[HN Gopher] Why is 'juice jacking' suddenly back in the news?
___________________________________________________________________
Why is 'juice jacking' suddenly back in the news?
Author : todsacerdoti
Score : 37 points
Date : 2023-04-14 20:38 UTC (2 hours ago)
(HTM) web link (krebsonsecurity.com)
(TXT) w3m dump (krebsonsecurity.com)
| dmix wrote:
| > Brian Markus is co-founder of Aries Security, and one of the
| researchers who originally showcased the threat from juice
| jacking at the 2011 DEFCON. Markus said he isn't aware of any
| public accounts of juice jacking kiosks being found in the wild,
| and said he's unsure what prompted the recent FBI alert.
|
| Maybe the FBI came across some foreign actor that talked about
| doing this or maybe they did come across it in real life and
| we'll have to wait for some future trial/operation to learn about
| it (if ever).
|
| Still that $180 USB cable is really interesting. Fortunately it's
| expensive, although it's designed for professional red teaming.
| morkalork wrote:
| Score one for QI charging?
| JohnFen wrote:
| Data blocker dongles are very cheap and effective.
| 01100011 wrote:
| Have any attacks surfaced which are effected only by manipulation
| of the power rails? I would think a charge only cable is
| sufficient to keep you safe.
| [deleted]
| spicybright wrote:
| Back in 2011 it was easy to just use a power only USB cable. Is
| there something like that for modern USB-C style charging?
| thaumasiotes wrote:
| USB-C has meant that cables have split into one paradigm with
| high power draw and low data transfer speed (for charging), and
| a separate paradigm with low power draw and high data transfer
| speed (for data transfer). You need to buy separate cables and
| then keep track of which is which, but, luckily for you, they
| have exactly the same connectors. It is not clear to me why
| this represents a technological advance over the ancient system
| of having separate power and data cables using different
| connectors.
|
| On the other hand, you don't see power cables with _no_ data
| transfer capabilities. For phones, the obvious solution would
| appear to be the fact that when you plug your phone into a
| power source that also has data capabilities, it defaults to
| "USB is for power only", and you'd have to manually switch it
| to data transfer if you actually wanted data transfer.
|
| For laptops... how often do USB-C-charging laptops accept data
| through the charging port?
| Tagbert wrote:
| If you buy regular USB-C cables design for data they will
| charge exactly as fast as the USB-PD cables. UBS-PD is setup
| as a spec so companies can sell cheaper cables just for
| charging.
|
| To avoid this kind of problem, you need to add an adaptor or
| cable with the data pins disabled.
| https://www.amazon.com/dp/B082WDHS22/ref=vp_d_cpf-
| substitute...
| Johnny555 wrote:
| I just use a battery pack as a go between -- I never plug my
| phone directly into a public charger, I either use a tiny
| charge cube and plug into the wall (if I can find an outlet),
| or recharge a battery pack that I use to charge my phone.
|
| Another advantage of the battery pack is that I'm a lot less
| worried about leaving a $15 battery pack unattended while I go
| pick up some food than my $500 phone.
| Eduard wrote:
| All this assuming there didn't exist an exploitable firmware
| in your USB chargers and powerbanks, which could be used to
| spread a USB virus or install a payload.
| UltimateEdge wrote:
| I doubt the USB data lines on a portable charger are
| connected to anything. When did you last update the
| firmware for your charger?
| Johnny555 wrote:
| Are there any $15 battery packs that have exposed firmware?
| quickthrower2 wrote:
| 2033: Virus that infects battery pack smart wifi connection
| and then infects phone that it charges
| Tagbert wrote:
| Yes, I keep exactly that kind of short cable in my travel bag.
| There are also USB-A versions for the more common kind of port
| you might find.
|
| https://www.amazon.com/dp/B082WDHS22/ref=vp_d_cpf-substitute...
| satoshiiii wrote:
| If you happen to be passing through an airport in a country where
| the government is known for engaging in mass surveillance
| activities, then you should take this advice very seriously,
| without any exceptions - you should always assume that your
| privacy is at risk of being violated or compromised.
| quickthrower2 wrote:
| That is one threat but it is not just the government.
| ppergame wrote:
| That's every country.
| strken wrote:
| How well does USB-C cope with missing data pins? Does it prevent
| the USB Power Delivery negotiation?
| the__alchemist wrote:
| Works fine. Still needs the CC pins wired though with the
| appropriate resistors.
| tedunangst wrote:
| Because the penalty for baseless "better safe than sorry"
| advisories is nil.
| jfghi wrote:
| Perhaps the actors just want to provide "a more personalized
| experience that respects your privacy"
| standardUser wrote:
| If airport USB chargers aren't considered secure, that seems like
| it's own _extremely_ serious problem that we should be taking
| drastic actions to remedy immediately. FFS.
| tedunangst wrote:
| For real, if I were to somehow conclude I'd been juice jacked
| at an airport, I would move mountains to go back and get ahold
| of that charger. I wouldn't wait three years and then drop an
| offhand HN comment that oh yeah, happened to me one time.
| Johnny555 wrote:
| How would you get ahold of a 6 foot tall charging kiosk and
| what would you do with it or prove to someone at the airport
| that it was the culprit? Especially since the "juicer" could
| be s small skimmer overlaid on top of a legit charger that's
| been removed since you last used it.
