Earlier quoted context omitted.
You don't need orientation handling if you've cut all the other signals, so... Power negotiation is also not a big problem. Just use a correct resistor on the CC pin and you can make the phone use up to 5V/3A, which is plenty for any smartphone. You'd have to make sure to use a 5V/15W capable power source, though.
> You'd have to make sure to use a 5V/15W capable power source, though. ... which precisely is something I cannot make sure on a device where I'm tempted to use a USB condom, and it won't be useful at all for laptops.
O.mg Cable
451–460 of 555 posts
Re: O.mg Cable
#452I wonder what happens if you fly with one of these.
I don't think transport security people would care about any small tech stuff until something happens inflight because of it.
Re: O.mg Cable
#453Earlier quoted context omitted.
It’s not really practical to defend against for most end users. Keeping a whitelist of known keyboards and mice is really the only defence even on Linux, and unless you work in a data centre that’s probably way overkill. With a home PC that doesn’t really work though, because in order to authenticate your mouse without some kind of central mouse log on a server you probably need to click a button, which you can’t do…
Whitelists don't work. As an attacker I just have the bootloaders of my malicious devices advertize the USB IDs of whitelisted devices like Apple Keyboards. The computer has no way of knowing it is not authentic. There is no signing or certification for USB devices. The only solution is a kernel that can place all newly attached USB devices in a queue for manual approval. This is what USBGuard and QubesOS both do. Th…
Would it recognize the newly attached one, if you do the swap while the computer is turned off and they have the same HW ID?
Because if not, then it's not much better than what Windows lets you do with group policies. Although on Windows you could do this swap even while the OS is running.
Re: O.mg Cable
#454Earlier quoted context omitted.
You don't need orientation handling if you've cut all the other signals, so... Power negotiation is also not a big problem. Just use a correct resistor on the CC pin and you can make the phone use up to 5V/3A, which is plenty for any smartphone. You'd have to make sure to use a 5V/15W capable power source, though.
> You'd have to make sure to use a 5V/15W capable power source, though. ... which precisely is something I cannot make sure on a device where I'm tempted to use a USB condom, and it won't be useful at all for laptops.
Security is inconvenient.
Re: O.mg Cable
#455Earlier quoted context omitted.
You could do that, but then you'd need to forgo USB Power Delivery, Qualcomm quick charging, etc. One thing I've heard other comments mention here is a USB condom (USB data blocker). It's just a male to female adapter with only the power lines patched through, not data lines.
If you have a powerbank with you (which may be empty), you could also charge the powerbank using the untrusted power source, and at the same time charge the phone via powerbank to "sanitize" the source. This way you could still benefit from quickcharging.
Re: O.mg Cable
#456Earlier quoted context omitted.
USB C charging happens well below the OS layer, using firmware that often isn't all that good. USBGuard or QubesOS won't help there (but will somewhat mitigate attacks trying to move up the stack)
The problem is not the charging. The problem is that a fake charger cable can run an HID attack over the +/- pins before it does a pass through to the power negotiation MCU for charging. A tampered USB C to C cable on a conference room table can compromise people all day long. If the USB C charge ports cut the data pins entirely then great, but I have not seen that be the case on any laptops yet.
Re: O.mg Cable
#457Earlier quoted context omitted.
> Anyone who thinks differently is arguing for a shadow gov, i.e. unelected bureaucrats who answer to no one and can make decisions unilaterally without consequence... not exactly democracy. Lots of countries have an establishment "civil service" comprised of those "unelected bureaucrats" that you mention, and it actually works out quite well for them. That said, they aren't unaccountable: they answer to departmental…
>A big advantage of the system is to prevent mad-swings in policy just because the head-of-government changed. You can frame this another way: it prevents meaningful change even if the electorate demands it. Sorry, I watched too much Yes Minister to think this is a good thing x)
I recognize I'm basically describing a utopia.
Re: O.mg Cable
#458Earlier quoted context omitted.
When I was frequently using things like this on coworkers in red teaming (back when being in an office was a thing) putting my own desktop in a steel cage with a good lock proved effective against retaliation. Then we moved on to attacking the firmware in each others keyboards.
>putting my own desktop in a steel cage with a good lock proved effective against retaliation. >Then we moved on to attacking the firmware in each others keyboards. In what world is hacking keyboard firmware easier than lockpicking?
Re: O.mg Cable
#459Earlier quoted context omitted.
Unfortunately, there aren't really all that many "good locks" on the market. The Lock Picking Lawyer on YouTube[1] has pretty much destroyed my faith in the modern lockmaking industry. [1]: https://www.youtube.com/c/lockpickinglawyer/videos
He can defeat just about anything, but he’s also exceptionally skilled. As a consumer of locks, I expect them to be defeatable by a skilled lockpicker. But I don’t expect them to be defeatable by a bic pen or by reaching in the keyhole with an oddly shaped wire to move the locking paul. You can buy locks that don’t have easy bypasses, and can’t be easily drilled, and can’t be picked by beginners.
I've been wondering the most sophisticated/effective/secure locks regular consumers have access to.
In other words, which locks does the Lock Picking Lawyer himself use in his house to protect his family?
Re: O.mg Cable
#460Earlier quoted context omitted.
He can defeat just about anything, but he’s also exceptionally skilled. As a consumer of locks, I expect them to be defeatable by a skilled lockpicker. But I don’t expect them to be defeatable by a bic pen or by reaching in the keyhole with an oddly shaped wire to move the locking paul. You can buy locks that don’t have easy bypasses, and can’t be easily drilled, and can’t be picked by beginners.
You can also buy locks that can't be picked by people like me who have been at it 20 years. To keep people like me out for a while buy a Medeco. Pins not only need to be at the right height, but also the right rotation. They are a real pain in the ass to pick. I don't even know any locksmiths that can pick them. Good security for the money. Bosnian Bill and LPL... Okay they can pick them, but they are like the 0.0001…