Live data from Hacker News

O.mg Cable

shop.hak5.org

251–260 of 555 posts

Re: O.mg Cable

#251

Earlier quoted context omitted.

They are really quite unlike us. And our sets of norms is, shall we say, somewhat different to theirs.

You are commenting on a forum full of people who build tools and technology for facebook and google and probably palintir and a thousand other facial recognition and thoughtcrime style systems.

[deleted]

Re: O.mg Cable

#252
post #144

Earlier quoted context omitted.

On most keyboards and mice the cables are not soldered on the inside but just a quick connector. You can get a female/male versions of this connector placed on either side of an attiny85 for a quick solderless implant no one will ever see. Then just undo 2 screws, plug your implant inside the mouse/keyboard, screw it back. To make this harder intentionally strip the screws with a drill, understanding you will never b…

Seems there are special drill bits for removing stripped screws…

Few strokes of a hacksaw and a rubber band (for grip). Or just some pliers

Re: O.mg Cable

#253

Earlier quoted context omitted.

https://blues.io/

This feels like a dumb question, but I can't find dimensions of the Notecard anywhere and I can't quite judge the scale from the pictures. How big is it?

https://github.com/blues/note-hardware/blob/master/Notecard/... has the measurements, looks like 35mm x 30mm

Re: O.mg Cable

#254

Earlier quoted context omitted.

The real answer? Because these people are just like us, geeks, nerds, techies, early adopters. They are just the same people we live and work with. The film Enemy of the State (1998) was science fiction except with the parts where the techy operators were just normal nerds like us. That what was most scary part of the film not the (at the time fantastic) surveillance.

They are really quite unlike us. And our sets of norms is, shall we say, somewhat different to theirs.

I for one don't necessarily disagree with government having a monopoly on violence and all that jazz. But I guess that what makes me HN crowd is that I'm also easily convinced to change my mind if someone brings up a convincing argument.

Re: O.mg Cable

#255
post #57
post #52

Earlier quoted context omitted.

When USB came out I was working in the defence sector. We closed the vector off with cages for the PCs with tied looms under desks, epoxy in all the holes we didn’t want people to use and with threat of being in deep shit.

When I was frequently using things like this on coworkers in red teaming (back when being in an office was a thing) putting my own desktop in a steel cage with a good lock proved effective against retaliation. Then we moved on to attacking the firmware in each others keyboards.

>putting my own desktop in a steel cage with a good lock proved effective against retaliation.

>Then we moved on to attacking the firmware in each others keyboards.

In what world is hacking keyboard firmware easier than lockpicking?

Re: O.mg Cable

#256
post #237

Earlier quoted context omitted.

That might help in San Francisco, but in Seattle, that's lost hours dealing with a soaked interior.

It may be getting soaked in SF too, but with different kind of fluids

Thanks for the f-shack

- Dirty Mike & The Boys

Re: O.mg Cable

#257
post #150
post #93

Earlier quoted context omitted.

It’s not really practical to defend against for most end users. Keeping a whitelist of known keyboards and mice is really the only defence even on Linux, and unless you work in a data centre that’s probably way overkill. With a home PC that doesn’t really work though, because in order to authenticate your mouse without some kind of central mouse log on a server you probably need to click a button, which you can’t do…

Whitelists don't work. As an attacker I just have the bootloaders of my malicious devices advertize the USB IDs of whitelisted devices like Apple Keyboards. The computer has no way of knowing it is not authentic. There is no signing or certification for USB devices. The only solution is a kernel that can place all newly attached USB devices in a queue for manual approval. This is what USBGuard and QubesOS both do. Th…

> It means no one can drive by plug something in when your computer is locked. You will get a popup asking if you want to give some device other than the keyboard you booted with access to behave as a keyboard .

Makes me think, what would happen if I plugged this cable, unplugged the keyboard, and power-cycled the computer? Or do a hard power down, then the switcheroo, and then power up? Would USBGuard/QubesOS block the new device, even though it's the one it just booted with?

(I think finding your computer rebooted would fly under the radar of most of the users - they'd blame it on automatic updates or intermittent power failure.)

On that note, I wonder how small you could go with a MITM device to attach between victim's peripheral and their computer. Could you pack enough useful features in a dongle that would not be immediately noticeable by most users?

Re: O.mg Cable

#258
post #86
post #79

Earlier quoted context omitted.

We just broke the locks on the cages with a screwdriver. Locks only keep honest people honest.

That would generally be considered "detectable intrusion" though.

Not if you replace it with another lock that looks similar

Re: O.mg Cable

#259
post #146
post #44

See also: C-to-C charger cables with Bluetooth remote activated dual payloads: https://sneaktechnology.com/product/usbninja-custom-type-c-t... I easily modified mine to mimmic Apple Keyboard USB IDs to avoid notifications. Works great! Cellular GPS tracking car charger: https://www.amazon.com/Charger-Locator-Professional-Listenin... Cellular GPS tracking USB charger cable: https://www.ebay.com/itm/223990414124 I have…

Curious if chromeOS does anything special here to mitigate usb attacks.

You need to explicitly mount (in your ChromeOS settings) any USB devices to the Linux system. Other than that I'm not aware of any specific mitigations.

Re: O.mg Cable

#260
post #139

Earlier quoted context omitted.

I don't expect good locks to keep people out. I expect good locks to be tamper evident so I know I can't trust my system.

Unfortunately, there aren't really all that many "good locks" on the market. The Lock Picking Lawyer on YouTube[1] has pretty much destroyed my faith in the modern lockmaking industry. [1]: https://www.youtube.com/c/lockpickinglawyer/videos

For most uses of a lock its job is to keep honest people out.

I have had doors kicked in, so these days I want the lock to be the weakest, not strongest, part of the door. So when it is kicked in it is a cheap lock that is destroyed not an expensive hardwood door (I like hardwood doors...)

Post reply on HN