| tedunangst wrote:
| Yeah, it's a real struggle that the evidence always
| disappears when I go back to look for it.
|
| Or maybe I toss an orange maintenance vest in my carryon,
| put it on past security, and rip the fucker apart on the
| spot. It's hilarious that just below this is a long thread
| about the impossibility of stopping somebody from
| installing a tainted outlet. What's to stop me from
| uninstalling it?
| enkid wrote:
| Why would they be considered secure? TSA isn't looking for
| hacking tools, they're looking for weapons.
| standardUser wrote:
| From what I understand, a bad actor would need to physically
| interact with these charging stations. Sounds like a pretty
| severe breach of security to me that _several_ agencies
| should be treating like an emergency. We are talking about
| spaces that are crawling with security and surveillance. If
| someone can plant a listening device like that, why can 't
| they plant an explosive or biological weapon?
| kube-system wrote:
| This is like someone's mother asking why a software
| developer can't fix her printer. Because "computers" is
| more than a single discipline.
|
| "Security" is not one big umbrella.
|
| The specific people and organizations tasked with
| protecting air travel are not tasked with protecting the
| cell phones of the passengers traveling.
| Bjartr wrote:
| > why can't they plant an explosive or biological weapon?
|
| Because you can't chemically detect a circuit based on its
| use case, but those two items have a low false-negative
| detection rate?
| enkid wrote:
| You're assuming the charging station isn't compromised to
| start with. A charging station with one of these tools
| would look basically the same as a normal charging station.
| One with a bomb or chemical weapon would look different.
| broast wrote:
| It's a little confusing about airports specifically.
| Usually official airport usb stations are built into the
| furniture. They would have to take the thing apart to
| insert a device? I don't see an example in this article
| of an inconspicuous device for these types of ports
| inconceivable wrote:
| what he's saying is the usb port thing is possibly
| compromised at the factory it was made in.
| bhk wrote:
| If so, how is carrying your own charger going to help?
| freedomben wrote:
| AC power lines don't have data lines, and even if they
| did the juice goes through a process to become DC 5V. It
| would be pretty tough to exploit a USB stack through a
| transformer and rectifier.
|
| I've learned never to say never, but ...
| georgyo wrote:
| I don't think the concern was the power...
|
| If the usb charger outlets being sent to a very federally
| regulated airports and installed without detection for
| many years are compromised at the factory, how am I to
| trust the USB charger I buy at a gas station or Amazon?
| FinnKuhn wrote:
| I think they meant, how you would know that your own
| charger is save, when they are malicious from the
| factory. The answer to that question is to buy from a
| reputable seller/manufacturer or/and use a cable without
| data lines (for example Apple MagSafe).
| acchow wrote:
| Someone could also bring in a USB charger and mount it onto
| a table to make it look like it was installed by the
| airport.
| [deleted]
| xattt wrote:
| > If someone can plant a listening device like that, why
| can't they plant an explosive or biological weapon?
|
| Because quiet infiltration is of more value than a violent
| attack.
| aftbit wrote:
| A sufficiently malicious, motivated, and suicidal (or
| misled) actor absolutely could use an explosive or
| biological weapon to attack an airport, essentially
| regardless of the on-premises security posture. For
| explosives, one would simply detonate their bomb IN the
| security line on a busy day. For biologicals, one would
| simply infect themselves first, then spend the day at the
| airport waiting for a plane. I continue to be baffled why
| we don't hear more of such attacks.
| dehrmann wrote:
| > We are talking about spaces that are crawling with
| security and surveillance
|
| For some of these outlets, you need a screwdriver, a
| compromised replacement outlet, and 30 seconds. Maybe a
| friend and some luggage to block cameras.
|
| I have no knowledge into the internal workings of airport
| security, but I doubt this is a threat they're worried
| about or looking for. No amount of cameras help with that.
| rocqua wrote:
| Exactly. It's not like it would take compromising the
| vendor, or the service contract. The install can be a
| simple and quick swap.
|
| The infeasiblity mostly seems targeting and monitization.
| You have no clue who or what will plug in, so it's barely
| useful for directed attacks. And actually getting value
| (intel or money) when all you know to expect is "a
| smartphone will connect" is quite hard.
| dehrmann wrote:
| Unlike a skimmer on an ATM.
| libraryatnight wrote:
| People have been installing skimmers on atms and gaspumps
| and who knows what else in heavily recorded and busy places
| for ages. Airports have the benefit of being 24 hours and
| you can loiter there all you want if you're waiting for
| another flight.
|
| As for the professional shampoo confiscators I wouldn't
| factor them at all.
|
| edit: I like the assertion below, too, that the ports may
| just be factory compromised and unsafe from the start.
| Paul-Craft wrote:
| TSA is not known to be great at finding weapons, either.
| nilespotter wrote:
| I wondered the same thing recently. I'm pretty sure you have to
| explicitly trust any new device that's plugged in on both Android
| and iOS now. Isn't this kind of solved?
| Bjartr wrote:
| I've never been asked to authorize a charger I've plugged in.
| Plus, that assumes no exploits against the could be used that
| circumvent that system.
| mr_mitm wrote:
| Chargers don't have to be authorized. Chargers that pretend
| to be a computer do.
| cyberbanjo wrote:
| But do chargers that pretend to be keyboards, and other HID
| (Human Interface Devices) have to be authorized?
___________________________________________________________________
(page generated 2023-04-14 23:01 UTC)