Earlier quoted context omitted.
Because very many people (and more importantly, businesses) have obscure buggy printers from the 90s or the equivalent thereof.
The key thing to realize is that malicious USB devices get to choose which device they identify themself as to the operating system, but have much less control over what they physically look like to the user. If you plug in an old printer, you know you just plugged in an old printer; you can load the old-printer device driver and it probably won't exploit it. But if you plug in a USB stick you found in the parking lo…
No one, not even the Secret Service, should randomly plug in a strange USB stick
121–130 of 231 posts
Re: No one, not even the Secret Service, should randomly plug in a strange USB stick
#122Earlier quoted context omitted.
> It's 2019. Why the f haven't Windows, MacOS and Linux all implemented these basic precautions? For linux you can actually require USB devices to be authorized first by changing a few kernel settings. A friend of mine wrote a few shellscripts a few years ago to do exactly that: https://git.quitesimple.org/usbfilter/tree/ As you can see it's something that's very simple to do, there's just no good "normal user" UI fo…
Better late than never? https://www.phoronix.com/scan.php?page=news_item&px=Linux-5.... https://usbguard.github.io
Re: No one, not even the Secret Service, should randomly plug in a strange USB stick
#123Earlier quoted context omitted.
I can totally buy some low-level Secret Service agent with little tech knowledge plugging it into a machine without thinking twice.
Or a high-level agent. There are many dimensions where level is independent of tech savvy. I'm sure >50% of Fortune 500 CEOs could be tricked in the same way -- at least among the ones who use a computer.
Re: No one, not even the Secret Service, should randomly plug in a strange USB stick
#124Do we serious think every time the Secret Service comes across a person they should spend hundreds of thousands of $ forensically analysing all their electronics?
This was a random person who was in a resort. Nothing more.
You check them out, open their phone, check their usb, check their laptop and move on, or investigate further if they seem suspicious.
The total lack of computer literacy here is amazing.
Garbage like this is straight out of a hollywood movie "threatened his own computing system and possibly the rest of the Secret Service network."
The Secret Service are human beings their kids will use their laptops, do we understand this as IT professionals? Or we living in gaga land of Hollywood?
It's up to their experienced network IT staff to contain their network at differing levels and a laptop in the field should be considered compromised.
Should they also have locked this lady down in a bio security suit in case she was carrying biological weapons? Is any other field as stupidly impractical as computer security 'experts'?
Re: No one, not even the Secret Service, should randomly plug in a strange USB stick
#125It's a severe discredit to the major operating system vendors that plugging in a USB stick can still compromise a system. If a USB device identifies itself as a keyboard, the system shouldn't accept its keystrokes until that keyboard has typed the user's login password (EDIT: or the user explicitly authorizes the device using a different keyboard). If it identifies itself as a storage device, the filesystem driver sh…
Am I the only one old enough to remember 'disk bombs' from the 90s where you filled 3.5" floppies with paste made from strike anywhere match heads so when the disk spun up it melted? You could do similar things with a USB stick. You could have a high voltage converter which fries your PC the second you plug it in.
Basically, it is always a bad idea to plug in unknown peripherals to your computers. The OS isn't going to save you in all cases.
Re: No one, not even the Secret Service, should randomly plug in a strange USB stick
#126I also don't like the new design of Macbook in which they merged the USB port and charging port into one. This really opens up huge security risks in my opinion.
Re: No one, not even the Secret Service, should randomly plug in a strange USB stick
#127I have a mysterious USB stick I received as a thank you from a delegation of the Chinese department of Customs (中华人民共和国海关总署) after presenting to them in Palo Alto. The USB is branded with the Chinese Customs logo and their slogan. I haven't dared plugging this in. First and foremost I'm afraid it isn't standards compliant and will somehow fry my motherboard, secondly I don't have a burner device and the necessary kno…
Re: No one, not even the Secret Service, should randomly plug in a strange USB stick
#128The stupidity of it (from an infosec standpoint) should be a given, yet this aspect appears to be the focus of the debate.
Am I missing something?
Re: No one, not even the Secret Service, should randomly plug in a strange USB stick
#129It's a severe discredit to the major operating system vendors that plugging in a USB stick can still compromise a system. If a USB device identifies itself as a keyboard, the system shouldn't accept its keystrokes until that keyboard has typed the user's login password (EDIT: or the user explicitly authorizes the device using a different keyboard). If it identifies itself as a storage device, the filesystem driver sh…
Re: No one, not even the Secret Service, should randomly plug in a strange USB stick
#130Earlier quoted context omitted.
I can totally buy some low-level Secret Service agent with little tech knowledge plugging it into a machine without thinking twice.
Or a high-level agent. There are many dimensions where level is independent of tech savvy. I'm sure >50% of Fortune 500 CEOs could be tricked in the same way -- at least among the ones who use a computer.