Live data from Hacker News

O.mg Cable

shop.hak5.org

171–180 of 555 posts

Re: O.mg Cable

#172
post #79

Earlier quoted context omitted.

We just broke the locks on the cages with a screwdriver. Locks only keep honest people honest.

Most common locks can be easily picked with a tiny bit of practice. I'm completely incompetent but I can pick any Master lock in 5 minutes or less.

Which is why you should never use Master Locks.

I am pretty decent at lockpicking but I can't pick a Medeco or better in any practical amount of time and very few in the world can.

Little bit more money vastly reduces your attack surface.

Re: O.mg Cable

#173
I would advise a trip to MG's own site that has a lot more technical information on the cable:

https://mg.lol/blog/

Its kind of cool to see someone I've been following for years and seeing the whole dev cycle of this product.

His exploding USB drive was pretty cool and came before this idea:

https://mg.lol/blog/mr-self-destruct/

Re: O.mg Cable

#175
post #93
post #80

Earlier quoted context omitted.

Windows and Mac users are currently easy targets. I don't know of any good defenses there. It's crazy to me that this is true. Does the government pay Microsoft and Apple to keep it this way, or are they just negligent?

It’s not really practical to defend against for most end users. Keeping a whitelist of known keyboards and mice is really the only defence even on Linux, and unless you work in a data centre that’s probably way overkill. With a home PC that doesn’t really work though, because in order to authenticate your mouse without some kind of central mouse log on a server you probably need to click a button, which you can’t do…

There are dongles that only let power through:

https://www.amazon.com/PortaPow-3rd-Data-Blocker-Pack/dp/B00...

But it's a pain in the neck to always use them and difficult to enforce use in an enterprise setting.

Re: O.mg Cable

#176
post #91

Earlier quoted context omitted.

I would expect nothing, because the security we put ourselves through is nowhere close to sophisticated enough to notice.

I'm pretty sure this would look kind of weird under xrays. They probably see thousands of cables and it'd be pretty easy to spot the difference.

Yes, perhaps. And so the day (after) someone brings down a plane with a non-standard cable, they'll start looking for cables that 'look kind of weird'.

Re: O.mg Cable

#178

Earlier quoted context omitted.

I'm in San Francisco, so not Seattle, but cars get broken into for the sport of it by this point. A friend's had her window broken and used, gross dog leashes and an old Nokia charger stolen. The lost hours of work to replace the window was the real cost to her dog walking business.

Just park with your windows open if there's nothing they can really take. Repairing the window isn't with the cost or the time.

My friend visited a car breakin prone area in canada once, and left his car unlocked like his girlfriend suggested. They broke his window anyway, and stole a minecraft keychain and about $4 in change.

Hilariously he actually got the stuff back eventually

Re: O.mg Cable

#179
post #95
post #44

See also: C-to-C charger cables with Bluetooth remote activated dual payloads: https://sneaktechnology.com/product/usbninja-custom-type-c-t... I easily modified mine to mimmic Apple Keyboard USB IDs to avoid notifications. Works great! Cellular GPS tracking car charger: https://www.amazon.com/Charger-Locator-Professional-Listenin... Cellular GPS tracking USB charger cable: https://www.ebay.com/itm/223990414124 I have…

With growing car theft in the US I've been curious about implanting GPS trackers on my own older enthusiast vehicles. There appears to be many options on Amazon but I can't bring myself to trust any of them. Has anyone here gone down that road before?

I would only do this if you either know the police will help retrieve your car if you have the location, or if you are ready to engage the robbers yourself. Otherwise it's useless to know where it is.

I have experience trying to get the cops to help in Oakland and San Jose and they really didn't want to.

Re: O.mg Cable

#180
post #52

Earlier quoted context omitted.

When USB came out I was working in the defence sector. We closed the vector off with cages for the PCs with tied looms under desks, epoxy in all the holes we didn’t want people to use and with threat of being in deep shit.

That's hard if your laptop relies on USB-C for charging...

I specifically don't recommend laptops that rely on USB C charging for applications where trust is critical -unless- they are running Linux with USBGuard or QubesOS.

That said I did make transparent and easily auditable USB type C condoms for one client that really wanted to use USB type C laptops.

Systems with security as a strong priority like the Librem 14 use barrel jacks for good reason.

I am in fact implying those that allow use of macbooks at coffee shops to directly access production systems at FAANG and fintech companies are taking a very inappropriate risk :-P

Post reply on HN