https://www.schneier.com/blog/archives/2023/04/fbi-advising-people-to-avoid-public-charging-stations.html Schneier on Security Menu * Blog * Newsletter * Books * Essays * News * Talks * Academic * About Me Search Powered by DuckDuckGo [ ] [Go] ( ) Blog ( ) Essays (*) Whole site Subscribe Atom FeedFacebookTwitterKindleE-Mail Newsletter (Crypto-Gram) HomeBlog FBI Advising People to Avoid Public Charging Stations The FBI is warning people against using public phone-charging stations, worrying that the combination power-data port can be used to inject malware onto the devices: Avoid using free charging stations in airports, hotels, or shopping centers. Bad actors have figured out ways to use public USB ports to introduce malware and monitoring software onto devices that access these ports. Carry your own charger and USB cord and use an electrical outlet instead. How much of a risk is this, really? I am unconvinced, although I do carry a USB condom for charging stations I find suspicious. News article. Tags: cell phones, FBI, malware, smartphones, USB Posted on April 12, 2023 at 7:11 AM * 12 Comments Comments warren * April 12, 2023 8:17 AM I don't carry a USB Condom I carry the whole charging chain - wall wart(s), cable(s), and device (s) to be charged Rarely do "public" charging ports ever work in my experience (especially in busy places like airports) - they're always loose, pushing too little current, not sending any power ... Zack * April 12, 2023 9:56 AM I assume the usb ports themselves are usually just wired to power, so I'm not sure what they would compromise to make this happen. But they could probably make card-skimmer like rigs that plug into the existing usb power ports exposing a new usb port that tries some set of attacks when a device is plugged in. I do wish they would show some photos of them the way that card skimmers are exposed so you would know what to look out for, and I'm not sure how they would do this where it would appear remotely flush to the wall. Vesselin Bontchev * April 12, 2023 10:11 AM There is not even a single case of malicious USB chargers used in the wild. It's only a theoretical threat, demonstrated at conferences. Anonymous * April 12, 2023 10:50 AM @Vesselin Bontchev, Actually, this has been around for years, and you can easily buy one online for $150: https://shop.hak5.org/products/omg-cable Andrew Almeida * April 12, 2023 11:15 AM Where potential for a threat exists, someone will find a way to exploit it. Craig * April 12, 2023 11:24 AM The history of the tech industry is full of things like this, where it seems so useful to do something, but people don't think about the possible dangers even enough to see the most obvious possibilities. Mixing power and data on one connector sounds really convenient, but if it means that the default is to expose your data connection even when you only need power, the potential for abuse is clear. Jill * April 12, 2023 12:09 PM and that coming from the very trustworthy fbi. tim * April 12, 2023 12:09 PM I rolled my eyes when I saw this notice from the FBI. This is has usful advice as "don't use public wifi". In both cases its just better to say "keep your devices up to date", have a nice scone, and call it a day. Steve * April 12, 2023 2:18 PM @Vesselin Bontchev and there is a single instance of a USB device exploding when plugged in but rare events happen every single day Aristotle * April 12, 2023 5:53 PM It is likely that unlikely things will happen. Does expectation times (negative) value really account for what the individual experiences? https://www.acumen-bcp.co.uk/ its-likely-that-something-unlikely-will-happen/ AreYouKidding? * April 12, 2023 6:10 PM I plug my phone or tablet into my computer. Getting it to work right is always a pain in the ass. But once done, in minutes I can download EVERYTHING. Email. Address book. Photos. Videos. Texts. All my contacts. EVERYTHING Will this work without my cooperation at a charging station? Who knows. Do I feel lucky? Nope. @tim: Public WiFi at the airport has been questionable. Anyone can offer a hotspot and man-in-the-middle. If it's encrypted, https, supposedly you're safe. My browser has a zillion certs corresponding to all sorts of out-of-the-way countries. If any one of them has been broken... Of course all this assumes your phone hasn't been broken to begin with, with malware or spyware pre-installed at the factory for your convenience. Andrew * April 12, 2023 6:56 PM Fascinating theme of disinterest here. Makes me think it's worthwhile. With all the remote zero days on modern phones coming out on a monthly basis, I'd consider it prudent to not plug a phone with cell service into any computer or car under your own control, much less someone else's (e.g. a public USB port). Ever look at how much circuitry is inside those USB-C to Aux adapters that all the mainstream high end phones force you to use, if you don't like bluetooth? Krebs wrote about this 9 years ago 'https://krebsonsecurity.com/2014/06/ gear-to-block-juice-jacking-on-your-mobile/ Atom Feed Subscribe to comments on this entry Leave a comment Cancel reply Login Name [ ] Email [ ] URL: [ ] [ ] Remember personal info? Fill in the blank: the name of this blog is Schneier on ___________ (required): [ ] [ ] [ ] [ ] [ ] [ ] [ ] [ ] Comments: [ ] [loader] Allowed HTML * * * *
    1. *
       Markdown Extra syntax via
      https://michelf.ca/projects/php-markdown/extra/
      
      [Preview] [Edit]
      
      [Submit] 
      
       [                                             ] 
       [                                             ] 
       [                                             ] 
       [                                             ] 
       [                                             ] 
       [                                             ] 
       [                                             ] 
      D[                                             ] 
      
      - Car Thieves Hacking the CAN Bus
      
      Sidebar photo of Bruce Schneier by Joe MacInnis.
      
      About Bruce Schneier
      
      [Bruce-Schn]
      
      I am a public-interest technologist, working at the intersection of
      security, technology, and people. I've been writing about security
      issues on my blog since 2004, and in my monthly newsletter since
      1998. I'm a fellow and lecturer at Harvard's Kennedy School, a board
      member of EFF, and the Chief of Security Architecture at Inrupt, Inc.
      This personal website expresses the opinions of none of those
      organizations.
      
      Related Entries
      
        * Car Thieves Hacking the CAN Bus
        * FBI (and Others) Shut Down Genesis Market
        * North Korea Hacking Cryptocurrency Sites with 3CX Exploit
        * Exploding USB Sticks
        * US Citizen Hacked by Spyware
      
      Featured Essays
      
        * The Value of Encryption
        * Data Is a Toxic Asset, So Why Not Throw It Out?
        * How the NSA Threatens National Security
        * Terrorists May Use Google Earth, But Fear Is No Reason to Ban It
        * In Praise of Security Theater
        * Refuse to be Terrorized
        * The Eternal Value of Privacy
        * Terrorists Don't Do Movie Plots
      
      More Essays
      
      Blog Archives
      
        * Archive by Month
        * 100 Latest Comments
      
      Blog Tags
      
        * 3d printers
        * 9/11
        * A Hacker's Mind
        * Aaron Swartz
        * academic
        * academic papers
        * accountability
        * ACLU
        * activism
        * Adobe
        * advanced persistent threats
        * adware
        * AES
        * Afghanistan
        * air marshals
        * air travel
        * airgaps
        * al Qaeda
        * alarms
        * algorithms
        * alibis
        * Amazon
        * Android
        * anonymity
        * Anonymous
        * antivirus
        * Apache
        * Apple
        * Applied Cryptography
        * artificial intelligence
      
      More Tags
      
      Latest Book
      
      A Hacker's Mind
      
      More Books
      
      Support Bloggers' Rights! Defend Privacy--Support Epic
      
        * Blog
        * Newsletter
        * Books
        * Essays
        * News
        * Talks
        * Academic
        * About Me