[HN Gopher] Why is 'juice jacking' suddenly back in the news?
       ___________________________________________________________________
        
       Why is 'juice jacking' suddenly back in the news?
        
       Author : todsacerdoti
       Score  : 37 points
       Date   : 2023-04-14 20:38 UTC (2 hours ago)
        
 (HTM) web link (krebsonsecurity.com)
 (TXT) w3m dump (krebsonsecurity.com)
        
       | dmix wrote:
       | > Brian Markus is co-founder of Aries Security, and one of the
       | researchers who originally showcased the threat from juice
       | jacking at the 2011 DEFCON. Markus said he isn't aware of any
       | public accounts of juice jacking kiosks being found in the wild,
       | and said he's unsure what prompted the recent FBI alert.
       | 
       | Maybe the FBI came across some foreign actor that talked about
       | doing this or maybe they did come across it in real life and
       | we'll have to wait for some future trial/operation to learn about
       | it (if ever).
       | 
       | Still that $180 USB cable is really interesting. Fortunately it's
       | expensive, although it's designed for professional red teaming.
        
       | morkalork wrote:
       | Score one for QI charging?
        
       | JohnFen wrote:
       | Data blocker dongles are very cheap and effective.
        
       | 01100011 wrote:
       | Have any attacks surfaced which are effected only by manipulation
       | of the power rails? I would think a charge only cable is
       | sufficient to keep you safe.
        
         | [deleted]
        
       | spicybright wrote:
       | Back in 2011 it was easy to just use a power only USB cable. Is
       | there something like that for modern USB-C style charging?
        
         | thaumasiotes wrote:
         | USB-C has meant that cables have split into one paradigm with
         | high power draw and low data transfer speed (for charging), and
         | a separate paradigm with low power draw and high data transfer
         | speed (for data transfer). You need to buy separate cables and
         | then keep track of which is which, but, luckily for you, they
         | have exactly the same connectors. It is not clear to me why
         | this represents a technological advance over the ancient system
         | of having separate power and data cables using different
         | connectors.
         | 
         | On the other hand, you don't see power cables with _no_ data
         | transfer capabilities. For phones, the obvious solution would
         | appear to be the fact that when you plug your phone into a
         | power source that also has data capabilities, it defaults to
         | "USB is for power only", and you'd have to manually switch it
         | to data transfer if you actually wanted data transfer.
         | 
         | For laptops... how often do USB-C-charging laptops accept data
         | through the charging port?
        
           | Tagbert wrote:
           | If you buy regular USB-C cables design for data they will
           | charge exactly as fast as the USB-PD cables. UBS-PD is setup
           | as a spec so companies can sell cheaper cables just for
           | charging.
           | 
           | To avoid this kind of problem, you need to add an adaptor or
           | cable with the data pins disabled.
           | https://www.amazon.com/dp/B082WDHS22/ref=vp_d_cpf-
           | substitute...
        
         | Johnny555 wrote:
         | I just use a battery pack as a go between -- I never plug my
         | phone directly into a public charger, I either use a tiny
         | charge cube and plug into the wall (if I can find an outlet),
         | or recharge a battery pack that I use to charge my phone.
         | 
         | Another advantage of the battery pack is that I'm a lot less
         | worried about leaving a $15 battery pack unattended while I go
         | pick up some food than my $500 phone.
        
           | Eduard wrote:
           | All this assuming there didn't exist an exploitable firmware
           | in your USB chargers and powerbanks, which could be used to
           | spread a USB virus or install a payload.
        
             | UltimateEdge wrote:
             | I doubt the USB data lines on a portable charger are
             | connected to anything. When did you last update the
             | firmware for your charger?
        
             | Johnny555 wrote:
             | Are there any $15 battery packs that have exposed firmware?
        
