Live data from Hacker News

O.mg Cable

shop.hak5.org

181–190 of 555 posts

Re: O.mg Cable

#181
post #139
post #79

Earlier quoted context omitted.

We just broke the locks on the cages with a screwdriver. Locks only keep honest people honest.

I don't expect good locks to keep people out. I expect good locks to be tamper evident so I know I can't trust my system.

The lock doesn't even need to be that good. As you said, the name of the game is intrusion detection, not necessarily intrusion avoidance.

The Lock Picking Lawyer chronicled very nicely a technique for turning a KW1-keyed Kwikset core (extremely common here in the US) into something that is tamper evident. See the YouTube video linked herein.

https://www.youtube.com/watch?v=7JlgKCUqzA0

This kind of thing thwarts covert attack attempts and serves as a good way to trigger an audit on the trust of the asset behind that lock.

Re: O.mg Cable

#182

Been a follower of Hak5 since way back in the day. Even crashed at the hak house with Darren a long time ago. Cool to see them here since they actually hack stuff haha.

Was very fortunate to meet Darren, Shannon, and Patrick Norton at Defcon in 2019.

It was surreal to see them and even though I probably acted all nervous around them (still kinda had a crush on Shannon even after all these years) they were beyond nice and friendly.

They were super busy selling their kits (these OMG cables were being sold unofficially as well lol) but they took the time to chat about the history of Hak5(TechTV in the case of Patrick) and to take pics. All around a superb bunch of folks.

Its crazy to think they have been doing Hak5 for like what 15-16 years now?! So many great memories all thanks to their hard work.

Re: O.mg Cable

#183

Earlier quoted context omitted.

The real answer? Because these people are just like us, geeks, nerds, techies, early adopters. They are just the same people we live and work with. The film Enemy of the State (1998) was science fiction except with the parts where the techy operators were just normal nerds like us. That what was most scary part of the film not the (at the time fantastic) surveillance.

They are really quite unlike us. And our sets of norms is, shall we say, somewhat different to theirs.

Morality is the difference. That's not exactly "norms" but somewhat on an adjacent path. But in terms of interest and participation in our club, *they are us*. That's the true terrible reality.

A more accessible idea which is quite different but allows some truth to shine in similarly is to consider how many of us are utterly dependent on advertising in our careers but we all adblock personally.

Re: O.mg Cable

#184
post #6

Earlier quoted context omitted.

That level of miniaturization is far older than Apple's removal of the iPhone headphone jack in 2016, but the related lightning-to-audio jack dongle had a microcontroller with a DAC inside that you'd never think existed due to the form factor.

The Lightning-to-HDMI adapter is also an insane miniaturization. It runs a (very) stripped down version of iOS/darwin (not sure what apple counts it as) that is loaded in about a second when you plug in the phone, establishes a network connection, and streams compressed video frames over the network over USB to the HDMI. That's why when you use the iPhone HDMI adapter, everything looks a little bit compressed. Becaus…

Ok, this is the most amazing tidbit I've learned in this site in months.

Thanks for the comment. Had no idea. Mind blown.

Re: O.mg Cable

#185
post #28
post #19

Earlier quoted context omitted.

A cable that costs $20 - $30 retail NEW doesn't seem worth risking jail time over.

There's no risk of jail for theft in Seattle. https://crosscut.com/2019/10/whats-seattle-doing-solve-its-s...

And people wonder why there is so much crime...

Re: O.mg Cable

#186
Who buys this stuff? Other things in the shop:

> Screen Crab: This covert inline screen grabber sits between HDMI devices - like a computer and monitor, or console and television - to quietly capture screenshots. Perfect for sysadmins, pentesters and anyone wanting to record what's on a screen.

> Shark Jack: This portable network attack tool is a pentesters best friend optimized for social engineering engagements and opportunistic wired network auditing. Out-of-the-box it's armed with an ultra fast nmap payload, providing quick and easy network reconnaissance.

> Key Croc: The Key Croc by Hak5 is a keylogger armed with pentest tools, remote access and payloads that trigger multi-vector attacks when chosen keywords are typed. It's the ultimate key-logging pentest implant.

They say "pentesters." What prevents a malicious actor from buying and using these tools?

I think I am missing something here.

Re: O.mg Cable

#187
post #186

Who buys this stuff? Other things in the shop: > Screen Crab: This covert inline screen grabber sits between HDMI devices - like a computer and monitor, or console and television - to quietly capture screenshots. Perfect for sysadmins, pentesters and anyone wanting to record what's on a screen. > Shark Jack: This portable network attack tool is a pentesters best friend optimized for social engineering engagements and…

I think you are missing nothing.

Re: O.mg Cable

#188
post #137
post #95

Earlier quoted context omitted.

With growing car theft in the US I've been curious about implanting GPS trackers on my own older enthusiast vehicles. There appears to be many options on Amazon but I can't bring myself to trust any of them. Has anyone here gone down that road before?

-Wouldn't an airtag (or two...) fit the bill nicely? (Assuming even car thieves use iPhones there's some poetic justice to be served in their own smartphones bringing them down...)

They will get a warning saying there is an air tag travelling with them. I have this problem. We have an air tag on one of my kids shoes when we are out, and whenever I’m not with them, my partner gets spammed with warnings on her phone saying there is an unknown air tag travelling with her.

Re: O.mg Cable

#189
post #186

Who buys this stuff? Other things in the shop: > Screen Crab: This covert inline screen grabber sits between HDMI devices - like a computer and monitor, or console and television - to quietly capture screenshots. Perfect for sysadmins, pentesters and anyone wanting to record what's on a screen. > Shark Jack: This portable network attack tool is a pentesters best friend optimized for social engineering engagements and…

I have a number of hak5 products to see what they fuss is about and to learn what kinds of attacks to worry about being used on me! In some cases they are not really usable anymore, like the WiFiPineapple, which is largely useless due to WPA2 being ubiquitous (yes, you can hack WPA2 but I don't feel like paying for a ton of AWS lamda functions to get on my neighbors wifi). They teach you about how things work from an entirely different point of view. BashBunny is my favorite and it still works, but who plugs in random USB sticks these days? I've never used it but I learned a lot more about USB!

Re: O.mg Cable

#190

Earlier quoted context omitted.

Just park with your windows open if there's nothing they can really take. Repairing the window isn't with the cost or the time.

As clever as this idea sounds, it's not a good suggestion. I once accidentally left my windows down in SF for 12 hours and my car was essentially stripped clean - headrests, registration, proof of insurance, manual, floor mats - all gone. Additionally all my doors and trunk were wide open.

Sounds horrible and for me it is unimaginable. In Croatia, you rarely hear that a car waa broken into even in bigger cities. In smaller towns a lot of people don't even bother to lock their cars.
Post reply on HN