?
SayJess@lemmy.blahaj.zone · 3 pts · 179d
That is gnarly!
in_my_honest_opinion@piefed.social · 4 pts · 179d
https://hackaday.com/tag/badusb/
dance_ninja@lemmy.world · 23 pts · 179d
Crazy that the USB-A housing is big enough for that. Makes me want to avoid anything that's not C to C.
Edit: someone pointed out there's an option for C to C 💀
moody@lemmings.world · 34 pts · 179d
C-to-C is even worse because Usb-C requires a chip in the connector, and you never know what that chip is capable of. Usb-A would only have a chip in it if it's been tampered with.
dance_ninja@lemmy.world · 6 pts · 179d
Yeah I was hoping the smaller form factor would make it difficult to fit in extra malicious hardware.
moody@lemmings.world · 16 pts · 179d
This was the smallest Bluetooth chip back in 2017. I can't even imagine what else they can fit into the form factor of a USB-C plug nowadays.
thallamabond@lemmy.world · 24 pts · 179d
Released last year, TI MSPM0C1104
https://www.electronics-lab.com/texas-instruments-unveils-mspm0c1104-worlds-smallest-microcontroller-for-space-constrained-applications/
Aceticon@lemmy.dbzer0.com · 1 pts · 178d
Whilst this wouldn't work for this specific application we're discussing (no USB support, no wireless), it's an amazing example of just how little a microcontroller can be nowadays.
docandersonn@literature.cafe · 5 pts · 179d
There's a USB-C option for the active end.
dRLY@lemmy.ml · 4 pts · 178d
Came to check if anyone had already linked hak5. Glad to see you had shared the link!
muusemuuse@sh.itjust.works · 3 pts · 178d
This is both incredible and horrifying at the same time
in_my_honest_opinion@piefed.social · 109 pts · 179d
You might be interested in the full Snowden leak
https://github.com/iamcryptoki/snowden-archive
MnemonicBump@lemmy.dbzer0.com · 42 pts · 179d
Yeah, it's scary how much people don't remember/don't know
chillpanzee@lemmy.ml · 16 pts · 179d
And don't care.
dRLY@lemmy.ml · 3 pts · 178d
Maybe, might also be that since tech literacy has degraded since his leak. Which means that they don't care because they are overwhelmed with the information that they don't understand. Hell, I imagine that a lot of the press that where sent the information didn't fully understand.
The average person likely defaulted to what they always do, and just assumed that the leak meant the feds had to stop and treat it like any other historic reveal (example being stuff like COINTELPRO and believing that it was bad but isn't done anymore). Hell, a shocking amount of libs honestly thought that Biden was going to bring Medicare for All (even though he said he wasn't) just because he said "the Democratic Party is the party of healthcare" a few times.
chillpanzee@lemmy.ml · 3 pts · 178d
I'm sure it's a spectrum, and some people may legitimately not be aware, but its been 13 years. As a society, we've had ample time to get literate and develop knowledge. Instead we've had three presidents from both major parties hold the line that Snowden was a criminal for blowing the whistle on rampant illegal surveillance, and all 3 of them just stepped on the gas.
Voters don't even see the irony in the pedophiles' ramping up the surveillance apparatus in the name of protecting the children.
Tollana1234567@lemmy.today · 0 pts · 178d
assange, chelsea manning, the msm crucified these 2 as well. funny enough putin allows him to stay because hes useful propaganda.
in_my_honest_opinion@piefed.social · 2 pts · 178d
I wouldn't include Assange in that list honestly. He was just out for himself in the end as he did muddy the waters in the 2016 election and was easily cajoled by the FSB to leak falsified documents and misinformation.
Chelsea however was a fucking patriot who was pillaried by the state to be made example of. She literally did her patriotic duty and was imprisoned for it.
9point6@lemmy.world · 107 pts · 179d
Not just the US government, anyone has been able to do this for years
Zer0_F0x@lemmy.world · 35 pts · 179d
We found out 15 years ago the hardware is probably older
DeathByBigSad@sh.itjust.works · 33 pts · 179d
Pro Tip: Leave a unique mark somewhere on the cable so if someone switches it, you can tell it apart. Always check for the mark before you use the cable, every time.
(Yes I actually do this, I'm paranoid)
Bunitonito@lemmy.world · 7 pts · 179d
If you're really paranoid you should buy all your stuff in a brick and mortar store. You'd have to be high up on a list for it to even be worth someone's time, but intercepting a package and swapping the contents is pretty easy to do, typical Tuesday multi-agency gun ring bust for some postal inspectors
DeathByBigSad@sh.itjust.works · 6 pts · 179d
My older brother is abusive, and I need precautions to be safe.
