Live data from Hacker News

I Tested an HDMI Adapter That Demands Your Location and Spams You with Ads

404media.co

101–110 of 132 posts

Re: I Tested an HDMI Adapter That Demands Your Location and Spams You with Ads

#102

I say the big 404 and instinctively bounced. I can’t be the only one. I went back to find their 404 page and am quite satisfied with what I found: https://www.404media.co/i-te/

The cyberdemon really ties the room together.

dont forget to click here

Re: I Tested an HDMI Adapter That Demands Your Location and Spams You with Ads

#103
post #96

Earlier quoted context omitted.

Not at all. Usbc is just the connector. Running display port graphics over usbc is no less safe than using a bigger display port connector.

Can a rogue displayport peripheral present as a storage device, keyboard, etc?

Answer is "it depends".

USB-C always has a usb2 channel available, then 4 lanes that can be display port or thunderbolt or usb2/3 or whatever else.

This is why most android phones have options for USB including "charge only".

Re: I Tested an HDMI Adapter That Demands Your Location and Spams You with Ads

#104

I say the big 404 and instinctively bounced. I can’t be the only one. I went back to find their 404 page and am quite satisfied with what I found: https://www.404media.co/i-te/

I’ve seen a few 404 Media articles on here as of late and I’ve been pleasantly surprised by the high quality of the content.

their podcast is also quite good

Re: I Tested an HDMI Adapter That Demands Your Location and Spams You with Ads

#105
post #70

Earlier quoted context omitted.

But pairing work well without the app involved, we could just give a permission to a specific already-paired devices and keep location for apps that actually need to scan.

Again - That still sends out a beacon. Searching for already-paired bluetooth devices still sends a bluetooth frame with your bluetooth MAC address, (which has to be consistent, because that's how bluetooth devices identify each other).

> Searching for already-paired bluetooth devices still sends a bluetooth frame with your bluetooth MAC address, (which has to be consistent, because that's how bluetooth devices identify each other).

It doesn't have to be readable by third parties. Given that the devices are already paired, it's perfectly feasible for that frame to be encrypted gibberish that only the other device can understand.

Re: I Tested an HDMI Adapter That Demands Your Location and Spams You with Ads

#106
post #41

Earlier quoted context omitted.

Ah yes, the many apps poor Android users are forced to sideload. As an Android user myself, so far I'm up to...zero?

Does Google ban apps that break if location information is denied? The last time I checked, Apple did and Google did not.

I wouldn’t expect better of Google. An app like Google Photos on iOS should (in my opinion) be banned because it requires access to all locally saved photos, breaking if either no access or selective/additive photo access is used.

Re: I Tested an HDMI Adapter That Demands Your Location and Spams You with Ads

#107
post #77

Earlier quoted context omitted.

Can't wait for the consumer keyboard that saves everything that was typed to it and/or executes things on its own

Yeah, it was sold to schools in the 90s. https://en.wikipedia.org/wiki/AlphaSmart

Oh yeah, I remember reading about the AlphaSmart somewhere! Though it is quite different from an ordinary-keyboard-looking spying device that I tried to describe in my original comment. The AlphaSmart feels like more of a digital typewriter that just had a really primitive data transfer method

Re: I Tested an HDMI Adapter That Demands Your Location and Spams You with Ads

#108
So, a trojan device that makes the user give it basically full control over their phone, allowing a third party to do whatever the hell they want with the user's data and accounts - and what does it actually do? Show targeted ads.

Truly the dumbest timeline.

Re: I Tested an HDMI Adapter That Demands Your Location and Spams You with Ads

#109
post #15

Given that the device is plugged in, trusted, shows up as a computer, and requires external power, it has all the connections it needs spy on the screen (at minimum) and remote control the victim iPhone without permission in the worst case. (it has video feed, and can emulate USB keyboard and mouse) Yikes!

Agreed. If you want to prove to yourself that this vulnerability is real, consider that you can replicate the hypothesized malicious device you describe by taking a WiFi Duck https://wifiduck.com/ and combining it with a regular lightning-to-HDMI adapter by plugging the WiFi Duck into the extra lightning port on the HDMI adapter. All that would be needed to use this attack on an unsuspecting victim would be to combine the WiFi Duck and the HDMI adapter functionality into a small enough circuit board to fit into the Apple-style white enclosure.

Re: I Tested an HDMI Adapter That Demands Your Location and Spams You with Ads

#110
We need to think about the role of government in regulating consumer electronics. Should the government require companies to disclose more information about the security and privacy risks of their products? Should the government ban the sale of products that pose a significant security risk?

The lack of transparency on the security details will take a toll on the consumers in the coming future.

Post reply on HN