Live data from Hacker News

O.mg Cable

shop.hak5.org

81–90 of 555 posts

Re: O.mg Cable

#81

Earlier quoted context omitted.

I'm in San Francisco, so not Seattle, but cars get broken into for the sport of it by this point. A friend's had her window broken and used, gross dog leashes and an old Nokia charger stolen. The lost hours of work to replace the window was the real cost to her dog walking business.

Just park with your windows open if there's nothing they can really take. Repairing the window isn't with the cost or the time.

As clever as this idea sounds, it's not a good suggestion. I once accidentally left my windows down in SF for 12 hours and my car was essentially stripped clean - headrests, registration, proof of insurance, manual, floor mats - all gone. Additionally all my doors and trunk were wide open.

Re: O.mg Cable

#82
post #48

Earlier quoted context omitted.

Problem in San Francisco is, you'll get people sleeping in your car if you do that.

Depending on the height of your windows I would think sleeping would be the best thing other people could do to your car.

Not sure why this is getting downvoted. I know at least one person who had to get rid of their car after a stinky street person crashed in it. This is a real thing that happens and once an awful stench has permeated cloth and upholstery there is no easy fix.

Re: O.mg Cable

#83

You should use a data blocker when using an unknown USB cable to charge your phone. Occasionally described as a USB condom. Simply a Male to Female USB adaptor with the data wires not passed through.

Is that USB-PD compatible?

The "USB condoms" I know are USB2/3 only which means there isn't any form of PD negotiation anyway, and the oldschool Qualcomm Quickcharge and Apple's negotiation won't work either as these depend on D+/D-.

A decent USB-C condom would also have to cut not just the USB2 D+/D- line, but also the USB3 SS and SBU lines... the really interesting thing is the CC wires, since without these you can't have reversible connectors, but not cutting them leaves an avenue for attackers (e.g. putting an USB-C port into JTAG mode). And on top of that USB-C PD 1 used the Vbus line with an overlaid HF signal.

That means a decent USB-C condom will need:

- a low-pass on the Vbus line to block PD1

- cut D+/D-, SS, SBU

- cut CC1/CC2 and insert an as-dumb-as-possible controller chip to handle plug orientation

Re: O.mg Cable

#84
post #79
post #57

Earlier quoted context omitted.

When I was frequently using things like this on coworkers in red teaming (back when being in an office was a thing) putting my own desktop in a steel cage with a good lock proved effective against retaliation. Then we moved on to attacking the firmware in each others keyboards.

We just broke the locks on the cages with a screwdriver. Locks only keep honest people honest.

Most common locks can be easily picked with a tiny bit of practice. I'm completely incompetent but I can pick any Master lock in 5 minutes or less.

Re: O.mg Cable

#85
The trick is, you can't buy this particular one because you just don't know what it does exactly.

I have tried to make a cable like that in the past be the best I got was to hide the electronics in what looked like a bead. Unfortunately, this only really works with USB-B devices where users are already used to having beads on the cable which for practical purposes limits attacks to printers and older scanners.

Re: O.mg Cable

#86
post #79
post #57

Earlier quoted context omitted.

When I was frequently using things like this on coworkers in red teaming (back when being in an office was a thing) putting my own desktop in a steel cage with a good lock proved effective against retaliation. Then we moved on to attacking the firmware in each others keyboards.

We just broke the locks on the cages with a screwdriver. Locks only keep honest people honest.

That would generally be considered "detectable intrusion" though.

Re: O.mg Cable

#87
post #58

Earlier quoted context omitted.

Why is the NSA so good at coming up with sweet codenames for things? I swear it's someone's full time job there.

IIRC the funny thing is, the system that provides the codenames is random in order for the system to not leak information about what the code name is for. But since there's no limit to how many times you can request a code name, the system is being abused and users try until they get a good one.

What was the codename for the project to create that system?

Re: O.mg Cable

#88

Wow! Is the trick that we now have powerful microcomputers small enough to fit into a USB plug? That's pretty incredible technology. How many years ago did this become possible? My IT security training is dated, I am aware of the risks of plugging in a random USB key, but just a cable from a helpful "coworker"? Yikes.

On a similar note, as I understand it skimmers placed on ATM machines and the like are now so small they are almost impossible to detect.
Post reply on HN