           | quickthrower2 wrote:
           | 2033: Virus that infects battery pack smart wifi connection
           | and then infects phone that it charges
        
         | Tagbert wrote:
         | Yes, I keep exactly that kind of short cable in my travel bag.
         | There are also USB-A versions for the more common kind of port
         | you might find.
         | 
         | https://www.amazon.com/dp/B082WDHS22/ref=vp_d_cpf-substitute...
        
       | satoshiiii wrote:
       | If you happen to be passing through an airport in a country where
       | the government is known for engaging in mass surveillance
       | activities, then you should take this advice very seriously,
       | without any exceptions - you should always assume that your
       | privacy is at risk of being violated or compromised.
        
         | quickthrower2 wrote:
         | That is one threat but it is not just the government.
        
         | ppergame wrote:
         | That's every country.
        
       | strken wrote:
       | How well does USB-C cope with missing data pins? Does it prevent
       | the USB Power Delivery negotiation?
        
         | the__alchemist wrote:
         | Works fine. Still needs the CC pins wired though with the
         | appropriate resistors.
        
       | tedunangst wrote:
       | Because the penalty for baseless "better safe than sorry"
       | advisories is nil.
        
         | jfghi wrote:
         | Perhaps the actors just want to provide "a more personalized
         | experience that respects your privacy"
        
       | standardUser wrote:
       | If airport USB chargers aren't considered secure, that seems like
       | it's own _extremely_ serious problem that we should be taking
       | drastic actions to remedy immediately. FFS.
        
         | tedunangst wrote:
         | For real, if I were to somehow conclude I'd been juice jacked
         | at an airport, I would move mountains to go back and get ahold
         | of that charger. I wouldn't wait three years and then drop an
         | offhand HN comment that oh yeah, happened to me one time.
        
           | Johnny555 wrote:
           | How would you get ahold of a 6 foot tall charging kiosk and
           | what would you do with it or prove to someone at the airport
           | that it was the culprit? Especially since the "juicer" could
           | be s small skimmer overlaid on top of a legit charger that's
           | been removed since you last used it.
        
             | tedunangst wrote:
             | Yeah, it's a real struggle that the evidence always
             | disappears when I go back to look for it.
             | 
             | Or maybe I toss an orange maintenance vest in my carryon,
             | put it on past security, and rip the fucker apart on the
             | spot. It's hilarious that just below this is a long thread
             | about the impossibility of stopping somebody from
             | installing a tainted outlet. What's to stop me from
             | uninstalling it?
        
         | enkid wrote:
         | Why would they be considered secure? TSA isn't looking for
         | hacking tools, they're looking for weapons.
        
           | standardUser wrote:
           | From what I understand, a bad actor would need to physically
           | interact with these charging stations. Sounds like a pretty
           | severe breach of security to me that _several_ agencies
           | should be treating like an emergency. We are talking about
           | spaces that are crawling with security and surveillance. If
           | someone can plant a listening device like that, why can 't
           | they plant an explosive or biological weapon?
        
             | kube-system wrote:
             | This is like someone's mother asking why a software
             | developer can't fix her printer. Because "computers" is
             | more than a single discipline.
             | 
             | "Security" is not one big umbrella.
             | 
             | The specific people and organizations tasked with
             | protecting air travel are not tasked with protecting the
             | cell phones of the passengers traveling.
        
             | Bjartr wrote:
             | > why can't they plant an explosive or biological weapon?
             | 
             | Because you can't chemically detect a circuit based on its
             | use case, but those two items have a low false-negative
             | detection rate?
        
             | enkid wrote:
             | You're assuming the charging station isn't compromised to
             | start with. A charging station with one of these tools
             | would look basically the same as a normal charging station.
             | One with a bomb or chemical weapon would look different.
        
               | broast wrote:
               | It's a little confusing about airports specifically.
               | Usually official airport usb stations are built into the
               | furniture. They would have to take the thing apart to
               | insert a device? I don't see an example in this article
               | of an inconspicuous device for these types of ports
        
               | inconceivable wrote:
               | what he's saying is the usb port thing is possibly
               | compromised at the factory it was made in.
        
