Live data from Hacker News

FBI is warning people against using public phone-charging stations

schneier.com

61–70 of 328 posts

Re: FBI is warning people against using public phone-charging stations

#61

If you have a zero day takeover via usb/lightning why would you waste it on public charging infrastructure? That seems ridiculous.

It's not really. Supposed a nefarious group wants to get ahold of an executives phone who always flies out of LAX or goes to a certain mall and uses a public charger. It would be smart to zero day one of those and if a few extra people are exploited, maybe some bonus bank info.

Re: FBI is warning people against using public phone-charging stations

#64

If you have a zero day takeover via usb/lightning why would you waste it on public charging infrastructure? That seems ridiculous.

What other attack vector would you choose?

You could ship the victim malicious USB cables in the mail with amazon branding on the box.

Many people would use them, assuming they were just mis-shipped or ordered by their spouse.

Re: FBI is warning people against using public phone-charging stations

#65
post #41

Earlier quoted context omitted.

Nice. Alas, that will probably also block fast charging on iPhone 15+: https://9to5mac.com/2023/03/20/usb-c-faster-charging-iphone-...

Idea: use a power bank that allows in/out at the same time. It should charge both at high speed while also acting as a firewall. This is also assuming that your powerbank can’t be hacked. In which case, god save us all.

It does add a slight extra layer in that they have to both have a compromise for whatever chip is controlling your bank and a compromise for whatever phone is attached which is more difficult to pack into a small controller chip. Although I'm willing to be a lot of power bank controllers are similar across the market which narrows that difficulty.

Re: FBI is warning people against using public phone-charging stations

#67
post #37

Earlier quoted context omitted.

Personally...I run a Linode VPN with openvpn on it listening on port 443. Anytime I am on an public wifi or untrusted network (including the occaisonal time at my job with a personal device), i connect to that. Since its 443, its generally not blocked, even through the TLS connection is not "standard" because it uses a 2048 bit PSK to as a pre-cursor to start a connection, then a certificate based auth to establish t…

OpenVPN is a noisy protocol. Every network operator knows you’re on a VPN. Point is, port 443 isn’t really the best way if you dont want to be blocked. You may want to consider stunnel if this ever becomes a problem for you.

The thing is though, im not trying to hide the fact I am on OpenVPN. Simple inspection of the handshake tells you EXACTLY what it is. But thats generally not the issue.

The issue is many will simply block UDP or the default port 1194 or basically anything other than a handful of outbound ports, of which 443 outbound is almost never actually blocked for obvious reasons. In fact I cant think of a single time I havent been able to use that VPN, even when my normal road-warrior profile to my house IS blocked.

Either way there are ways are ways to mask the fact that its clearly OpenVPN that if your issue is nation-states or things like the Great Firewall like Obfsproxy, but even then, something like Mullvad would be called for since you are likely going to need an array of endpoints.

Im just trying to ensure my traffic is running through a trusted source until the point that its supposed to him the open internet. Things like DNS filtering are getting more pervasive. For me that means I want to know the endpoint until I am ready for it to egress.

I have also had this setup for years at this point. Before tailscale or even hearing of things like mullvad. But I work in IT, so its one of those things that makes others that dont work in tech look at me funny if they see it.

Re: FBI is warning people against using public phone-charging stations

#68
post #48

I'm surprised Schneier says "I am unconvinced". We know (I think?) attackers can apparently easily introduce MitM skimmers to credit card swipers (I _think_ that's how my CC number keeps getting stolen?), possibly even without cooperation of the proprietor? Why not a little invisible injector on a charging port, that seems if anything easier. Or is the skepticism around something else, I guess? Motivation? Lack of co…

>I'm surprised Schneier says "I am unconvinced". And immediately after he says he's unconvinced this is a concern, he states that he does, in fact, carry a tool with him that would protect him in these circumstances.

He also mentions that he only uses said tool with "charging stations I find suspicious". Which is very curious, because I would assume an attacker who is willing to risk burning such an attack would make sure their charging station is looking the least suspicious and most ordinary.

I'm not sure if "find suspicious" is a good heuristic here. Although of course we don't know what he bases his suspicion on.

Re: FBI is warning people against using public phone-charging stations

#69
post #41

Earlier quoted context omitted.

Nice. Alas, that will probably also block fast charging on iPhone 15+: https://9to5mac.com/2023/03/20/usb-c-faster-charging-iphone-...

Idea: use a power bank that allows in/out at the same time. It should charge both at high speed while also acting as a firewall. This is also assuming that your powerbank can’t be hacked. In which case, god save us all.

[deleted]

Re: FBI is warning people against using public phone-charging stations

#70

Earlier quoted context omitted.

What other attack vector would you choose?

You could ship the victim malicious USB cables in the mail with amazon branding on the box. Many people would use them, assuming they were just mis-shipped or ordered by their spouse.

This would totally work on me. My wife is always buying USB cables from amazon, IDK what we do with them all.
Post reply on HN