That's my threat model.
I actually would rather run a phone with stock OS with verified boot, rather than LineageOS but with bootloader unlocked. Evil Maid from someone you know wanting fuck around with you is more scary to me than government tbh
(I don't have a pixel for graphene)
Edit: Also these cables cost like $200 online from HAK5. My brother definitely can pull some shit if he tried. He's in Computer Science in college.
okamiueru@lemmy.world · 3 pts · 179d
Is it not possible to lock the bootloader again with LineageOS?
DeathByBigSad@sh.itjust.works · 4 pts · 179d
Only with a few rare phones... most phones just gets bricked if you attempt to lock it under a custom os because they don't support custom keys.
Pixel supports it, but I don't have a pixel. (If I did I would just use Graphene lol)
New is expensive
and I really distrust the used market... feels very sketchy and it could have hidden damage that doesn't manifest itself until the return window is already passed (if they even allow a return at all), also I have a paranoia about getting an IMEI that a criminal have used and then cops come knocking thinking its ME doing the illegal activity (cuz you know they do the "oops wrong address" thing often and they've shot people to death over it )
pipi1234@lemmy.world · 31 pts · 179d
I knew about these, but always thought I could spot them.
I wouldn't!!!
YiddishMcSquidish@lemmy.today · 30 pts · 179d
This is pretty much the reason I exclusively use dollar store cables and/or dedicated chargers. Saw a yt video about these things at an airport. The more I learn about tech, the more it makes me wanna uncle Ted the fuck out.
GreenKnight23@lemmy.world · 9 pts · 179d
muusemuuse@sh.itjust.works · 10 pts · 178d
I do call center work in a health care environment. We get lots of scams. Most of them are bad and obvious but someone recently did the math and figured out the don’t need to be good to work.
Follow me for a moment.
Call comes in. It’s a recording. You know this recording. It’s a busy office environment. Paper rustling, typing, annoyed sigh exactly the same number of seconds in every call.
There is no response to your voice. But you have to say the same thing 3 times with no response before you can disconnect the call. So the recoding loops and you continue talking to the bot.
Why?
Well on my side, I know it’s dumb but I have to do it because metrics mean I can continue to almost afford to do things like eat food or masturbate in a warm house in the winter.
They do it because this bot lets them map out our IVR (whatever, it sucks now that it’s AI) and capture voice samples from people who are forbidden to hang up.
Now in years past this wouldn’t be all that useful. The samples are of reps saying basically the same damn thing. But we now live in the era of lifeless AI. So the bar has been lowered for what a legit interaction is. (Seriously, some places paid extra for a more “lifelike” AI that did everything the old EVA bot did but in an Indian accent with the sound of crumpling paper in the background and the occasional “um” thrown in.)
So those voice samples can be used to create a fake call center based on real employee voices. This is a known attack vector that is being used against us in health care right NOW.
But AI needs to profitable so nothing is done about it.
Seriously, they protect AI to such a ridiculous extent they know the scam is happening from the same phone number and they won’t block it or even issue it a challenge.
YiddishMcSquidish@lemmy.today · 3 pts · 179d
Bruh, real talk! I did some limited packet tracking. But going deep I learned about the occilation of the fan attack on air gapped machines a few years ago. I'm just done at this point. They gunna get your info regardless.
YellowParenti@lemmy.wtf · 4 pts · 179d
Every time I learn something about modern living
Funny enough, im reading up on timber frame houses.
YiddishMcSquidish@lemmy.today · 4 pts · 179d
Ok, granted. Maybe not THAT Uncle Ted out. But it is kinda fucked how the CIA used his professor to manipulate homie.
TerdFerguson@lemmy.world · 4 pts · 178d
Yachts at sea.
YiddishMcSquidish@lemmy.today · 3 pts · 178d
Yas Queen!
sommerset@thelemmy.club · 28 pts · 179d
Ya no definitely. Anything just not a health care for people
Salamanderwizard@lemmy.world · 8 pts · 178d
The government is that dude who'll talk a big game about how great he is, get ya in bed, fuck you and not even finger blast ya to the finish.
fallaciousBasis@lemmy.world · 24 pts · 179d
Anyone can do this.
