This makes it sound like plugging USB sticks guests are carrying into a computer is standard procedure for the Secret Service. That might make sense if they have some sandboxed computer designed for this purpose, as suggested by other commenters. But then the rest of the quote makes it sound like the agents were unprepared for files to be copied and they panicked and aborted the "analysis" to prevent "corruption". Which makes it sound like, no, they just plug it into their own computers...
No one, not even the Secret Service, should randomly plug in a strange USB stick
11–20 of 231 posts
Re: No one, not even the Secret Service, should randomly plug in a strange USB stick
#12It's a severe discredit to the major operating system vendors that plugging in a USB stick can still compromise a system. If a USB device identifies itself as a keyboard, the system shouldn't accept its keystrokes until that keyboard has typed the user's login password (EDIT: or the user explicitly authorizes the device using a different keyboard). If it identifies itself as a storage device, the filesystem driver sh…
Re: No one, not even the Secret Service, should randomly plug in a strange USB stick
#13I know secretive service agent =/= computer expert but jesus...both my little sister and 60 year old mother know better.
Re: No one, not even the Secret Service, should randomly plug in a strange USB stick
#14It's a severe discredit to the major operating system vendors that plugging in a USB stick can still compromise a system. If a USB device identifies itself as a keyboard, the system shouldn't accept its keystrokes until that keyboard has typed the user's login password (EDIT: or the user explicitly authorizes the device using a different keyboard). If it identifies itself as a storage device, the filesystem driver sh…
Re: No one, not even the Secret Service, should randomly plug in a strange USB stick
#15It's a severe discredit to the major operating system vendors that plugging in a USB stick can still compromise a system. If a USB device identifies itself as a keyboard, the system shouldn't accept its keystrokes until that keyboard has typed the user's login password (EDIT: or the user explicitly authorizes the device using a different keyboard). If it identifies itself as a storage device, the filesystem driver sh…
I'd rather this device presented itself as a drive containing various virtual files that contain temperature data in them, but the cat's out of the bag, so to speak.
Re: No one, not even the Secret Service, should randomly plug in a strange USB stick
#16I don't know much about this case but depending on the level of concern, even just plugging the device into a safe, isolated machine and performing an image may be insufficient. You could imagine a USB device that presented as a harmless file store unless certain conditions were detected, in which case the device could re-present as a keyboard (providing pre-programmed keystrokes) or potentially a bluetooth or wirele…
I would be absolutely shocked if the US’ three letter agencies did not have some form of custom tooling to detect this — especially considering the sophisticated multi-vector I/O exploitation they demonstrated a decade ago with Stuxnet and the Equation Group.
Regardless of your views on his policy, Trump has demonstrated zero respect for opsec — even in a national security context — so I would also not be surprised if those three letter agencies have decided the White House is untrustworthy with its cyber warfare capabilities.
Re: No one, not even the Secret Service, should randomly plug in a strange USB stick
#17It's a severe discredit to the major operating system vendors that plugging in a USB stick can still compromise a system. If a USB device identifies itself as a keyboard, the system shouldn't accept its keystrokes until that keyboard has typed the user's login password (EDIT: or the user explicitly authorizes the device using a different keyboard). If it identifies itself as a storage device, the filesystem driver sh…
Because up until 10 years ago, developing your own USB device was generally expensive and malicious devices ended up being out of scope in threat modelling. In addition, some models these days still define 'physical access == game over'...
Re: No one, not even the Secret Service, should randomly plug in a strange USB stick
#18It's a severe discredit to the major operating system vendors that plugging in a USB stick can still compromise a system. If a USB device identifies itself as a keyboard, the system shouldn't accept its keystrokes until that keyboard has typed the user's login password (EDIT: or the user explicitly authorizes the device using a different keyboard). If it identifies itself as a storage device, the filesystem driver sh…
Keep in mind that autoplay is not unique to USB drives either. CD-ROM drives have had that feature forever.
Re: No one, not even the Secret Service, should randomly plug in a strange USB stick
#19it immediately began to install files, a “very out-of-the-ordinary” event that he had never seen happen before during this kind of analysis. The agent had to immediately stop the analysis to halt any further corruption of his computer This makes it sound like plugging USB sticks guests are carrying into a computer is standard procedure for the Secret Service. That might make sense if they have some sandboxed computer…
Re: No one, not even the Secret Service, should randomly plug in a strange USB stick
#20It's a severe discredit to the major operating system vendors that plugging in a USB stick can still compromise a system. If a USB device identifies itself as a keyboard, the system shouldn't accept its keystrokes until that keyboard has typed the user's login password (EDIT: or the user explicitly authorizes the device using a different keyboard). If it identifies itself as a storage device, the filesystem driver sh…
Because very many people (and more importantly, businesses) have obscure buggy printers from the 90s or the equivalent thereof.
This type of protection parent is referencing is "endpoint protection" and there are many industry standard solutions. Why should an OS be more limiting? If you have physical access to a machine that stores things you shouldn't have access to, it's already compromised in my opinion. Why the eff are people overlooking physical security in 2019 is the better question.