Live data from Hacker News

FBI is warning people against using public phone-charging stations

schneier.com

191–200 of 328 posts

Re: FBI is warning people against using public phone-charging stations

#191
post #189

Earlier quoted context omitted.

>(Though, yeah, I'd avoid a lot of "normal" activities if I ever attended BlackHat.) I wonder whether you‘d take similar precautions on a site named Hacker News

Accessing a known non-sketchy website? No.

hacker news is a link aggregator

Re: FBI is warning people against using public phone-charging stations

#193
post #111

Earlier quoted context omitted.

Many people, including many people on this site (and, yes, including myself) wouldn't think twice about plugging into an available port if they need a charge. Maybe I don't plug into an unlabeled port in some random location where it doesn't look like it belongs, but honestly I wouldn't think twice about charging at a designated area at a conference. (Though, yeah, I'd avoid a lot of "normal" activities if I ever att…

>(Though, yeah, I'd avoid a lot of "normal" activities if I ever attended BlackHat.) I wonder whether you‘d take similar precautions on a site named Hacker News

So far, web standards don’t support online supply of direct (constant) current, alternating (sine wave) current, they can only provide imaginary (square root of stealing your) current.

So you can’t trust any site for power.

—-

Although teleporting power Via quantum entanglement has been demonstrated as possible given a line of communication.

So crazily, “power over data” may happen one day.

Perhaps, we can all look forward to hackers draining our last 1% of battery power as a reward for not using end-to-end power encryption.

Re: FBI is warning people against using public phone-charging stations

#194

But how? Most devices are charge-only by default, most users have USB debugging disabled, and those who know how to enable it, won't allow the adb server to connect to the phone (you have to explicitly give it permission).

I believe the assertion is "just because you don't know ow how to do it doesn't mean it can't be done." It turns out several generations of USB controllers did "undefined" things when presented with "undefined" behavior on the data pins. Sometimes "undefined" was "just doesn't work", sometimes it was "put data in physical memory, bypassing the MMU and it's data protection features." I've never seen it myself, but I w…

> I believe the assertion is "just because you don't know ow how to do it doesn't mean it can't be done."

Okay, but tell me how it can be done if you want me to take the threat seriously. You could also say “always store your phone in a sound-isolating container because attackers can hack your phone with ultrasonics.”

Re: FBI is warning people against using public phone-charging stations

#195

It really surprised me when this article blew up on Twitter as I thought it was common knowledge to never use public chargers and avoid untrusted usb anything after “bad usb”. It showed me how I live in a tech security bubble-a good reminder.

> common knowledge to never use public chargers Perhaps here on HN. Most people will plug their smartphone into any accepting receptacle. trains, airplanes, NYC SmartLink, or ask the bartender if they can plug it in behind the bar. I still carry a DIY Altoids charger that takes a 9V battery (pulled down to proper volts for iPhone). In a battery emergency, my phone is simply on life support and I don't have to look fo…

I try to always travel with a “USB data condom”. The one I have is called a “PortaPow”, and it’s red. It was about $10 on Amazon and it’s a great investment for scenarios where I _reasonably_ trust a power-only USB port not to have been tampered with, like the built in ports on aircraft.

Re: FBI is warning people against using public phone-charging stations

#196

Anker batteries come in a zillion sizes, are cheap and are safe to plug into public chargers. With how hungry phones are these days, I don't know how people live without portable batteries.

For my own needs, carrying a compact foldable GaN power brick like the Anker 511 (or 747, if carrying my laptop) has been sufficient. Sleeping MacBooks also work as extremely fancy extremely high capacity power banks if the need arises, which in the past has covered the odd case where I'm not near an AC outlet.

I also travel with a compact Anker GaN charger and I _love_ that thing.

Re: FBI is warning people against using public phone-charging stations

#197

Earlier quoted context omitted.

The malicious charger can pretend to be keyboard, mouse and screen, and just remote control the phone. Or just a keyboard, if you want to an easier implementation. At least Android phones are completely usable this way, with universal keyboard/mouse support and widespread USB-C display support. Without any confirmation steps.

If a keyboard is the attack vector, what I don't get is: why not suggest people lock their phones and charge them when they're locked? Or maybe even shut them down and charge them before booting. Is there any reason not to suggest those? It certainly seems more practical than telling people they're out of luck, unless there are other attack vectors - in which case, what are they?

Most people use public charging ports are the same ones who want to use their phone while charging.

Physical security is also a consideration, I wouldn't really suggest that people leave their phones plugged into the wall in a public or semi-public place.

Re: FBI is warning people against using public phone-charging stations

#198

I don't use public chargers, and I use USB condoms for charging my devices even with chargers I own, because basically all the charging devices are made in untrustable supply chains. I thought this was common knowledge, and basically what everyone is doing. Wireless charging helps a lot with this, and I now prefer wireless charging whenever possible. The only devices I connect my devices to using USB are computers I…

> USB condoms I have one of these. I like that I can look in it and see that it has no data pins > Wireless I know you meant charging, but for data, with some of the spy cables out there with embedded chips and wireless access, it's ironic that wireless is in some ways more secure.

The wireless charging port is an specialized one. That's why it's more secure. The wireless data transfer options vary from "it's broken, forget about it" to actually quite secure, but the charging isn't done through them.

When people decided to use USB for everything, well, they had to make USB support every use case.

Re: FBI is warning people against using public phone-charging stations

#199

I'm seeing a lot of hysteria in response to this random tweet by the Denver FBI's social media person. Do we know of a single real-world use of this hypothetical exploit? Do we know that iOS's (and presumably Android's) protection against untrusted device access isn't enough?

We do know of shady companies that sell "own this phone" USB devices to governments, but AFAIK they only sell to governments and the details aren't available to the public.

I have never heard about a non-government sponsored attacker doing that kind of thing. If this is relevant or not to you, it's a matter of your threat model. If I were a journalist, I would be very weary. Personally, I don't plug my phone on random outlets and don't plug random devices on my computers, but it's clearly an overreaction.

Re: FBI is warning people against using public phone-charging stations

#200
post #111

Earlier quoted context omitted.

Many people, including many people on this site (and, yes, including myself) wouldn't think twice about plugging into an available port if they need a charge. Maybe I don't plug into an unlabeled port in some random location where it doesn't look like it belongs, but honestly I wouldn't think twice about charging at a designated area at a conference. (Though, yeah, I'd avoid a lot of "normal" activities if I ever att…

I've had booths on cyber security trade fairs hand out USB flash drives as prizes for spinning a wheel, with no awareness how that might seem odd. I guess people would be reluctant to accept them at BlackHat, but everywhere else people are very trusting towards USB stuff.

I once worked at a place where the security team had a USB stick delivered to all the desktops with some digital brochure about not trusting strangers or some such. Not the cyber security team, but still.
Post reply on HN