• