Live data from Hacker News

O.mg Cable

shop.hak5.org

51–60 of 555 posts

Re: O.mg Cable

#51

I want to need one of these things. Pranks on my friends are difficult with a lockdown and permanent wfh status, so I’d need a better reason. Can anyone think of non evil uses? My imagination is stunted I guess.

Couple legitimate uses could be to test a driver or "port mirror" for debugging. (It does more than just keylog... eg. logs raw HID reports)

Re: O.mg Cable

#52
post #44

See also: C-to-C charger cables with Bluetooth remote activated dual payloads: https://sneaktechnology.com/product/usbninja-custom-type-c-t... I easily modified mine to mimmic Apple Keyboard USB IDs to avoid notifications. Works great! Cellular GPS tracking car charger: https://www.amazon.com/Charger-Locator-Professional-Listenin... Cellular GPS tracking USB charger cable: https://www.ebay.com/itm/223990414124 I have…

When USB came out I was working in the defence sector. We closed the vector off with cages for the PCs with tied looms under desks, epoxy in all the holes we didn’t want people to use and with threat of being in deep shit.

Re: O.mg Cable

#53
I remember about decades ago that keyloggers would be very scary and powerful because your only defense was your password, and you couldn't know someone was logging in at the same time as you if you were not aware of it.

Nowadays, with 2FA and all the big companies doing extra security check up when they see something wrong with the login patterns ... I don't see the use of keyloggers anymore.

Re: O.mg Cable

#54
post #48

Earlier quoted context omitted.

Just park with your windows open if there's nothing they can really take. Repairing the window isn't with the cost or the time.

Problem in San Francisco is, you'll get people sleeping in your car if you do that.

Depending on the height of your windows I would think sleeping would be the best thing other people could do to your car.

Re: O.mg Cable

#55
post #53

I remember about decades ago that keyloggers would be very scary and powerful because your only defense was your password, and you couldn't know someone was logging in at the same time as you if you were not aware of it. Nowadays, with 2FA and all the big companies doing extra security check up when they see something wrong with the login patterns ... I don't see the use of keyloggers anymore.

I can assure you keyloggers still work very well at most major companies.

Maybe in a couple more decades they will have begun to use basic defenses already available.

Re: O.mg Cable

#56
post #8

Wow! Is the trick that we now have powerful microcomputers small enough to fit into a USB plug? That's pretty incredible technology. How many years ago did this become possible? My IT security training is dated, I am aware of the risks of plugging in a random USB key, but just a cable from a helpful "coworker"? Yikes.

It’s a copy of the NSA ANT Coppermouth cables. That was part of the Snowden leak, so it’s been possible since at least then (the doc itself is circa 2008) if you have a three-letter name and a national security black budget. https://en.m.wikipedia.org/wiki/NSA_ANT_catalog

Well the technology differs a bit.

The NSA implant was a passive retroreflector implant, which when illuminated by powerful radio waves, broadcasted back what was being typed, or what was visible on screen.

This seems to be more of a tiny chip that captures and stores keystrokes etc.

Re: O.mg Cable

#57
post #52
post #44

See also: C-to-C charger cables with Bluetooth remote activated dual payloads: https://sneaktechnology.com/product/usbninja-custom-type-c-t... I easily modified mine to mimmic Apple Keyboard USB IDs to avoid notifications. Works great! Cellular GPS tracking car charger: https://www.amazon.com/Charger-Locator-Professional-Listenin... Cellular GPS tracking USB charger cable: https://www.ebay.com/itm/223990414124 I have…

When USB came out I was working in the defence sector. We closed the vector off with cages for the PCs with tied looms under desks, epoxy in all the holes we didn’t want people to use and with threat of being in deep shit.

When I was frequently using things like this on coworkers in red teaming (back when being in an office was a thing) putting my own desktop in a steel cage with a good lock proved effective against retaliation.

Then we moved on to attacking the firmware in each others keyboards.

Re: O.mg Cable

#58
post #8

Earlier quoted context omitted.

It’s a copy of the NSA ANT Coppermouth cables. That was part of the Snowden leak, so it’s been possible since at least then (the doc itself is circa 2008) if you have a three-letter name and a national security black budget. https://en.m.wikipedia.org/wiki/NSA_ANT_catalog

Why is the NSA so good at coming up with sweet codenames for things? I swear it's someone's full time job there.

IIRC the funny thing is, the system that provides the codenames is random in order for the system to not leak information about what the code name is for. But since there's no limit to how many times you can request a code name, the system is being abused and users try until they get a good one.

Re: O.mg Cable

#60
post #53

I remember about decades ago that keyloggers would be very scary and powerful because your only defense was your password, and you couldn't know someone was logging in at the same time as you if you were not aware of it. Nowadays, with 2FA and all the big companies doing extra security check up when they see something wrong with the login patterns ... I don't see the use of keyloggers anymore.

Even if 2FA prevents you from logging in, you still get A LOT of information from a keylogger.

You know the content of all the emails this user writes. You know the websites they visit. Based on the 2FA auth key they use, you may find out what kind of system it is.

A great start for social engineering. The target user writes an email to someone and the day afterwards you can fake call them and pretend to be the recipient of the email (you have all the information). If you're lucky they wrote an email to management and now you can pass orders in this call.

Post reply on HN