Live data from Hacker News

Usbkill – anti-forensic tool to halt computer when new USB device is connected

github.com

131–140 of 195 posts

Re: Usbkill – anti-forensic tool to halt computer when new USB device is connected

#131
post #112

Earlier quoted context omitted.

You can present yourself as a standard file system or some device you know has a known exploit in the driver on the other side. Then on the USB 'drive' side you have a full out arm CPU. It can issue commands too as it is connected to the serial bus. Many USB drives already have small embedded CPU in them.

>Many USB drives already have small embedded CPU in them. For most common hardware this is just an 8051 variant that sets up the USB and DMA peripherals. It's easy enough to get something more powerful, but I am doubtful you'd want to reuse consumer hardware.

The 8051 is a decently capable CPU (it is the cpu at the heart of the furby toy). At one point they built whole computer ecosystems around it. Remember the point here is to take over the computer not have a full out modern OS. They USB manufactures use them because they work well on low power and are decently cheap and small. Now most usb sticks do not do much more than like you say. But that would not stop someone from reflashing the firmware in it who is making one of these things. The use case here is different than what most people would use it for. Sometimes you will see an older ARM design too.

Re: Usbkill – anti-forensic tool to halt computer when new USB device is connected

#132
post #89
post #86

Earlier quoted context omitted.

This is a somewhat pessimistic outlook on humanity, first off I would say that those who are most commonly at risk are those with trade secrets. Patented tech and investment intel for example. As for the dissenters, I’m sure they would appreciate their co-conspirators remain secret.

> This is a somewhat pessimistic outlook on humanity, first off I would say that those who are most commonly at risk are those with trade secrets. Patented tech and investment intel for example. Can you provide any evidence at all of police or "thugs" (or anyone, really) kicking down doors to get at trade secrets being a common problem? Because there are countless news articles of police raids seizing computers to st…

The threat model in corporate espionage is absolutely one of theft of property. It’s a lot easier to steal somebody’s laptop than to hack it.

Re: Usbkill – anti-forensic tool to halt computer when new USB device is connected

#133
post #130

Earlier quoted context omitted.

Besides keyloggers, another reason people want this is because law enforcement has USB keepalive devices that will simulate mouse movement/keypresses to keep your computer from going to sleep. They do this to make sure your computer stays on and your RAM doesn't get powered off, which will allow them to read any decrypted data in memory whether or not your data is encrypted on disk. When they raid you, they come with…

How will they replug my single PSU workstation to their UPS’?

Use insulated tools and a steady hand to cut into the power cord and splice in the UPS. The UPS is configured to match phase with the power that's already in the cord.

Re: Usbkill – anti-forensic tool to halt computer when new USB device is connected

#134
post #133
post #130

Earlier quoted context omitted.

How will they replug my single PSU workstation to their UPS’?

Use insulated tools and a steady hand to cut into the power cord and splice in the UPS. The UPS is configured to match phase with the power that's already in the cord.

.. or get a HotPlug https://www.cru-inc.com/products/wiebetech/hotplug_field_kit...

Just discovered this now myself. The same company sells mouse jigglers.

Re: Usbkill – anti-forensic tool to halt computer when new USB device is connected

#135
post #118
post #84

Earlier quoted context omitted.

I've always been surprised that autorun wasn't re-enabled when app stores / code signing was introduced. If Microsoft or Apple is willing to sign an installer saying that it's something safe to install, isn't that proof enough to let it run when you insert the USB key it's on? I know this isn't really very relevant for the specific combination of installers and physical media any more, since it's rare for anyone to b…

Windows code signing does not include a step where Microsoft inspects the code. The developer gets a certificate from a commercial CA and signs the code. If the certificate is an EV certificate, that's basically it. If it's a regular certificate, Windows does a callback to Microsoft that seems to just be a popularity check --- if the certificate has been used a lot, then the prompts go away. At best, Windows code sig…

Regular developer code-signing, yes. But I'm talking about the code-signing that's done by Microsoft (rather than by your own Microsoft-signed cert) on the Microsoft Store backend; or the code-signing that's manually done by Microsoft when a third party submits a driver package to them for inclusion as a Windows update.

Re: Usbkill – anti-forensic tool to halt computer when new USB device is connected

#136
post #117

Earlier quoted context omitted.

> Investigators need the key to prevent or detect crime That's a bit scary. 'Detect crime' could be pure speculation on the polices' part. "We think you've done something bad, let us see the contents of your phone. No we don't have any evidence already as we're detecting the crime right now."

I'm not sure that would be proportionate. It's not great, but it's better than before where this kind of crime detection had much less regulation.

Get out spook.

Re: Usbkill – anti-forensic tool to halt computer when new USB device is connected

#137
not as easy but more fun to ruin the usb device.

if they use mousewiggling the screensaver could use other triggers/patterns to keep the box on. say 1 google search per 15 min minimum. randomly moving the mouse seems a good reason to shut down.

Re: Usbkill – anti-forensic tool to halt computer when new USB device is connected

#138
post #134
post #133

Earlier quoted context omitted.

Use insulated tools and a steady hand to cut into the power cord and splice in the UPS. The UPS is configured to match phase with the power that's already in the cord.

.. or get a HotPlug https://www.cru-inc.com/products/wiebetech/hotplug_field_kit... Just discovered this now myself. The same company sells mouse jigglers.

HotPlug is one of the turnkey versions of this, yes

Re: Usbkill – anti-forensic tool to halt computer when new USB device is connected

#139
post #134
post #133

Earlier quoted context omitted.

Use insulated tools and a steady hand to cut into the power cord and splice in the UPS. The UPS is configured to match phase with the power that's already in the cord.

.. or get a HotPlug https://www.cru-inc.com/products/wiebetech/hotplug_field_kit... Just discovered this now myself. The same company sells mouse jigglers.

Which is why if you want to defend against the easy versions of these and make people have to do work, only plug your desktop PCs into standalone outputs not on a surge protector.

Yes, it won't defend against cord cutting.

Edit: A more interesting defense I think would be to modify a surge protector for this specifically to defeat HotPlug. Only put your computer on a specific outlet and wire it so that if any other outlets complete circuit to kill power to the whole thing.

Re: Usbkill – anti-forensic tool to halt computer when new USB device is connected

#140

Interesting project, I'm sure this is useful for people at risk. Somewhat related, I'm wondering about the physical security of computers. There is an attack where they open your PC, take out the ram, and freeze it immediately so the bits don't decay and they can extract your encryption keys. All BIOSes have an option for cassis intrusion detection, but I've never seen a case that has the necessary cable. Has anybody…

Back in the BBS days, there were textfile describing how to wire your beige box to either turn on strong magnets or ignite termite if a case was detected. ... I don’t know of anyone actually implementing this though :)

I think in most cases the thermite trap would probably get you into more trouble for ATF violations and not even help by adding destruction of evidence and whatever they imagined was on the drive unless you had some authority like security clearence and classified documents or some sort of legal pretext to justify uses of such flammable boobytraps.
Post reply on HN