Live data from Hacker News

I Tested an HDMI Adapter That Demands Your Location and Spams You with Ads

404media.co

81–90 of 132 posts

Re: I Tested an HDMI Adapter That Demands Your Location and Spams You with Ads

#81
post #15

Given that the device is plugged in, trusted, shows up as a computer, and requires external power, it has all the connections it needs spy on the screen (at minimum) and remote control the victim iPhone without permission in the worst case. (it has video feed, and can emulate USB keyboard and mouse) Yikes!

It's not THAT weird. Lightning can't carry HDMI at all so even Apple's official adaptor is essentially setting up an Airplay connection over USB and has an ARM SoC to handle it. I'm guessing 3rd parties can't do the same trick without Apple's blessing which results in scary seeming workarounds.

Re: I Tested an HDMI Adapter That Demands Your Location and Spams You with Ads

#82
post #77

Earlier quoted context omitted.

Integrating everything into USB has been great at physical simplification, but it really opened up the attack surface. First party malware is the worst.

Can't wait for the consumer keyboard that saves everything that was typed to it and/or executes things on its own

usb keyloggers have existed since just after USB came out, and badusb is totally a thing.

Re: I Tested an HDMI Adapter That Demands Your Location and Spams You with Ads

#83
post #80

Earlier quoted context omitted.

The official Apple HDMI adapter does the same thing with an SoC in there. The difference is native iOS support instead of a 3rd party app needed to support it.

I still find it hilarious that that’s how the old cable worked, the iPhone encoded an H.264 video stream and sent it to the dongle, which decoded it and sent it down HDMI. Now that iPhones have USB-C they no longer need a custom adapter. A standard USB-C to HDMI cable is supposed to work. I believe.

Thing is, I thought Lightning had that too? HDMI or DP over the wire? Guess I was wrong...

Re: I Tested an HDMI Adapter That Demands Your Location and Spams You with Ads

#84
post #15

Given that the device is plugged in, trusted, shows up as a computer, and requires external power, it has all the connections it needs spy on the screen (at minimum) and remote control the victim iPhone without permission in the worst case. (it has video feed, and can emulate USB keyboard and mouse) Yikes!

It's not THAT weird. Lightning can't carry HDMI at all so even Apple's official adaptor is essentially setting up an Airplay connection over USB and has an ARM SoC to handle it. I'm guessing 3rd parties can't do the same trick without Apple's blessing which results in scary seeming workarounds.

Do you have a source on that? I ask because it’s genuinely such a cool thing but I can’t find anything about it online even though I have seen this mentioned before.

Re: I Tested an HDMI Adapter That Demands Your Location and Spams You with Ads

#85
post #84

Earlier quoted context omitted.

It's not THAT weird. Lightning can't carry HDMI at all so even Apple's official adaptor is essentially setting up an Airplay connection over USB and has an ARM SoC to handle it. I'm guessing 3rd parties can't do the same trick without Apple's blessing which results in scary seeming workarounds.

Do you have a source on that? I ask because it’s genuinely such a cool thing but I can’t find anything about it online even though I have seen this mentioned before.

https://www.theverge.com/2013/3/1/4055758/why-does-apples-li...

Re: I Tested an HDMI Adapter That Demands Your Location and Spams You with Ads

#87
post #85
post #84

Earlier quoted context omitted.

Do you have a source on that? I ask because it’s genuinely such a cool thing but I can’t find anything about it online even though I have seen this mentioned before.

https://www.theverge.com/2013/3/1/4055758/why-does-apples-li...

Seems to have been debunked.

Re: I Tested an HDMI Adapter That Demands Your Location and Spams You with Ads

#88
post #77

Earlier quoted context omitted.

Can't wait for the consumer keyboard that saves everything that was typed to it and/or executes things on its own

usb keyloggers have existed since just after USB came out, and badusb is totally a thing.

They have, but all of them are "personalized" attacks - as in, a malicious person needs to install these on specifically your computer, without your knowledge. What I was talking about is some kind of device from some noname Chinese manufacturer that presents as harmless, but actually sends off some additional data back home

Re: I Tested an HDMI Adapter That Demands Your Location and Spams You with Ads

#89

> I decided to connect the cord using an old iPhone that I no longer use and that no longer has anything I care about on it. Uh oh. Hope that means securely wiped and not just "I deleted the notes and photos and put in a drawer."

It's far easier just to securely wipe. Half a dozen taps, not including passphrase input.

Re: I Tested an HDMI Adapter That Demands Your Location and Spams You with Ads

#90
post #15

Given that the device is plugged in, trusted, shows up as a computer, and requires external power, it has all the connections it needs spy on the screen (at minimum) and remote control the victim iPhone without permission in the worst case. (it has video feed, and can emulate USB keyboard and mouse) Yikes!

It's not THAT weird. Lightning can't carry HDMI at all so even Apple's official adaptor is essentially setting up an Airplay connection over USB and has an ARM SoC to handle it. I'm guessing 3rd parties can't do the same trick without Apple's blessing which results in scary seeming workarounds.

[deleted]
Post reply on HN