FBI is warning people against using public phone-charging stations
161–170 of 328 posts
Re: FBI is warning people against using public phone-charging stations
#162But how? Most devices are charge-only by default, most users have USB debugging disabled, and those who know how to enable it, won't allow the adb server to connect to the phone (you have to explicitly give it permission).
Re: FBI is warning people against using public phone-charging stations
#163Earlier quoted context omitted.
I don't get it, even after I reset my phone it's still locked, and by default not sharing data via USB. What am I missing?
https://en.wikipedia.org/wiki/BadUSB
Re: FBI is warning people against using public phone-charging stations
#164Earlier quoted context omitted.
If you can connect your turned off phone to your computer and start a reset, then that’s never going to be enough. If you want data safety, you must skip the data pins. If you want current safety, you must skip public chargers.
I don't get it, even after I reset my phone it's still locked, and by default not sharing data via USB. What am I missing?
Not "sharing data" doesn't really mean not sharing data.
Re: FBI is warning people against using public phone-charging stations
#165I'm seeing a lot of hysteria in response to this random tweet by the Denver FBI's social media person. Do we know of a single real-world use of this hypothetical exploit? Do we know that iOS's (and presumably Android's) protection against untrusted device access isn't enough?
It just doesn't seem like a plausible hack when you take in all the circumstances that have to line up correctly: 1. The station has to be using USB Ports / Charging cables that are data enabled, not just cables that carry power 2. The hacker would need some way of injecting the malware into the charging station ports without being seen, I doubt many charging stations are internet connected so you would have to be at…
> 1. The station has to be using USB Ports / Charging cables that are data enabled, not just cables that carry power
Doesn't matter, because you're (unwittingly) plugging into the attacker's device, not the station's.
> 2. The hacker would need some way of injecting the malware into the charging station ports without being seen, I doubt many charging stations are internet connected so you would have to be at the device.
You don't need to "inject" anything; you just need to physically place it between the user and the actual port and disguise it enough that people not paying attention won't notice. Or even just put a fake "charging station" in a place that the station didn't have one.
> 3. You need to have an active exploit for iOS or Android (or both) that will compromise the device and steal it's data.
People are plugging in their phone so they can use it. They'll plug in the phone, unlock it, and browse the internet. What can't you do in that situation?
Re: FBI is warning people against using public phone-charging stations
#166Earlier quoted context omitted.
...leaving a literal paper trail of package location tracking? Mail fraud is considered serious. Why commit an extra crime?
Less serious than tampering with fixtures in a secure area at an American international airport?
Sure, you would be leaving evidence, but if your plan works, that evidence won't be sought out anyway.
If you sent a mysterious package, it wouldn't be strange or out-of-character for someone to investigate that package intentionally: which presents a significant attack surface for the discovery of your ruse.
Re: FBI is warning people against using public phone-charging stations
#167Earlier quoted context omitted.
Just go on a trip where you use your GPS a lot and take pictures with your phone and it will last half a day at best.
Why would GPS use more power? It’s only receiving.
Basically, the phone’s battery life depends on disabling hardware components, or running them in a low power mode, as much as possible.
Re: FBI is warning people against using public phone-charging stations
#168I suggest to get data blockers like this: https://www.amazon.com/PortaPow-NA-USB-C-Data-Blocker/dp/B08...
Re: FBI is warning people against using public phone-charging stations
#169I'm seeing a lot of hysteria in response to this random tweet by the Denver FBI's social media person. Do we know of a single real-world use of this hypothetical exploit? Do we know that iOS's (and presumably Android's) protection against untrusted device access isn't enough?
Anecdotally, I have had a previous iphone infected by using a public charging station at SFO a few years ago.