https://krebsonsecurity.com/2023/04/why-is-juice-jacking-suddenly-back-in-the-news/ Advertisement [1] Advertisement [10] Krebs on Security Skip to content * Home * About the Author * Advertising/Speaking Why is 'Juice Jacking' Suddenly Back in the News? April 14, 2023 8 Comments [publiccharger] KrebsOnSecurity received a nice bump in traffic this week thanks to tweets from the Federal Bureau of Investigation (FBI) and the Federal Communications Commission (FCC) about "juice jacking," a term first coined here in 2011 to describe a potential threat of data theft when one plugs their mobile device into a public charging kiosk. It remains unclear what may have prompted the alerts, but the good news is that there are some fairly basic things you can do to avoid having to worry about juice jacking. On April 6, 2023, the FBI's Denver office issued a warning about juice jacking in a tweet. "Avoid using free charging stations in airports, hotels or shopping centers," the FBI's Denver office warned. "Bad actors have figured out ways to use public USB ports to introduce malware and monitoring software onto devices. Carry your own charger and USB cord and use an electrical outlet instead." Five days later, the Federal Communications Commission (FCC) issued a similar warning. "Think twice before using public charging stations," the FCC tweeted. "Hackers could be waiting to gain access to your personal information by installing malware and monitoring software to your devices. This scam is referred to as juice jacking." The FCC tweet also provided a link to the agency's awareness page on juice jacking, which was originally published in advance of the Thanksgiving Holiday in 2019 but was updated in 2021 and then again shortly after the FBI's tweet was picked up by the news media. The alerts were so broadly and breathlessly covered in the press that a mention of juice jacking even made it into this week's Late Late Show with James Corden. The term juice jacking crept into the collective paranoia of gadget geeks in the summer of 2011, thanks to the headline for a story here about researchers at the DEFCON hacker convention in Vegas who'd set up a mobile charging station designed to educate the unwary to the reality that many mobile devices connected to a computer would sync their data by default. Since then, Apple, Google and other mobile device makers have changed the way their hardware and software works so that their devices no longer automatically sync data when one plugs them into a computer with a USB charging cable. Instead, users are presented with a prompt asking if they wish to trust a connected computer before any data transfer can take place. On the other hand, the technology needed to conduct a sneaky juice jacking attack has become far more miniaturized, accessible and cheap. And there are now several products anyone can buy that are custom-built to enable juice jacking attacks. Probably the best known example is the OMG cable, a $180 hacking device made for professional penetration testers that looks more or less like an Apple or generic USB charging cable. But inside the OMG cable is a tiny memory chip and a Wi-Fi transmitter that creates a Wi-Fi hotspot, to which the attacker can remotely connect using a smartphone app and run commands on the device. [omgcable] The $180 "OMG cable." Image: hak5.org. Brian Markus is co-founder of Aries Security, and one of the researchers who originally showcased the threat from juice jacking at the 2011 DEFCON. Markus said he isn't aware of any public accounts of juice jacking kiosks being found in the wild, and said he's unsure what prompted the recent FBI alert. But Markus said juice jacking is still a risk because it is far easier and cheaper these days for would-be attackers to source and build the necessary equipment. "Since then, the technology and components have become much smaller and very easy to build, which puts this in the hands of less sophisticated threat actors," Markus said. "Also, you can now buy all this stuff over the counter. I think the risk is possibly higher now than it was a decade ago, because a much larger population of people can now pull this off easily." How seriously should we take the recent FBI warning? An investigation by the myth-busting site Snopes suggests the FBI tweet was just a public service announcement based on a dated advisory. Snopes reached out to both the FBI and the FCC to request data about how widespread the threat of juice jacking is in 2023. "The FBI replied that its tweet was a 'standard PSA-type post' that stemmed from the FCC warning," Snopes reported. "An FCC spokesperson told Snopes that the commission wanted to make sure that their advisory on "juice-jacking," first issued in 2019 and later updated in 2021, was up-to-date so as to ensure 'the consumers have the most up-to-date information.' The official, who requested anonymity, added that they had not seen any rise in instances of consumer complaints about juice-jacking." What can you do to avoid juice jacking? Bring your own gear. A general rule of thumb in security is that if an adversary has physical access to your device, you can no longer trust the security or integrity of that device. This also goes for things that plug into your devices. Juice jacking isn't possible if a device is charged via a trusted AC adapter, battery backup device, or through a USB cable with only power wires and no data wires present. If you lack these things in a bind and still need to use a public charging kiosk or random computer, at least power your device off before plugging it in. This entry was posted on Friday 14th of April 2023 04:27 PM A Little Sunshine Latest Warnings Security Tools Aries Security Brian Markus defcon fbi FCC juice jacking OMG cable Snopes Post navigation - Microsoft (& Apple) Patch Tuesday, April 2023 Edition 8 thoughts on "Why is 'Juice Jacking' Suddenly Back in the News?" 1. LarryF April 14, 2023 One thing to note: Most smartphones will power on when plugged in, because the charger circuit in the phone requires power itself. You can turn the phone off after it starts charging, but how much damage can be done in those few seconds? And what if you don't notice that the phone has powered on? So I would suggest skipping the advice to power it off, and only use your own power sources. Reply - 1. Josh K April 14, 2023 I can't imagine that is a realistic risk vector. The charging circuit may be powered, but the OS isn't booted up and the storage would still be encrypted. Reply - 2. Aggelos April 14, 2023 Well, sure enough you can find "power only" cables. But what I have seen missing from this whole noise about Juice Jacking is the use of USB condoms. Are there issues with the condoms I'm not aware of ? Reply - 3. Smooth Jimmy Apollo April 14, 2023 Good thing I saved my Juice-Jack Defender. Reply - 4. Steve April 14, 2023 Not sure about "most smartphones," but any recent generations of Samsung phones that are powered off do not boot up when plugged in. They only go into a state that's powered up enough to allow the charging system to function. In that state, no data is accessible through the USB port. Of course if the phone is already booted when plugged, or if the user physically pushes the right combination of buttons to put it into a recovery state, that's a different story. But most people don't want to power off their phone to charge it at public charging locations, as they probably want to use the phone while it's charging. The best advice when using such public charging stations is to use your own AC adapter and/or a USB cable that only has the power lines connected (the data lines are disconnected). Reply - 5. Billy Jack April 14, 2023 I have some of the USB batteries that you can charge and then use to charge your cell phone. They were giving them away at a meeting I went to last year and they gave me a couple handfuls of them. Since I'm not a big cell phone user, I haven't actually needed to use them -- a charge is usually enough for a week for me. Reply - 6. Craig Keefner April 14, 2023 95% of phone charging at airports takes place on airport provided charging ports run by third party I think. You want to juice Jack then Jack the provider networks. Reply - 7. redrocket April 14, 2023 c'mon, Prof Brian... !?Snopes?! surely you jest...why give mention/ credence to a tturd? asks this 'ol mechanic& your faithful reader from your days bygone at WaPo. cheers Reply - Leave a Reply Cancel reply Your email address will not be published. Required fields are marked * [ ] [ ] [ ] [ ] [ ] [ ] [ ] Comment * [ ] Name * [ ] Email * [ ] Website [ ] [Post Comment] [ ] [ ] [ ] [ ] [ ] [ ] [ ] D[ ] Advertisement [3] Advertisement Mailing List Subscribe here Search KrebsOnSecurity Search for: [ ] [Search] Recent Posts * Why is 'Juice Jacking' Suddenly Back in the News? * Microsoft (& Apple) Patch Tuesday, April 2023 Edition * FBI Seizes Bot Shop 'Genesis Market' Amid Arrests Targeting Operators, Suppliers * A Serial Tech Investment Scammer Takes Up Coding? * German Police Raid DDoS-Friendly Host 'FlyHosting' Spam Nation Spam Nation A New York Times Bestseller! Thinking of a Cybersecurity Career? Thinking of a Cybersecurity Career? Read this. All About Skimmers All About Skimmers Click image for my skimmer series. Story Categories * A Little Sunshine * All About Skimmers * Ashley Madison breach * Breadcrumbs * Data Breaches * DDoS-for-Hire * Employment Fraud * How to Break Into Security * Latest Warnings * Ne'er-Do-Well News * Other * Pharma Wars * Ransomware * Russia's War on Ukraine * Security Tools * SIM Swapping * Spam Nation * Target: Small Businesses * Tax Refund Fraud * The Coming Storm * Time to Patch * Web Fraud 2.0 The Value of a Hacked PC valuehackedpc Badguy uses for your PC Badguy Uses for Your Email Badguy Uses for Your Email Your email account may be worth far more than you imagine. Donate to Krebs On Security Most Popular Posts * Sextortion Scam Uses Recipient's Hacked Passwords (1076) * Online Cheating Site AshleyMadison Hacked (798) * Sources: Target Investigating Data Breach (620) * Trump Fires Security Chief Christopher Krebs (534) * Why Paper Receipts are Money at the Drive-Thru (530) * Cards Stolen in Target Breach Flood Underground Markets (445) * Reports: Liberty Reserve Founder Arrested, Site Shuttered (416) * Was the Ashley Madison Database Leaked? (376) * DDoS-Guard To Forfeit Internet Space Occupied by Parler (374) * True Goodbye: 'Using TrueCrypt Is Not Secure' (363) Why So Many Top Hackers Hail from Russia [computered-580x389] Category: Web Fraud 2.0 Criminnovations Innovations from the Underground [shreddedID-copy-285x189] ID Protection Services Examined Is Antivirus Dead? Is Antivirus Dead? The reasons for its decline The Growing Tax Fraud Menace The Growing Tax Fraud Menace File 'em Before the Bad Guys Can Inside a Carding Shop Inside a Carding Shop A crash course in carding. Beware Social Security Fraud Beware Social Security Fraud Sign up, or Be Signed Up! How Was Your Card Stolen? How Was Your Card Stolen? Finding out is not so easy. Krebs's 3 Rules... Krebs's 3 Rules... ...For Online Safety. (c) Krebs on Security - Mastodon