7rokhym@lemmy.ca · 24 pts · 179d
USB condoms for charging exist for a reason.
okamiueru@lemmy.world · 4 pts · 179d
Would limit higher power charging
flowers_galore2@lemmynsfw.com · 3 pts · 179d
That’s the tradeoff yes
otter@lemmy.ca · 22 pts · 179d
You can see a CT scan of one of these
https://www.techspot.com/news/105863-usb-c-cable-can-hide-lot-malicious-hardware.html
brachiosaurus@mander.xyz · 5 pts · 179d
damn i though they would use the type A connector because it's bigger but it can be fit even into usb C
muusemuuse@sh.itjust.works · 2 pts · 178d
Apple did it with lightning.
muusemuuse@sh.itjust.works · 13 pts · 179d
Dude, we’ve been able to do that with a fucking arduino for years.
quediuspayu@lemmy.dbzer0.com · 13 pts · 179d
https://darknetdiaries.com/episode/161/
There's a darknet episode about these cables
rumba@lemmy.zip · 12 pts · 178d
You can just buy them
https://shop.hak5.org/products/omg-cable
Tetsuo@jlai.lu · 10 pts · 179d
There is also the whole "Bad USB" type of vulns that is pretty scary...
Widdershins@lemmy.world · 9 pts · 179d
I've been using wireless chargers for years. I find it "more secure" in the sense that my phone's port is full of gunk and if I want to wake up with full batteries I can count on wireless a lot more.
HubertManne@piefed.social · 7 pts · 179d
I like wireless and magnetic mainly because fucking up the cable is like the most common thing I might do to a device. not saying I do it all the time but its the most likley break to happen.
fossilesque@mander.xyz · 8 pts · 178d
TrollTrollrolllol@lemmy.world · 5 pts · 178d
the Chinese government did it to those
fossilesque@mander.xyz · 3 pts · 178d
Itdidnttrickledown@lemmy.world · 8 pts · 179d
Any government and crooks as well. Its been possible a lot longer than fifteen years.
Compromising computers with tech is nearly as old as computers themselves. The wireless aspect makes it more convenient but in no way is doing so new.
possiblylinux127@lemmy.zip · 7 pts · 179d
I am not terribly worried about USB/thunderbolt attacks since Android requires authentication before it does anything.
unit327@lemmy.zip · 7 pts · 179d
Lol, plug a usb mouse or keyboard into your android and it will just work. Anything you can do these things can do.
possiblylinux127@lemmy.zip · 4 pts · 179d
My phone still requires auth to use plus there is no way for them to get what's on the screen. I'm also pretty sure that typing a pin requires the screen but I could be mistaken.
Even if there was a way to attack from USB, I still wouldn't be that worried. USB attacks typically are only used against targeted individuals not some rando. The reason why you see warnings about chargers is because it makes easy clickbait.
DeathByBigSad@sh.itjust.works · 6 pts · 179d
No permission needed for a keyboard to open up a malicious webpage.
Yes a keyboard. Your USB cable wears a trench coat that says "Hey I'm a Keyboard, lemmy in"
possiblylinux127@lemmy.zip · -1 pts · 178d
Last time I checked a keyboard can't just open up a web page. That's not how it works.
DeathByBigSad@sh.itjust.works · 4 pts · 178d
Shortcuts...
A human on a keyboard attached to a device while its unlocked can navigate to a webpage just bypressing keys, so malicious USB can just do what a person can do, but automatically.
It probably works much better on a computer after the user walks away, it's a bit harder on a phone since most people instinctively presses the power button to turn off the screen so it autolocks (since you usually put it away in your pocket, so its muscle memory), but for a computer, there are certain people that just walks away to the bathroom or something and leave their device unlocked... so a person with access to a keyboard connected to that computer can do stuff on it... same as a script on a chip that sends keystrokes to the computer...
HugeNerd@lemmy.ca · 7 pts · 178d
Joke's on you, I still use Firewire.
nutsack@lemmy.dbzer0.com · 4 pts · 178d
yeah that's a good joke
scala@lemmy.ml · 5 pts · 179d
USB condom!
possiblylinux127@lemmy.zip · 1 pts · 179d
Fast charging won't work without a proper connection
mlg@lemmy.world · 5 pts · 178d
Don't worry, I'm pretty sure TAO won't bother to bug your cables since the NSA already has the data they want on you anyway lol
Gladaed@feddit.org · 3 pts · 178d
This is rather trivial to do. Micro chips are small.
Gammelfisch@lemmy.world · 2 pts · 179d
Impressive and spooky.
abbadon420@sh.itjust.works · 2 pts · 179d
America has a governmental deparment of CSS? No wonder your government is causing a Constant State of Suffering
Tollana1234567@lemmy.today · -3 pts · 178d
and all the scary propaganda they used about HUWEI tech, yea sure the ccp is doing it, but they are likely not an immediate threat unlike the usa doing it.
Gladaed@feddit.org · 3 pts · 178d
You are wrong for the fear was not about capability but intend and government ambition.
The Chinese are regular people. Assuming they couldn't is akin to assuming them intellectually defective.