Free Republic
Browse · Search
General/Chat
Topics · Post Article

Skip to comments.

Half of people plug in USB drives they find in the parking lot
The Register ^ | 4/11/16 | Shaun Nichols

Posted on 04/11/2016 2:26:42 PM PDT by markomalley

A new study has found that almost half the people who pick up a USB stick they happen across in a parking lot plug said drives into their PCs.

Researchers from Google, the University of Illinois Urbana-Champaign, and the University of Michigan, spread 297 USB drives around the Urbana-Champaign campus. They found that 48 percent of the drives were picked up and plugged into a computer, some within minutes of being dropped.

"The security community has long held the belief that users can be socially engineered into picking up and plugging in seemingly lost USB flash drives they find," the researchers reported this month.

"Unfortunately, whether driven by altruistic motives or human curiosity, the user unknowingly opens their organization to an internal attack when they connect the drive – a physical Trojan horse."

The study dropped USB sticks containing HTML files that had img tags embedded; opening the files fetched the image from a remote server, allowing the researchers to track the USB drives' use and rough location. It's obviously not a perfect means to detect usage, but close enough. And, yes, we're talking about people – students and staff – who hang around a uni campus.

The drives were usually picked up within hours of being left in the lot, with one being opened just six minutes after being dropped off. Overall, 48 per cent of the drives were picked up and plugged into a PC.

Additionally, the study found that just 16 per cent of users bothered to scan the drives with anti-virus software before loading the files; 68 per cent of the respondents said they took no precautions whatsoever before plugging in the drives.

The users said that, for the most part, they were acting in good faith. 68 per cent of the users said they were only accessing the drive in order to find its owner, though a "handful" of respondents said they were planning to keep the USB drive for themselves.

This led the researchers to believe that an attacker would have no problem spreading malware in an organization by simply dropping an infected USB drive in a public place.

"We hope that by bringing these details to light, we remind the security community that some of the simplest attacks remain realistic threats," the researchers said.

"There is still much work needed to understand the dynamics of social engineering, develop technical defenses, and learn how to effectively teach users how to protect themselves." ®


TOPICS: Computers/Internet
KEYWORDS: trojanhorse; usb; virus
Navigation: use the links below to view more comments.
first 1-2021-31 next last

1 posted on 04/11/2016 2:26:42 PM PDT by markomalley
[ Post Reply | Private Reply | View Replies]

To: markomalley

What could go wrong?


2 posted on 04/11/2016 2:27:26 PM PDT by rdl6989
[ Post Reply | Private Reply | To 1 | View Replies]

To: markomalley

That’s like snacking on the discarded french fries left on the fast food table next to you. Ewwww!!!


3 posted on 04/11/2016 2:27:56 PM PDT by fwdude
[ Post Reply | Private Reply | To 1 | View Replies]

To: markomalley

Well duh. It’s like saying you have to program people to pick up money. I don’t think so! The researchers don’t know how many drives were viewed without a broswer, either.


4 posted on 04/11/2016 2:29:24 PM PDT by Cboldt
[ Post Reply | Private Reply | To 1 | View Replies]

To: markomalley

I’ve heard of one company doing classified work that scattered USB drives in its parking lot. Any employee who plugged one into a company computer was fired on the spot.


5 posted on 04/11/2016 2:30:57 PM PDT by null and void ("when authority began inspiring contempt, it had stopped being authority" ~ H. Beam Piper)
[ Post Reply | Private Reply | To 1 | View Replies]

To: markomalley

The users said that, for the most part, they were acting in good faith. 68 per cent of the users said they were only accessing the drive in order to find its owner, though a “handful” of respondents said they were planning to keep the USB drive for themselves.

____________________________________________

Baloney. They were all looking for that free porm.

Woo Hoo.

*They found some all right. Under age porn. Now the FBI wants a word with them.


6 posted on 04/11/2016 2:31:53 PM PDT by Responsibility2nd
[ Post Reply | Private Reply | To 1 | View Replies]

To: null and void

That sounds like a good test.


7 posted on 04/11/2016 2:34:12 PM PDT by wally_bert (I didn't get where I am today by selling ice cream tasting of bookends, pumice stone & West Germany)
[ Post Reply | Private Reply | To 5 | View Replies]

To: null and void

Sounds like a relatively painless way to make staff reductions for the next crop of H1B’s.


8 posted on 04/11/2016 2:34:20 PM PDT by Vigilanteman (ObaMao: Fake America, Fake Messiah, Fake Black man. How many fakes can you fit into one Zer0?)
[ Post Reply | Private Reply | To 5 | View Replies]

To: Vigilanteman

Except citizenship is required to work in such a facility. No H1-Bs.


9 posted on 04/11/2016 2:36:26 PM PDT by null and void ("when authority began inspiring contempt, it had stopped being authority" ~ H. Beam Piper)
[ Post Reply | Private Reply | To 8 | View Replies]

To: markomalley

We have a couple of dedicated computers at work that do only two things. Scan for bad stuff and list the files on the drive. That way, you not only keep any bad stuff from getting into a company computer, by looking at the list of files, you stand a good chance of finding the owner of the lost drive.

I’ve done it many times.


10 posted on 04/11/2016 2:37:58 PM PDT by ButThreeLeftsDo (Get Ready)
[ Post Reply | Private Reply | To 1 | View Replies]

To: markomalley

I never see any lying around

My son did have his 200 dollar plus Bose headphones fall out the FJ door recently

It was 10pm or so and we drove back 8 miles to a near empty lot and there they were right where they fell out in perfect shape

We got lucky


11 posted on 04/11/2016 2:41:26 PM PDT by wardaddy (is Cruz last name a coincidence or a blessing or is he the anti Christ?)
[ Post Reply | Private Reply | To 1 | View Replies]

To: markomalley

Well, people love finding free stuff... Especially if it’s someone elses personal private stuff.
Apparently that includes free virus’s.


12 posted on 04/11/2016 2:42:30 PM PDT by Bullish (Face it, insanity is just not presidential.)
[ Post Reply | Private Reply | To 1 | View Replies]

To: Vigilanteman
Sounds like a relatively painless way to make staff reductions for the next crop of H1B’s.

Of course, firing on the spot wouldn't be an option since the employee would have to be kept on just long enough to train the H1B.

13 posted on 04/11/2016 2:42:37 PM PDT by Fresh Wind (Hey now baby, get into my big black car, I just want to show you what my politics are.)
[ Post Reply | Private Reply | To 8 | View Replies]

To: markomalley

If I find a 64 GB USB drive, you damn right I’ll plug it in.

If I cant ID the owner, finder’s keepers!

My PC doesn’t run anything off of one automatically, and I’m not going to click on .exe, .bat, or HTML files as a matter of years old habit.


14 posted on 04/11/2016 2:43:55 PM PDT by VanDeKoik
[ Post Reply | Private Reply | To 1 | View Replies]

To: markomalley

I plug in found flash drives, but I do it at a public library computer. I look for identifying information and have found owners two out of three times. “Your flash drive is at the desk in the ____ library.”

Put one in my own computer? No way!


15 posted on 04/11/2016 2:44:31 PM PDT by Pollster1 (Somebody who agrees with me 80% of the time is a friend and ally, not a 20% traitor. - Ronald Reagan)
[ Post Reply | Private Reply | To 1 | View Replies]

To: VanDeKoik

A brand new 64GB USB3.0 flash drive will cost you less than twenty bucks.


16 posted on 04/11/2016 2:46:20 PM PDT by NorthMountain (A plague o' both your houses.)
[ Post Reply | Private Reply | To 14 | View Replies]

To: markomalley

Millennials at a university, no wonder they have such a high rate of STD infections.


17 posted on 04/11/2016 2:46:39 PM PDT by doorgunner69
[ Post Reply | Private Reply | To 1 | View Replies]

To: VanDeKoik
My PC doesn’t run anything off of one automatically

I've read about cases where these devices have been hacked to identify themselves as USB keyboards, and then they start sending keystrokes automatically when they're plugged in.

18 posted on 04/11/2016 2:48:39 PM PDT by tacticalogic ("Oh bother!" said Pooh, as he chambered his last round.)
[ Post Reply | Private Reply | To 14 | View Replies]

To: markomalley

Of course they are! Hoping to find some home-made pron!


19 posted on 04/11/2016 2:49:18 PM PDT by bigbob
[ Post Reply | Private Reply | To 1 | View Replies]

To: null and void
Except citizenship is required to work in such a facility . . .

Unless you know a good document counterfeiter. If you are useful to the ruling class, they will even appoint one for you.

20 posted on 04/11/2016 2:52:45 PM PDT by Vigilanteman (ObaMao: Fake America, Fake Messiah, Fake Black man. How many fakes can you fit into one Zer0?)
[ Post Reply | Private Reply | To 9 | View Replies]


Navigation: use the links below to view more comments.
first 1-2021-31 next last

Disclaimer: Opinions posted on Free Republic are those of the individual posters and do not necessarily represent the opinion of Free Republic or its management. All materials posted herein are protected by copyright law and the exemption for fair use of copyrighted works.

Free Republic
Browse · Search
General/Chat
Topics · Post Article

FreeRepublic, LLC, PO BOX 9771, FRESNO, CA 93794
FreeRepublic.com is powered by software copyright 2000-2008 John Robinson