PoisonTap – Exploits locked computers over USB
1–10 of 57 posts
Re: PoisonTap – Exploits locked computers over USB
#2Re: PoisonTap – Exploits locked computers over USB
#3By default anything stuck into a USB port should be sandboxed and various integrity checks need to be performed before access is allowed.
Re: PoisonTap – Exploits locked computers over USB
#4But if your box's physical security has been compromised, you're already screwed in any case.
Re: PoisonTap – Exploits locked computers over USB
#5Does using SRI ( https://developer.mozilla.org/en-US/docs/Web/Security/Subres... ) defeat a portion of this attack?
Re: PoisonTap – Exploits locked computers over USB
#6That is impressive. And scary. But if your box's physical security has been compromised, you're already screwed in any case.
There's a gradient to the screwage, however.
For example, I've encrypted my disk, so someone would need to steal my computer and then try bruteforcing it with some new-fangled graphics card.
With this insanity, I risk someone stealing my unencrypted traffic with a plug-and-play device any time I get up from my desk to pee. Then again, they can already do that with Wireshark.
Re: PoisonTap – Exploits locked computers over USB
#7Additionally you could reject any DHCP lease for a subnet that purports to overlap with the address range of any other directly connected network.
Re: PoisonTap – Exploits locked computers over USB
#8It's long past time that USB security is taken seriously. By default anything stuck into a USB port should be sandboxed and various integrity checks need to be performed before access is allowed.
You mean, before we started using USB for charging...?
It wouldn't be hard at all to make a convincing looking power adapter with something like PoisonTap baked in.
Re: PoisonTap – Exploits locked computers over USB
#9It's long past time that USB security is taken seriously. By default anything stuck into a USB port should be sandboxed and various integrity checks need to be performed before access is allowed.
So even if you follow Samy's recommendation of putting cement on your USB ports, [0] you're still vulnerable to injection and interception.
Moral of the story: encrypt all the things.
Re: PoisonTap – Exploits locked computers over USB
#10This wouldn't fully solve this problem, but it might just help protect me from people plugging devices into my machine while it's locked, and could even alert me that the device I thought was just charging has reported itself as a keyboard, despite looking nothing like one.