               | bhk wrote:
               | If so, how is carrying your own charger going to help?
        
               | freedomben wrote:
               | AC power lines don't have data lines, and even if they
               | did the juice goes through a process to become DC 5V. It
               | would be pretty tough to exploit a USB stack through a
               | transformer and rectifier.
               | 
               | I've learned never to say never, but ...
        
               | georgyo wrote:
               | I don't think the concern was the power...
               | 
               | If the usb charger outlets being sent to a very federally
               | regulated airports and installed without detection for
               | many years are compromised at the factory, how am I to
               | trust the USB charger I buy at a gas station or Amazon?
        
               | FinnKuhn wrote:
               | I think they meant, how you would know that your own
               | charger is save, when they are malicious from the
               | factory. The answer to that question is to buy from a
               | reputable seller/manufacturer or/and use a cable without
               | data lines (for example Apple MagSafe).
        
             | acchow wrote:
             | Someone could also bring in a USB charger and mount it onto
             | a table to make it look like it was installed by the
             | airport.
        
             | [deleted]
        
             | xattt wrote:
             | > If someone can plant a listening device like that, why
             | can't they plant an explosive or biological weapon?
             | 
             | Because quiet infiltration is of more value than a violent
             | attack.
        
             | aftbit wrote:
             | A sufficiently malicious, motivated, and suicidal (or
             | misled) actor absolutely could use an explosive or
             | biological weapon to attack an airport, essentially
             | regardless of the on-premises security posture. For
             | explosives, one would simply detonate their bomb IN the
             | security line on a busy day. For biologicals, one would
             | simply infect themselves first, then spend the day at the
             | airport waiting for a plane. I continue to be baffled why
             | we don't hear more of such attacks.
        
             | dehrmann wrote:
             | > We are talking about spaces that are crawling with
             | security and surveillance
             | 
             | For some of these outlets, you need a screwdriver, a
             | compromised replacement outlet, and 30 seconds. Maybe a
             | friend and some luggage to block cameras.
             | 
             | I have no knowledge into the internal workings of airport
             | security, but I doubt this is a threat they're worried
             | about or looking for. No amount of cameras help with that.
        
               | rocqua wrote:
               | Exactly. It's not like it would take compromising the
               | vendor, or the service contract. The install can be a
               | simple and quick swap.
               | 
               | The infeasiblity mostly seems targeting and monitization.
               | You have no clue who or what will plug in, so it's barely
               | useful for directed attacks. And actually getting value
               | (intel or money) when all you know to expect is "a
               | smartphone will connect" is quite hard.
        
               | dehrmann wrote:
               | Unlike a skimmer on an ATM.
        
             | libraryatnight wrote:
             | People have been installing skimmers on atms and gaspumps
             | and who knows what else in heavily recorded and busy places
             | for ages. Airports have the benefit of being 24 hours and
             | you can loiter there all you want if you're waiting for
             | another flight.
             | 
             | As for the professional shampoo confiscators I wouldn't
             | factor them at all.
             | 
             | edit: I like the assertion below, too, that the ports may
             | just be factory compromised and unsafe from the start.
        
           | Paul-Craft wrote:
           | TSA is not known to be great at finding weapons, either.
        
       | nilespotter wrote:
       | I wondered the same thing recently. I'm pretty sure you have to
       | explicitly trust any new device that's plugged in on both Android
       | and iOS now. Isn't this kind of solved?
        
         | Bjartr wrote:
         | I've never been asked to authorize a charger I've plugged in.
         | Plus, that assumes no exploits against the could be used that
         | circumvent that system.
        
           | mr_mitm wrote:
           | Chargers don't have to be authorized. Chargers that pretend
           | to be a computer do.
        
             | cyberbanjo wrote:
             | But do chargers that pretend to be keyboards, and other HID
             | (Human Interface Devices) have to be authorized?
        
       ___________________________________________________________________
       (page generated 2023-04-14 23:01 UTC)