Live data from Hacker News

FBI is warning people against using public phone-charging stations

schneier.com

241–250 of 328 posts

Re: FBI is warning people against using public phone-charging stations

#241

Earlier quoted context omitted.

I've had booths on cyber security trade fairs hand out USB flash drives as prizes for spinning a wheel, with no awareness how that might seem odd. I guess people would be reluctant to accept them at BlackHat, but everywhere else people are very trusting towards USB stuff.

I once worked at a place where the security team had a USB stick delivered to all the desktops with some digital brochure about not trusting strangers or some such. Not the cyber security team, but still.

  [autorun]
  
  open=you_didnt_read_the_brochure_right.exe
  icon=setup.exe,0
  label=My install CD

Re: FBI is warning people against using public phone-charging stations

#242

Earlier quoted context omitted.

Can you elaborate on this? What kind of phone? Android or iOS? Fully patched? What kind of infection? How did you discover it? How did you get rid of it?

I bet their iphone was running android

There have been many jailbreaks available that only required plugging the phone in and running some program on the other end of the cable. There's been jailbreaks where all you needed to do was visit a website... Apple's security isn't as bullet-proof as some make it out to be.

So, is it plausible a malicious charging station could gain root and sideload something nefarious on an iPhone? Absolutely. Particularly for non-tech-savvy folks desperate to get a charge before their connecting flight...

Has it happened? ...No idea. I guess that's where the anecdotes come in...

Re: FBI is warning people against using public phone-charging stations

#243

I don't use public chargers, and I use USB condoms for charging my devices even with chargers I own, because basically all the charging devices are made in untrustable supply chains. I thought this was common knowledge, and basically what everyone is doing. Wireless charging helps a lot with this, and I now prefer wireless charging whenever possible. The only devices I connect my devices to using USB are computers I…

> USB condoms I have one of these. I like that I can look in it and see that it has no data pins > Wireless I know you meant charging, but for data, with some of the spy cables out there with embedded chips and wireless access, it's ironic that wireless is in some ways more secure.

Not all usb condoms show the connections. I got one from a well-known vendor at a conference. Seems like an easier attack vector to create and sell malware infested usb condoms…

Re: FBI is warning people against using public phone-charging stations

#244
post #242

Earlier quoted context omitted.

I bet their iphone was running android

There have been many jailbreaks available that only required plugging the phone in and running some program on the other end of the cable. There's been jailbreaks where all you needed to do was visit a website... Apple's security isn't as bullet-proof as some make it out to be. So, is it plausible a malicious charging station could gain root and sideload something nefarious on an iPhone? Absolutely. Particularly for…

My point was that the person who made the comment stating that they had an iPhone, the person I'm replying to went on to ask them if they had iOS or android

Re: FBI is warning people against using public phone-charging stations

#245

I'm seeing a lot of hysteria in response to this random tweet by the Denver FBI's social media person. Do we know of a single real-world use of this hypothetical exploit? Do we know that iOS's (and presumably Android's) protection against untrusted device access isn't enough?

We do know of shady companies that sell "own this phone" USB devices to governments, but AFAIK they only sell to governments and the details aren't available to the public. I have never heard about a non-government sponsored attacker doing that kind of thing. If this is relevant or not to you, it's a matter of your threat model. If I were a journalist, I would be very weary. Personally, I don't plug my phone on rando…

Heh, if I'm remembering right, a couple of years ago there was a public charging station at DEFCON that was sponsored by the NSA. I did not plug my phone into it :D

Re: FBI is warning people against using public phone-charging stations

#246
post #242

Earlier quoted context omitted.

There have been many jailbreaks available that only required plugging the phone in and running some program on the other end of the cable. There's been jailbreaks where all you needed to do was visit a website... Apple's security isn't as bullet-proof as some make it out to be. So, is it plausible a malicious charging station could gain root and sideload something nefarious on an iPhone? Absolutely. Particularly for…

My point was that the person who made the comment stating that they had an iPhone, the person I'm replying to went on to ask them if they had iOS or android

Good point, I missed that bit upstream.

