|
|
Log in / Subscribe / Register

Security quotes of the week

Security quotes of the week

Posted Sep 16, 2016 9:59 UTC (Fri) by k8to (guest, #15413)
Parent article: Security quotes of the week

I'm not sure I grasp the USB Kill Stick.

It's cute and all, but wouldn't a hammer offer similar results if you have local access to insert a USB device?


to post comments

Security quotes of the week

Posted Sep 16, 2016 11:13 UTC (Fri) by liw (subscriber, #6379) [Link]

It doesn't need to be the attacker who inserts the USB Kill Stick into the computer. Simple social engineering will get people to insert a USB Kill Stick into their own computer. Getting them to hit the computer with a hammer is somewhat harder in practice.

Security quotes of the week

Posted Sep 16, 2016 12:28 UTC (Fri) by farnz (subscriber, #17727) [Link]

If I were to "accidentally" drop a USB stick that looked like a USB Flash drive, labelled "Google plans - please return to MTV campus if found" somewhere near a TechCrunch writer, the chances are extremely high that said writer would plug it into a machine to see what was on it. Similarly, you could probably get a political journalist with a stick labelled "Trump master plans - destroy if found". It'd be chancy (what happens if the wrong person picks up the stick?), but you can drop and forget, thus being safely out of the way when the laptop goes "bang!".

Security quotes of the week

Posted Sep 16, 2016 19:49 UTC (Fri) by Cyberax (✭ supporter ✭, #52523) [Link] (1 responses)

In one company I worked, security department once did a campaign of dropping USB sticks that caused corporate computers to lock up if inserted. And then anyone asking the tech support department for help got a stern lecture.

Security quotes of the week

Posted Sep 19, 2016 12:40 UTC (Mon) by cwillu (guest, #67268) [Link]

Thus ensuring that future issues with lock-ups are not directed to support; brilliant!

Security quotes of the week

Posted Sep 17, 2016 13:04 UTC (Sat) by gioele (subscriber, #61675) [Link]

> I'm not sure I grasp the USB Kill Stick.
>
> It's cute and all, but wouldn't a hammer offer similar results if you have local access to insert a USB device?

I see the USB Kill Stick as the physical counterpart to software security proof of concepts.

Typical sw scenario:

* "We do not need to fix this obscure crash, it never happens with proper input and it is not exploitable anyway"
* ... 2 days later ...
* "PoC published: read a file with `asdasda20101031rm-Rvf/` and it will format your disk"

The USB Kill is a nice demonstration that you need (among thousands of other things) current protection on all your USB ports. It is just a matter of letting a user plug an innocent looking stick into a USB port. Anybody with a USB stick is allowed near copiers in a copy shop and they can kill completely a thousands $currency machine in a second. I'd say it is harder to trash the same machine with a hammer without being noticed.

I hope this nice HW PoC will force manufacturer to think about this problem, especially now that USB is being pushed as a charging interface.


Copyright © 2026, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds