Live data from Hacker News

USB Killer

kukuruku.co

151–160 of 198 posts

Re: USB Killer

#151
Best comment from the page: "It needs to have en eInk display to say 128, 129"

Such yes.

...

I was walking past a tall wooden fence the other day, you know the kind you see outside a building site. As I walked along beside it I heard chanting coming from behind the fence further up... they were chanting numbers, or rather just one number. "Thirteen, thirteen, thirteen, thirteen, ..." they excitedly chanted. It sounded like a small crowd, young and old; men, women and children. All of them saying the same number over and over. As I approached I saw a small hole in the fence just big enough to look through. The hole was right where the sound appeared to be originating from. So, with the crowd continuing to chant "... thirteen, thirteen, thirteen, thirteen" and it seeming to become more intense as I leaned down to place my eye at the hole and work out WTF was happening in there. Just as I put my eye to the hole a small finger like that of a child poked me in the eye and the crowd stared cheered loudly and started chanting again.. "Fourteen, fourteen, fourteen..."

Re: USB Killer

#152
post #22

Someone joked that this would be useful to ensure people won't randomly plug USB drives into their computers. Sounds insane, except that... "During a stop-over in Hong Kong, he finds a spare USB key in his hotel room. Curious, he inserts it into his laptop. By the time he arrives in Australia, his computer is infected."[1] This was the one of the infection vectors for a large flare-up between the Chinese government a…

A standard procedure in somewhat-security-concerned firms is that when you travel, you go and get a freshly installed travel laptop (a loaner) from IT dept, use it on the trip, and after the trip, you return it to the department that wipes out everything on the disk and re-images it. This wouldn't protect against things like firmware-based malware, attacks that major three-letter spy agencies could deploy when they f…

>A colleague of mine purchases fresh laptops for when he goes overseas and then never uses them again. He doesn't even work in an industry where commercial secrets are common. I'd hope that anywhere that features security implications or commercial secrets would also act at this level.

IMO that's an overkill. Why not just use ICloak [1] or Tails [2]? They are both Linux distributions which boot from USB stick without touching hard drive, randomize MAC address and give you access to Tor and other goodies.

[1]: https://icloak.org/

[2]: https://tails.boum.org/

Re: USB Killer

#153

One could give these out to activists around the world, they seem to be always at risk of getting their electronic devices confiscated by law enforcement.

They have it bad enough already without adding felony charges for destruction of government property.

What about putting it in a plastic bag, with big sticker - "DO NOT PLUG THIS INTO ANY DEVICE. " :)

Re: USB Killer

#154
post #22

Someone joked that this would be useful to ensure people won't randomly plug USB drives into their computers. Sounds insane, except that... "During a stop-over in Hong Kong, he finds a spare USB key in his hotel room. Curious, he inserts it into his laptop. By the time he arrives in Australia, his computer is infected."[1] This was the one of the infection vectors for a large flare-up between the Chinese government a…

When I read some of that stuff back in 2010 I was curious why some of the targets didn't try to understand how they were compromised and then publish the details. Especially attacks with such an, errr, tangible vector of infection.

Clearly some attacks are quite stealthy and difficult to characterize, but some are not, and in the 2010-era reporting about Chinese computer espionage against travelers to China many targets seemed to believe that they had confirmed the compromises.

So people could have taken a computer with some extra sensors or logging processes, a different OS than usual, and then publish the results, helping defend similarly situated others, including their own coworkers. If they believe the attacks are pervasive today, they could do this today.

Re: USB Killer

#155

Earlier quoted context omitted.

A standard procedure in somewhat-security-concerned firms is that when you travel, you go and get a freshly installed travel laptop (a loaner) from IT dept, use it on the trip, and after the trip, you return it to the department that wipes out everything on the disk and re-images it. This wouldn't protect against things like firmware-based malware, attacks that major three-letter spy agencies could deploy when they f…

>A colleague of mine purchases fresh laptops for when he goes overseas and then never uses them again. He doesn't even work in an industry where commercial secrets are common. I'd hope that anywhere that features security implications or commercial secrets would also act at this level. IMO that's an overkill. Why not just use ICloak [1] or Tails [2]? They are both Linux distributions which boot from USB stick without…

Customs officals are agents of another, sometimes hostile, power.

If your risk assessment says you're worried about AoHPs then you can't trust your computer after they've had it in their possession.

Re: USB Killer

#156

Earlier quoted context omitted.

A standard procedure in somewhat-security-concerned firms is that when you travel, you go and get a freshly installed travel laptop (a loaner) from IT dept, use it on the trip, and after the trip, you return it to the department that wipes out everything on the disk and re-images it. This wouldn't protect against things like firmware-based malware, attacks that major three-letter spy agencies could deploy when they f…

>A colleague of mine purchases fresh laptops for when he goes overseas and then never uses them again. He doesn't even work in an industry where commercial secrets are common. I'd hope that anywhere that features security implications or commercial secrets would also act at this level. IMO that's an overkill. Why not just use ICloak [1] or Tails [2]? They are both Linux distributions which boot from USB stick without…

I think the bigger concern (which has been backed up by recent research) is that there are vulnerabilities in the hardware that might be exploited to install malicious software. If that software lives in a BIOS or a hard disk firmware wiping your hard disk will not protect you.

Re: USB Killer

#157

Earlier quoted context omitted.

> Does anyone actually care that their plugs are elegant? Some people do, I think its an expression of culture. Its hard not to notice that the swiss and the nordic countries (especially Sweden and Norway) value a certain aesthetics. This expresses itself in many things, ranging from architecture to product design, art and the design of public spaces. There is a reason swiss typography was big, and why nordic design…

Relevant example from Iceland http://www.choishine.com/port_projects/landsnet/iceland.html

You're aware that's not real, right?

Re: USB Killer

#158

Reminds me of one my favorite "Bastard Operator From Hell" stories: http://www.chinet.com/html/bofh/tradeshow.html Turns out this is a very old idea. :-)

Haha very witty. Such a cynical outlook on life and people in that article.

Most definitely. There's a whole series of them: http://bofh.ntk.net/BOFH/

Re: USB Killer

#159
What if the voltage kills someone? Is it not too dangerous?

Lesson is not to use/touch the USB stuffs not belongs to you. Good moral story for 2nd grader.

Re: USB Killer

#160

Earlier quoted context omitted.

Part of the niceness of the UK plug is that if you pull the cable right out of the housing, the internals disconnect in the safest order. The plug comparison sites I've found don't discuss the internals of the plugs much; does anyone know how other plug types approach this (or do they just ignore it)? Looking at plugs, I suspect that many get round this by making the housing of the plug much more firmly attached to t…

They don't ignore it; Schuko (CEE 7/3) plugs also keep earth connected while live and neutral pins are pulled out. Same is true for the French (CEE 7/5) and Danish (107-2-D1) designs.

That's when you pull the plug out of the socket.

OP is talking about the failure mode when you pull the cable out of the plug - the live and neutral cables are shorter and tighter and will fail first, leaving the earth wire to fail last.

Post reply on HN