Free Republic
Browse · Search
General/Chat
Topics · Post Article

Skip to comments.

Don't use public USB charging ports
tech radar ^ | 11/15/2019 | Anthony Spadafora

Posted on 11/15/2019 4:48:04 PM PST by BenLurkin

Los Angeles District Attorney has warned travelers to avoid charging their smartphones and other devices using public USB power charging stations as they may contain dangerous malware.

USB was designed to transfer both power and data and security researchers as well as cybercriminals have learned how to use USB connections to deliver malicious payloads to users who thought they were merely charging their devices.

Over the past few years, several proofs of concepts were created with the most notorious being Mactans, which was unveiled at the Black Hat security conference back in 2013. While the device may look like an ordinary USB wall charger, it actually has the capability to deploy malware on iOS devices.

(Excerpt) Read more at techradar.com ...


TOPICS: Computers/Internet
KEYWORDS: chargingports; juicejacking; mactans; usb
Navigation: use the links below to view more comments.
first 1-2021-4041-51 next last

1 posted on 11/15/2019 4:48:04 PM PST by BenLurkin
[ Post Reply | Private Reply | View Replies]

To: BenLurkin

https://www.aukey.com/products/7000mah-power-bank-glossy-pb-n55


2 posted on 11/15/2019 4:51:25 PM PST by Paladin2
[ Post Reply | Private Reply | To 1 | View Replies]

To: BenLurkin

I did this once and got a 5 volt shock.


3 posted on 11/15/2019 4:52:05 PM PST by steve86 (Prophecies of Maelmhaedhoc O'Morgair (Latin form: Malachy))
[ Post Reply | Private Reply | To 1 | View Replies]

To: BenLurkin

l


4 posted on 11/15/2019 4:56:12 PM PST by Jane Austen (Neo-cons are liberal Democrats who love illegal aliens and war.)
[ Post Reply | Private Reply | To 1 | View Replies]

To: BenLurkin

Saw these in airports recently. Also used on our tour bus.


5 posted on 11/15/2019 5:00:48 PM PST by RushIsMyTeddyBear (:¬| Beep beep)
[ Post Reply | Private Reply | To 1 | View Replies]

To: BenLurkin

Including hotel lamps?


6 posted on 11/15/2019 5:01:23 PM PST by Raycpa
[ Post Reply | Private Reply | To 1 | View Replies]

To: RushIsMyTeddyBear

And on our plane. I used the portable.


7 posted on 11/15/2019 5:02:04 PM PST by RushIsMyTeddyBear (:¬| Beep beep)
[ Post Reply | Private Reply | To 5 | View Replies]

To: BenLurkin

You can also get a charge only USB cable which doesn’t have the data wires.


8 posted on 11/15/2019 5:06:24 PM PST by KarlInOhio (Who's the leader of the club that feeds on dead babies? M-O-L... O-C-H... M-O-U-S-E.)
[ Post Reply | Private Reply | To 1 | View Replies]

To: BenLurkin

Never a problem.


9 posted on 11/15/2019 5:07:48 PM PST by MrEdd (Caveat Emptors)
[ Post Reply | Private Reply | To 1 | View Replies]

To: BenLurkin

The charging sockets in the seats at the SW gates at LAX are so loose that a plug-in charging adapter won’t work. You need to use the built-in USB charging ports instead. Maybe those sockets are loose for a reason . . .


10 posted on 11/15/2019 5:08:43 PM PST by Neanderthal (As you import the third world, you become the third world)
[ Post Reply | Private Reply | To 1 | View Replies]

To: BenLurkin

Here is something not commonly known...

Some devices are rigged to pass data over the VCC and GND pins on the USB port....yes, REALLY.

Think about if for a moment and you will imagine all sorts of nefarious uses.

Hardware data protection circuitry generally enables only the VCC and GND pins and leaves the data pins unconnected....so Joe Blo thinks the charger has to be safe. Joe sticks his device on the charger and it passes data over the VCC and GND lines as a pattern of voltage variations.

Joe’s device has to be rigged to handle data on the VCC and GND lines of course...but just think how easy it would be to add that to a smartphone or whatever.

You can buy ‘safe’ USB cables that only have the VCC and GND wires in them..no data lines. So they just have to be safe, right!? lol

The chipping and hardware rigging in hardware would make your head spin...if they could do it, they have done it.

Naughty NSA tricks...

https://www.amazon.com/Plugable-Universal-Charge-Only-Adapter-Android/dp/B00FA9GXKM


11 posted on 11/15/2019 5:09:27 PM PST by Bobalu (Buy and hold physical silver! Consider this a warning my FRiend.)
[ Post Reply | Private Reply | To 1 | View Replies]

To: KarlInOhio

See my post #11


12 posted on 11/15/2019 5:11:25 PM PST by Bobalu (Buy and hold physical silver! Consider this a warning my FRiend.)
[ Post Reply | Private Reply | To 8 | View Replies]

To: Raycpa

You can use a USB data blocker (aka USB condom) to charge your device safely. They sell them on Amazon here:

https://www.amazon.com/Blocker-hi-speed-charging-iPhones-Androids/dp/B0785PB829/ref=sr_1_4?crid=1W40HSZJNRBQG&keywords=usb+condom&qid=1573866562&s=electronics&sprefix=USB+condom%2Caps%2C233&sr=1-4

I would always use them in sketchy travel locations.


13 posted on 11/15/2019 5:11:48 PM PST by Bo1988
[ Post Reply | Private Reply | To 6 | View Replies]

To: Bo1988

Thanks.


14 posted on 11/15/2019 5:12:41 PM PST by Raycpa
[ Post Reply | Private Reply | To 13 | View Replies]

To: BenLurkin

Much of this was mitigated when Apple released iOS 7 beta 2.

Read the Blackhat 2013 paper:

https://media.blackhat.com/us-13/US-13-Lau-Mactans-Injecting-Malware-into-iOS-Devices-via-Malicious-Chargers-WP.pdf

Key to not getting this virus is to refuse any software loading or other device sharing request that appear soon after plugging in the charging station.


15 posted on 11/15/2019 5:14:16 PM PST by Alas Babylon! (The media is after us. Trump's just in the way.)
[ Post Reply | Private Reply | To 1 | View Replies]

To: Bobalu

“Some devices are rigged to pass data over the VCC and GND pins on the USB port....yes, REALLY.”

The receiving device would have to be designed to accept that in order for it to work. But a small capacitor across those pins would completely put an end to that kind of hanky panky anyways.

A tamper proof charging cable or filter would be an easy design and would be a good seller if people take this seriously.


16 posted on 11/15/2019 5:19:30 PM PST by Revel
[ Post Reply | Private Reply | To 11 | View Replies]

To: Bo1988

And there you go!


17 posted on 11/15/2019 5:20:47 PM PST by Revel
[ Post Reply | Private Reply | To 13 | View Replies]

To: MrEdd
"Never a problem."

That you're aware of.

18 posted on 11/15/2019 5:23:14 PM PST by MV=PY (The Magic Question: Who's paying for it?)
[ Post Reply | Private Reply | To 9 | View Replies]

To: BenLurkin

I guess this has to be said, although it should be obvious.


19 posted on 11/15/2019 5:24:18 PM PST by bigbob (Trust Trump. Trust the Plan.)
[ Post Reply | Private Reply | To 1 | View Replies]

To: Bobalu

“Joe sticks his device on the charger and it passes data over the VCC and GND lines as a pattern of voltage variations.”

Digital Telegraph.


20 posted on 11/15/2019 5:26:41 PM PST by Openurmind (The ultimate test of a moral society is the kind of world it leaves to its children. ~ D. Bonhoeffer)
[ Post Reply | Private Reply | To 11 | View Replies]


Navigation: use the links below to view more comments.
first 1-2021-4041-51 next last

Disclaimer: Opinions posted on Free Republic are those of the individual posters and do not necessarily represent the opinion of Free Republic or its management. All materials posted herein are protected by copyright law and the exemption for fair use of copyrighted works.

Free Republic
Browse · Search
General/Chat
Topics · Post Article

FreeRepublic, LLC, PO BOX 9771, FRESNO, CA 93794
FreeRepublic.com is powered by software copyright 2000-2008 John Robinson