Live data from Hacker News

FBI is warning people against using public phone-charging stations

schneier.com

221–230 of 328 posts

Re: FBI is warning people against using public phone-charging stations

#221

Earlier quoted context omitted.

hacker news is a link aggregator

If you've spent any time on here you know that no one actually clicks the links to read the article. Users need only trust the pages with an orange header.

I know I don’t but surely some people do

perhaps hacker news is merely a conversation prompt aggregator

Re: FBI is warning people against using public phone-charging stations

#222

Earlier quoted context omitted.

hacker news is a link aggregator

If you've spent any time on here you know that no one actually clicks the links to read the article. Users need only trust the pages with an orange header.

I don't trust orange headers, only blue ones.

Re: FBI is warning people against using public phone-charging stations

#223

Earlier quoted context omitted.

If you've spent any time on here you know that no one actually clicks the links to read the article. Users need only trust the pages with an orange header.

I know I don’t but surely some people do perhaps hacker news is merely a conversation prompt aggregator

HN as a separate entity has practically no value, it could just be reddit.com/r/hackernews and it'd be practically the same.

Re: FBI is warning people against using public phone-charging stations

#224
post #223

Earlier quoted context omitted.

I know I don’t but surely some people do perhaps hacker news is merely a conversation prompt aggregator

HN as a separate entity has practically no value, it could just be reddit.com/r/hackernews and it'd be practically the same.

reddit doesn’t have dang

Re: FBI is warning people against using public phone-charging stations

#225

I'm seeing a lot of hysteria in response to this random tweet by the Denver FBI's social media person. Do we know of a single real-world use of this hypothetical exploit? Do we know that iOS's (and presumably Android's) protection against untrusted device access isn't enough?

Thousands of O.MG cables are out in the wild… https://shop.hak5.org/products/omg-cable

Wouldn't this be considered the same attack? Users would connect the cable, unlock their phone, and then would need to explicitly "Trust" the external device attempting to connect to their phone via USB.

I suppose the difference is that people may be using the cable to connect to a device where that prompt is expected, in contrast to the "charging port in an airport" scenario where it would seem appropriately alarming.

Re: FBI is warning people against using public phone-charging stations

#226

Earlier quoted context omitted.

Anecdotally, I have had a previous iphone infected by using a public charging station at SFO a few years ago.

Can you elaborate on this? What kind of phone? Android or iOS? Fully patched? What kind of infection? How did you discover it? How did you get rid of it?

I bet their iphone was running android

Re: FBI is warning people against using public phone-charging stations

#227

This is like abstinence-only education. Use a USB condom: https://www.zdnet.com/article/protect-your-data-with-a-usb-c...

The use of public chargers is easy to avoid with some basic planning and awareness of your phone's battery habits.

Re: FBI is warning people against using public phone-charging stations

#228

Earlier quoted context omitted.

A website would be hard pressed to emulate a keyboard plugged into my computer.

very true. nevertheless, I’m curious if you implicitly trust the security of links on HN? I know I largely do, but perhaps that’s unwise, especially given the site’s stated target audience

Serious browser exploits are extremely rare these days. Like, the worst you get is cryptocurrency mining while you're on the page.

Re: FBI is warning people against using public phone-charging stations

#229

It really surprised me when this article blew up on Twitter as I thought it was common knowledge to never use public chargers and avoid untrusted usb anything after “bad usb”. It showed me how I live in a tech security bubble-a good reminder.

I lately had trouble convincing some non-tech acquaintances that IoT "cloud-enabled" cameras all over their house (including bedroom) as anti-break-in measure are a bad idea as those devices or the storage in some chinese cloud could be hacked. They ridiculed this as "far fetched".

I'll never be able to bring up this risk with USB to those guys.

Edit: IoC typo -> IoT

Re: FBI is warning people against using public phone-charging stations

#230

But how? Most devices are charge-only by default, most users have USB debugging disabled, and those who know how to enable it, won't allow the adb server to connect to the phone (you have to explicitly give it permission).

I can picture a malicious actor convincing less tech savvy folks into enabling USB debugging to "unlock wifi speed" or some similar BS.
Post reply on HN