Earlier quoted context omitted.
>I'm surprised Schneier says "I am unconvinced". And immediately after he says he's unconvinced this is a concern, he states that he does, in fact, carry a tool with him that would protect him in these circumstances.
In general, you can be unconvinced that various things are actually a meaningful real-world danger, but you choose to mitigate against them anyway if you can do so easily.
FBI is warning people against using public phone-charging stations
321–328 of 328 posts
Re: FBI is warning people against using public phone-charging stations
#322Earlier quoted context omitted.
There’s a fair amount of signal processing going on inside a GPS device. Modern GPS chips only need around 25mW apparently - older chips can pull 100mW though. Scanning needs a bit more power than tracking.
Is it the same on sport watches? They seem to easily do 24h when doing GPS tracking. That is the popular models there are watches that can track more than 100h (but they always have bigger batteries). This is impressive for me since I remember doing tracking back in 2005 and that meant using lots of batteries. On phones I think the problem mainly is that the GPS needs to wake up an app that need to handle the GPS dat…
Re: FBI is warning people against using public phone-charging stations
#323Earlier quoted context omitted.
There have been many jailbreaks available that only required plugging the phone in and running some program on the other end of the cable. There's been jailbreaks where all you needed to do was visit a website... Apple's security isn't as bullet-proof as some make it out to be. So, is it plausible a malicious charging station could gain root and sideload something nefarious on an iPhone? Absolutely. Particularly for…
It’s been many years since I rooted (or even owned) an android phone but is there really no interaction from the user required beyond plugging it in? On iOS there’s a pop up asking if you want to trust the computer, and that’s after you’ve unlocked the screen
Re: FBI is warning people against using public phone-charging stations
#324Earlier quoted context omitted.
There have been many jailbreaks available that only required plugging the phone in and running some program on the other end of the cable. There's been jailbreaks where all you needed to do was visit a website... Apple's security isn't as bullet-proof as some make it out to be. So, is it plausible a malicious charging station could gain root and sideload something nefarious on an iPhone? Absolutely. Particularly for…
It’s been many years since I rooted (or even owned) an android phone but is there really no interaction from the user required beyond plugging it in? On iOS there’s a pop up asking if you want to trust the computer, and that’s after you’ve unlocked the screen
And yes, in the past many iOS jailbreaks were shockingly simple. The website one in particular - you went to a URL and clicked a button... your phone rebooted and was jailbroken.
Re: FBI is warning people against using public phone-charging stations
#325Earlier quoted context omitted.
It is almost impossible to drain my iPhone to 0 unless I am doing something really unhealthy, like staring at it for 10 hours. I take a charger with me on trips so I can charge over night, but otherwise.. it's literally not possible in my reasonable life to run my phone out of juice. Back when I used android, it was much more common that runaway apps would drain my phone in 2 hours. But now? Doing a anker battery wou…
Just go on a trip where you use your GPS a lot and take pictures with your phone and it will last half a day at best.
Re: FBI is warning people against using public phone-charging stations
#326This is like abstinence-only education. Use a USB condom: https://www.zdnet.com/article/protect-your-data-with-a-usb-c...
The use of public chargers is easy to avoid with some basic planning and awareness of your phone's battery habits.
Re: FBI is warning people against using public phone-charging stations
#327Earlier quoted context omitted.
Try plugging a keyboard into your phone. That setting does not work the way you think it does.
(Apart from very low level USB firmware stack attacks:) That's a purely software issue, though, and actually easier to solve on phones (with built-in display+input) than on PCs (how to trust a keyboard/mouse without having keyboard/mouse to input approval with?). https://usbguard.github.io/
I know, that's why I'm so annoyed! And Android is already half-way there; they've already acknowledged that I should be able to control how my phone interacts over USB with a PC, now all that's left is a proactive control that sets the mode for the USB port globally instead of asking my preference in reaction to a device being connected.
>and actually easier to solve on phones (with built-in display+input) than on PCs (how to trust a keyboard/mouse without having keyboard/mouse to input approval with?).
I feel like PCs are less of an issue; I'm not out with my PC at a coffee shop or bus station when suddenly I'm tempted to use the publicly available USB keyboard. At least to me phones and tablets seem like the problematic devices here since charging them (with a wire at least) necessitates connecting them via USB.
Re: FBI is warning people against using public phone-charging stations
#328Earlier quoted context omitted.
> Okay, but tell me how it can be done if you want me to take the threat seriously. That is not a precautionary attitude. I don't know how a candle left unattended in the middle of my granite counter island could light anything on fire, there aren't any drapes near it, but I'm not going to leave it unattended so I can find out.
Indeed, I’m explicitly rejecting the precautionary principle.