Live data from Hacker News

FBI is warning people against using public phone-charging stations

schneier.com

201–210 of 328 posts

Re: FBI is warning people against using public phone-charging stations

#201
post #165

Earlier quoted context omitted.

It just doesn't seem like a plausible hack when you take in all the circumstances that have to line up correctly: 1. The station has to be using USB Ports / Charging cables that are data enabled, not just cables that carry power 2. The hacker would need some way of injecting the malware into the charging station ports without being seen, I doubt many charging stations are internet connected so you would have to be at…

None of these are necessary, except half of #2. All you'd need is a "middleman" device that is subtle enough to avoid notice by the person plugging in, just like how credit card skimmers work. > 1. The station has to be using USB Ports / Charging cables that are data enabled, not just cables that carry power Doesn't matter, because you're (unwittingly) plugging into the attacker's device, not the station's. > 2. The…

> They'll plug in the phone, unlock it, and browse the internet.

iOS devices (maybe Android too, idk) ask you if you want to allow new accessories to access your device. That's why they said you need an exploit.

Re: FBI is warning people against using public phone-charging stations

#202
post #165

Earlier quoted context omitted.

It just doesn't seem like a plausible hack when you take in all the circumstances that have to line up correctly: 1. The station has to be using USB Ports / Charging cables that are data enabled, not just cables that carry power 2. The hacker would need some way of injecting the malware into the charging station ports without being seen, I doubt many charging stations are internet connected so you would have to be at…

None of these are necessary, except half of #2. All you'd need is a "middleman" device that is subtle enough to avoid notice by the person plugging in, just like how credit card skimmers work. > 1. The station has to be using USB Ports / Charging cables that are data enabled, not just cables that carry power Doesn't matter, because you're (unwittingly) plugging into the attacker's device, not the station's. > 2. The…

I'm confused about #1. If I have a power adapted plugged into the wall, and a USB cable from that power adapted to my phone, how exactly could my phone be compromised?

Re: FBI is warning people against using public phone-charging stations

#203
post #22

Earlier quoted context omitted.

You can use a power only cable.

Where can I get one and how can I verify it is what it says?

> Where can I get one

Yeah, people usually have the opposite problem. You just search for power-only cable.

> how can I verify

Plug it into your phone and your computer. None should see the other, but the phone should charge.

And then tag it, because having all kinds of cables exactly alike is the worst decision the USB designers ever made.

Re: FBI is warning people against using public phone-charging stations

#204

But how? Most devices are charge-only by default, most users have USB debugging disabled, and those who know how to enable it, won't allow the adb server to connect to the phone (you have to explicitly give it permission).

> But how?

Ask that your average parent using an Android 6 from a decade ago, not being able to update because the manufacturer decided to not support their devices anymore after a year.

There is no such thing as an updateable Android, because something will always be outdated. Even lineageOS builds are using decades old kernels and kernel mods that have never been backported or upstreamed.

Android has a huge update problem. I'd probably bet that stagefright or, say, the pegasus zeroday for whatsapp works still on a large percentage of devices even though it was leaked more than 5 years ago.

Re: FBI is warning people against using public phone-charging stations

#205
post #165

Earlier quoted context omitted.

None of these are necessary, except half of #2. All you'd need is a "middleman" device that is subtle enough to avoid notice by the person plugging in, just like how credit card skimmers work. > 1. The station has to be using USB Ports / Charging cables that are data enabled, not just cables that carry power Doesn't matter, because you're (unwittingly) plugging into the attacker's device, not the station's. > 2. The…

I'm confused about #1. If I have a power adapted plugged into the wall, and a USB cable from that power adapted to my phone, how exactly could my phone be compromised?

The attack involves placing a device between the cord and the wall.

Re: FBI is warning people against using public phone-charging stations

#206

But how? Most devices are charge-only by default, most users have USB debugging disabled, and those who know how to enable it, won't allow the adb server to connect to the phone (you have to explicitly give it permission).

> But how? Ask that your average parent using an Android 6 from a decade ago, not being able to update because the manufacturer decided to not support their devices anymore after a year. There is no such thing as an updateable Android, because something will always be outdated. Even lineageOS builds are using decades old kernels and kernel mods that have never been backported or upstreamed. Android has a huge update…

Hmm, if someone is using a phone from a decade ago, they will certainly be vulnerable to evil charging stations, as their battery will almost certainly be extremely tired (then again, phones that old were a lot easier to replace batteries in, so maybe there's some hope).

Re: FBI is warning people against using public phone-charging stations

#208

It really surprised me when this article blew up on Twitter as I thought it was common knowledge to never use public chargers and avoid untrusted usb anything after “bad usb”. It showed me how I live in a tech security bubble-a good reminder.

Everyone wants everyone to be more informed about their subject matter area, but there just isn’t enough cognitive load for it all.

I’d like to just rely on my device to protect me by asking if I want to trust the device.

Re: FBI is warning people against using public phone-charging stations

#209
post #165

Earlier quoted context omitted.

None of these are necessary, except half of #2. All you'd need is a "middleman" device that is subtle enough to avoid notice by the person plugging in, just like how credit card skimmers work. > 1. The station has to be using USB Ports / Charging cables that are data enabled, not just cables that carry power Doesn't matter, because you're (unwittingly) plugging into the attacker's device, not the station's. > 2. The…

> They'll plug in the phone, unlock it, and browse the internet. iOS devices (maybe Android too, idk) ask you if you want to allow new accessories to access your device. That's why they said you need an exploit.

“This fast charge station requires accessories access to your device for high speed charging”

Anyone who would believe a notice like that (or would click trust without thinking) is a prime target.

It’s like many scam/spam emails- they often intentionally look a bit dubious, poor grammar, typos etc as the attacker just wants to deal with low hanging fruit, not someone who may wise up quickly that something isn’t right.

Re: FBI is warning people against using public phone-charging stations

#210
We badly need a DC electrical plug/jack standard that doesn't play double-duty as a data transmission standard. Innumerable small appliances and devices use DC power, solar panels make DC power, yet if you want to charge such devices you have to go through a DC->AC->DC conversion, or use USB which can evidently pwn your devices. What a sorry state of affairs.
Post reply on HN