Earlier quoted context omitted.
None of these are necessary, except half of #2. All you'd need is a "middleman" device that is subtle enough to avoid notice by the person plugging in, just like how credit card skimmers work. > 1. The station has to be using USB Ports / Charging cables that are data enabled, not just cables that carry power Doesn't matter, because you're (unwittingly) plugging into the attacker's device, not the station's. > 2. The…
> They'll plug in the phone, unlock it, and browse the internet. iOS devices (maybe Android too, idk) ask you if you want to allow new accessories to access your device. That's why they said you need an exploit.
If not an exploit, you need the victim to do something a lot more obviously (though the absolute obviousness of course remains debatable) dumb/risky than merely plug in.