Live data from Hacker News

O.mg Cable

shop.hak5.org

441–450 of 555 posts

Re: O.mg Cable

#441

The product description does a really poor job of explaining what this is to someone who has never heard of it. It's just a wink-wink-nudge-nudge reference to some DEFCON talk. Can someone explain what this is? Is it a hardware keylogger?

It can also do keystroke injection.

Re: O.mg Cable

#442

After looking at that product page and seeing how something that looks innocuous can be so insidious, does anyone else wonder just a bit whether the page is not so innocent and visiting it may have been a mistake.

yep.

chrome is now showing me a new "you added this to your cart" feature on my new tab page. it says i have added that product to my "cart".

that page is obviously doing something but i can't say anything evil.

Re: O.mg Cable

#443

After looking at that product page and seeing how something that looks innocuous can be so insidious, does anyone else wonder just a bit whether the page is not so innocent and visiting it may have been a mistake.

Hak5 is legitimate. They sell all kinds of pentesting equipment, and most of it is good. It's mostly just small ARM linux "boxes" with some Bash scripts on top, though things like the WiFi Pineapple will (attempt) to break wifi passwords for you (https://shop.hak5.org/collections/sale/products/wifi-pineapp...)

For lack of a better use (just a hobby for me), i use a Screen Crap (https://shop.hak5.org/collections/sale/products/screen-crab) along with a Key Croc (https://shop.hak5.org/collections/sale/products/key-croc) for a poor mans KVM to my headless server :)

I don't know about the omg.lol page :)

Re: O.mg Cable

#444

Earlier quoted context omitted.

Not sure I understand those last two sentences. Could you clarify?

Things may have changed, but in my prior life when I had a clearance, for example, dating (or marrying for that matter) a foreign national would result in heavy vetting, including possibly losing your clearance and/or being terminated.

I hope it would have just been your contract that would have been terminated? ;-)

Re: O.mg Cable

#445
These are normally made with something like an esp32 squeezed into the plug.

To exfiltrate data by WiFi, there is a neat way to get data out... Just have the esp32 connect to all unencrypted WiFi networks in turn and send the data out via a DNS tunnel.

Then the attacker can provide their own WiFi network, but it will also work with airplane WiFi, cafe WiFi, guest networks, etc.

And obviously with DNS tunnelling it works against WiFi networks that require a 'sign in' after connection, even without signing in.

Re: O.mg Cable

#447
post #413

Earlier quoted context omitted.

Putting aside the politics of it for a second, all clearence stems from the executive branch which stems from the president. Saying the president shouldn't have clearance doesn't make a lot of sense, he's the one who authorized it. He's the one who decides who gets it. Anyone who thinks differently is arguing for a shadow gov, i.e. unelected bureaucrats who answer to no one and can make decisions unilaterally without…

> Anyone who thinks differently is arguing for a shadow gov, i.e. unelected bureaucrats who answer to no one and can make decisions unilaterally without consequence... not exactly democracy. Lots of countries have an establishment "civil service" comprised of those "unelected bureaucrats" that you mention, and it actually works out quite well for them. That said, they aren't unaccountable: they answer to departmental…

>A big advantage of the system is to prevent mad-swings in policy just because the head-of-government changed.

You can frame this another way: it prevents meaningful change even if the electorate demands it.

Sorry, I watched too much Yes Minister to think this is a good thing x)

Re: O.mg Cable

#449

I want to need one of these things. Pranks on my friends are difficult with a lockdown and permanent wfh status, so I’d need a better reason. Can anyone think of non evil uses? My imagination is stunted I guess.

I'd be afraid to prank someone with a tool like this. It seems like it would be easy to unintentionally hack said friend or at least make them believe that you might have hacked them.

Re: O.mg Cable

#450
post #339

Earlier quoted context omitted.

> It means no one can drive by plug something in when your computer is locked. You will get a popup asking if you want to give some device other than the keyboard you booted with access to behave as a keyboard . Makes me think, what would happen if I plugged this cable, unplugged the keyboard, and power-cycled the computer? Or do a hard power down, then the switcheroo, and then power up? Would USBGuard/QubesOS block…

If you rebooted my computer you would be greeted with a full disk decryption prompt which requires a smartcard and a pin to unlock. It won't go unnoticed. If your computer can reboot itself for updates that should be a cause for concern as it means your FDE is being cached somewhere that can use it unattended. I don't allow such things personally. You do have to check for any untrusted USB devices at boot on a deskto…

> It won't go unnoticed.

Of course the reboot itself will be noticed when the user gets back - whether it's the login prompt, or boot prompt, or just all applications being closed. I meant it might not be noticed as something unusual, warranting further investigation. Typical user, even tech-savvy one, will just think, "must have been a power glitch", or "damn, those updates forced a reboot again".

The latter is something Windows users are conditioned for. Coming back from the toilet to be faced by a fresh login prompt is common enough even in the age of Windows 10 - and especially when the laptop is controlled by your employer, as IT tends to force a stricter schedule on updates[0]. In my case, this happens 1-2 times a week. While I'm working from home this doesn't matter, but if I were back in the office and came back from lunch to a rebooted computer, I would've assumed it was updates again.

> You do have to check for any untrusted USB devices at boot on a desktop. No getting around that one as you need to be able to use input devices at boot.

Makes sense, thanks for clarifying. I was assuming at least some of these solutions are trying to eliminate this requirement, but ultimately it may not be possible.

(Or perhaps it would be, if USB had something like HDCP so that you couldn't construct a dongle that could be transparently inserted between the computer and the peripheral.)

> For a laptop you have a better story

Right. Also, in case of attacker forcing reboot, they can't rely on users assuming it was a power glitch because laptops have batteries.

> I connect my USB webcam to the one VM that needs it on demand, for instance.

I need to read more about such setups, where you compartmentalize your system with VMs. Is there any good primer you could recommend?

--

[0] - I'm increasingly convinced Windows 10 update system is evil, and does this on purpose. It just so happens that it always forces an update and reboot on my work machine whenever I step away from it for more than 10 minutes. It's like it was monitoring idle time, and thinking "ooh, the user is away, let's reboot the machine and lose all the state". I also recently had to switch Lenovo updater malware to manual, because it kept choosing the exact middle of our weekly team meeting as the time to forcibly update video drivers, blanking my screen for anywhere between 2 and 20 minutes.

(Did I mention I hate automatic updates?)

Post reply on HN