My general point about how easy it can be to maliciously root someone's device stands, so I will leave my comment as-is.

Folks - don't plug your devices into untrusted USB ports...

Re: FBI is warning people against using public phone-charging stations

#247

Earlier quoted context omitted.

Anecdotally, I have had a previous iphone infected by using a public charging station at SFO a few years ago.

did you have to say yes to the “trust this computer” question to enable data exchange?

Your non-tech-savvy folks will pound through nearly any popup if they are desperate to get a charge before their connecting flight, for instance.

The popup really should be a toggle somewhere in the settings that forces a user to explicitly enable data - not a popup users are mostly self-trained into ignoring.

Additionally, real charging stations should not offer cables with data lines at all.

Re: FBI is warning people against using public phone-charging stations

#248

Earlier quoted context omitted.

Have fun with most devices only charging at 2.5 watts (ie. 6 hours for a full phone charge)...

plz explain. I have something similar to these https://www.amazon.com/OffGrid-Blocker-Unwanted-Transfer-Pro... And it seems to charge quick enough (albeit never timed it)...

The way USB high power charging works is that unless the charger and the device agree on high power the charger just charges at the older pre-high power USB rate. That's why you can plug ancient devices into a high power charger without worry that they will get fried.

The way the charger and the device agree on how much power the charger should supply involves the data lines.

Thus, if you simply drill out the data lines leaving just the power lines as the person a few comments up suggested a properly functioning high power charger will see your device as only supporting the original USB power spec.

I suspect that those things you linked to are active USB devices. The USB port on the charge side has the data lines connected and uses them to negotiate high power from the charger. The USB port on the device side similarly has the data lines connected and uses them to negotiate high power with the device.

It protects the device because the data lines on the charger side are not connected to the data lines on the device side.

Re: FBI is warning people against using public phone-charging stations

#249

Earlier quoted context omitted.

> common knowledge to never use public chargers Perhaps here on HN. Most people will plug their smartphone into any accepting receptacle. trains, airplanes, NYC SmartLink, or ask the bartender if they can plug it in behind the bar. I still carry a DIY Altoids charger that takes a 9V battery (pulled down to proper volts for iPhone). In a battery emergency, my phone is simply on life support and I don't have to look fo…

I try to always travel with a “USB data condom”. The one I have is called a “PortaPow”, and it’s red. It was about $10 on Amazon and it’s a great investment for scenarios where I _reasonably_ trust a power-only USB port not to have been tampered with, like the built in ports on aircraft.

> _reasonably_ trust a power-only USB ... like the built in ports on aircraft.

I'm with you, this might fall under "safe". Then again, from threads posted here and elsewhere, and through personal investigation...the infotainment systems on airplanes are an absolute disaster with regards to security and software design. They're often part of the same system as the provided USB ports. While the risk is small, there's nothing stopping 1 person from running a script that exploits some flaw in the outdated Linux distro the airline is using to manage their in-flight entertainment.

There's also a chance I'm paranoid and spend too much time here, but I'm gonna stick with my Altoids.

Re: FBI is warning people against using public phone-charging stations

#250

I'm seeing a lot of hysteria in response to this random tweet by the Denver FBI's social media person. Do we know of a single real-world use of this hypothetical exploit? Do we know that iOS's (and presumably Android's) protection against untrusted device access isn't enough?

Usually the risk for something like is that if there's some unexploited bug in the USB stack or the OS. Which, from what I know from writing software, I don't trust shit.

I think the risk is insanely low for your average person because you'd have to use an unpatched bug on a well-supported system, you'd have to put bug a USB port in a popular place, and you'd need a reason to do all that.

But at the same time, this is well in the wheelhouse and capability of some bored teen with a lot of time who wants to screw with people FWIW. You could also have fun and write a worm that infects everyone that connect to your USB port and have it DDoS a website or something. The first worms were created by bored people.

Post reply on HN