There were lots of businesses, stores, malls, warehouses and parking lots,
but I was horrified by the sheer number of baby cribs, bedrooms, living
rooms and kitchens; all of those were within homes where people should be
safest, but were awaiting some creeper to turn the “security surveillance
footage” meant for protection into an invasion of privacy.
— "
As expected, Karsten Nohl 's new BadUSB exposure info presented at #PacSec14 is not pretty. In the survey of 8 common USB chipset manufacturers and 52 chipset families, about half of your devices, including chargers, storage, cameras, CD-ROM drives, SD card adapters, keyboards, mice, phones, and so on, are all likely to be proven easily reprogrammable and trivially used to piggyback/host multi-platform (portable to different OSes, and even different kinds of devices) attack software - and the others are not necessarily safe, it's just more work to make the attack software.
The depressing part is there is no real solution on the horizon - even the "fuse bit" solutions some folks are touting can be easily bypased by reprogramming/deleting the entire devices. More depressing is that this problem seems so hard that while lots of people are working on attacks, the problem is frustrating enough that very few are working on solutions.
Most of these devices have 32k of firmware. Karsten's attack code including DHCP server and network stack was only a couple of K.... So, yes, your USB charger can attack your phone and your mouse can attack your laptop.
—
Another network-tampering threat to user safety has come to light from other providers: email encryption downgrade attacks. In recent months, researchers have reported
ISPs in the US and
Thailand intercepting their customers' data to strip a security flag—called STARTTLS—from email traffic. The
STARTTLS flag is an essential security and privacy protection used by an email server to request encryption when talking to another server or client.
1
—