Live data from Hacker News

O.mg Cable

shop.hak5.org

121–130 of 555 posts

Re: O.mg Cable

#121
post #39

Earlier quoted context omitted.

Interesting. I'm not sure if that is for pre-programmed payloads or not

As was posted in a separate thread, you might look at http://tomu.im/ too

Those are pretty cool. One of the big use-cases for me is small-form-factor USB-passthru sniffing, however. I don't think any of the Tomu devices have that but would definitely be an option if so.

Re: O.mg Cable

#122
post #95
post #44

See also: C-to-C charger cables with Bluetooth remote activated dual payloads: https://sneaktechnology.com/product/usbninja-custom-type-c-t... I easily modified mine to mimmic Apple Keyboard USB IDs to avoid notifications. Works great! Cellular GPS tracking car charger: https://www.amazon.com/Charger-Locator-Professional-Listenin... Cellular GPS tracking USB charger cable: https://www.ebay.com/itm/223990414124 I have…

With growing car theft in the US I've been curious about implanting GPS trackers on my own older enthusiast vehicles. There appears to be many options on Amazon but I can't bring myself to trust any of them. Has anyone here gone down that road before?

If you want to diy it, Check out ray Ozzie's recent project featured here on HN recently. Very reasonable priced with one up front payment for (10 ?) years of connectivity

Re: O.mg Cable

#123

Earlier quoted context omitted.

Is that USB-PD compatible?

The "USB condoms" I know are USB2/3 only which means there isn't any form of PD negotiation anyway, and the oldschool Qualcomm Quickcharge and Apple's negotiation won't work either as these depend on D+/D-. A decent USB-C condom would also have to cut not just the USB2 D+/D- line, but also the USB3 SS and SBU lines... the really interesting thing is the CC wires, since without these you can't have reversible connecto…

You don't need orientation handling if you've cut all the other signals, so...

Power negotiation is also not a big problem. Just use a correct resistor on the CC pin and you can make the phone use up to 5V/3A, which is plenty for any smartphone. You'd have to make sure to use a 5V/15W capable power source, though.

Re: O.mg Cable

#124
post #95

Earlier quoted context omitted.

With growing car theft in the US I've been curious about implanting GPS trackers on my own older enthusiast vehicles. There appears to be many options on Amazon but I can't bring myself to trust any of them. Has anyone here gone down that road before?

AirTag

Doesn’t work as it notifies the person traveling with it.

Re: O.mg Cable

#125
post #91

Earlier quoted context omitted.

I would expect nothing, because the security we put ourselves through is nowhere close to sophisticated enough to notice.

I'm pretty sure this would look kind of weird under xrays. They probably see thousands of cables and it'd be pretty easy to spot the difference.

Standard Apple cables already have a chip inside, and USB 3.1 cables are also supposed to have chips inside.

I would also assume they are not paying enough attention to even notice, there is no regulation against them so there is no reason to even train to notice differences in USB cables.

> They probably see thousands of cables and it'd be pretty easy to spot the difference.

If anything seeing thousands of cables will make them less likely to notice anything, change blindness is a real problem in jobs like that.

Re: O.mg Cable

#126
post #91

Earlier quoted context omitted.

I would expect nothing, because the security we put ourselves through is nowhere close to sophisticated enough to notice.

I'm pretty sure this would look kind of weird under xrays. They probably see thousands of cables and it'd be pretty easy to spot the difference.

They see thousands of cables and probably don't give any a second glance for the bare few seconds they gaze at each bag, an extra IC or two in the connector or not.

The sheer volume of bags that get run through those x-ray machines in a shift, and the time given to look at each one precludes too much fine grained inspection, especially for something as minor as cables.

Airport security is pretty dismal at detecting actual weapons or contraband, why should they be any better at noticing a slightly different cable?

Re: O.mg Cable

#127
post #6

Earlier quoted context omitted.

That level of miniaturization is far older than Apple's removal of the iPhone headphone jack in 2016, but the related lightning-to-audio jack dongle had a microcontroller with a DAC inside that you'd never think existed due to the form factor.

The Lightning-to-HDMI adapter is also an insane miniaturization. It runs a (very) stripped down version of iOS/darwin (not sure what apple counts it as) that is loaded in about a second when you plug in the phone, establishes a network connection, and streams compressed video frames over the network over USB to the HDMI. That's why when you use the iPhone HDMI adapter, everything looks a little bit compressed. Becaus…

Yup. It's actually an incredibly clever piece of tech that lets the iPad/iPhone get around the fact that lightning doesn't have enough bandwidth to transmit HDMI.

For regular home/app views, it does hardware compression of the iPad's screen, outputs that over lightning, then the adapter decompresses it to raw HDMI.

While for Netflix/etc. streams, it outputs the stream directly to the adapter to decompress, without quality loss. (And at full size as well, rather than double-letterboxed.)

I still haven't figured out the magic of how apps like Netflix are able to do overlays of subtitles on top of the compressed video stream. Best I can tell, there must be a separate API for that, that gets sent in parallel.

Re: O.mg Cable

#128

This makes me miss older, simpler protocols. Sure, a parallel cable could also be compromised to snoop but at least it couldn't pretend to be some other device or install rootkits.

Challenge accepted. Any time you have physical access (especially HID), you have the potential for exploits.

I couldn't find much for parallel port hax (in 5 min googling), but I'm sure it's been done. Probably too old to be documented on the shallow web.

https://www.quora.com/Can-a-computer-be-hacked-through-a-PS-...

Re: O.mg Cable

#129
post #96
post #87

Earlier quoted context omitted.

What was the codename for the project to create that system?

Probably “Project Phoenix”. If you ask any project team to come up with a project name they will probably pick ‘Project Phoenix’.

Because all project work is reviving something that has been done before?

Re: O.mg Cable

#130

As an aside: somewhat ironic that a shop selling gear such as this has such a large 3rd-party javascript footprint. At least some of that js is required for the page to work, as I'm unable to see pictures of the device. I counted 25 3rd party domains in uMatrix. That's quite the attack surface.

It threw a modal at me after enabling scripts and scrolling a bit. Yeah, not reading further.
Post reply on HN