Earlier quoted context omitted.
I'm in San Francisco, so not Seattle, but cars get broken into for the sport of it by this point. A friend's had her window broken and used, gross dog leashes and an old Nokia charger stolen. The lost hours of work to replace the window was the real cost to her dog walking business.
Just park with your windows open if there's nothing they can really take. Repairing the window isn't with the cost or the time.
O.mg Cable
81–90 of 555 posts
Re: O.mg Cable
#82Earlier quoted context omitted.
Problem in San Francisco is, you'll get people sleeping in your car if you do that.
Depending on the height of your windows I would think sleeping would be the best thing other people could do to your car.
Re: O.mg Cable
#83You should use a data blocker when using an unknown USB cable to charge your phone. Occasionally described as a USB condom. Simply a Male to Female USB adaptor with the data wires not passed through.
Is that USB-PD compatible?
A decent USB-C condom would also have to cut not just the USB2 D+/D- line, but also the USB3 SS and SBU lines... the really interesting thing is the CC wires, since without these you can't have reversible connectors, but not cutting them leaves an avenue for attackers (e.g. putting an USB-C port into JTAG mode). And on top of that USB-C PD 1 used the Vbus line with an overlaid HF signal.
That means a decent USB-C condom will need:
- a low-pass on the Vbus line to block PD1
- cut D+/D-, SS, SBU
- cut CC1/CC2 and insert an as-dumb-as-possible controller chip to handle plug orientation
Re: O.mg Cable
#84Earlier quoted context omitted.
When I was frequently using things like this on coworkers in red teaming (back when being in an office was a thing) putting my own desktop in a steel cage with a good lock proved effective against retaliation. Then we moved on to attacking the firmware in each others keyboards.
We just broke the locks on the cages with a screwdriver. Locks only keep honest people honest.
Re: O.mg Cable
#85I have tried to make a cable like that in the past be the best I got was to hide the electronics in what looked like a bead. Unfortunately, this only really works with USB-B devices where users are already used to having beads on the cable which for practical purposes limits attacks to printers and older scanners.
Re: O.mg Cable
#86Earlier quoted context omitted.
When I was frequently using things like this on coworkers in red teaming (back when being in an office was a thing) putting my own desktop in a steel cage with a good lock proved effective against retaliation. Then we moved on to attacking the firmware in each others keyboards.
We just broke the locks on the cages with a screwdriver. Locks only keep honest people honest.
Re: O.mg Cable
#87Earlier quoted context omitted.
Why is the NSA so good at coming up with sweet codenames for things? I swear it's someone's full time job there.
IIRC the funny thing is, the system that provides the codenames is random in order for the system to not leak information about what the code name is for. But since there's no limit to how many times you can request a code name, the system is being abused and users try until they get a good one.
Re: O.mg Cable
#88Wow! Is the trick that we now have powerful microcomputers small enough to fit into a USB plug? That's pretty incredible technology. How many years ago did this become possible? My IT security training is dated, I am aware of the risks of plugging in a random USB key, but just a cable from a helpful "coworker"? Yikes.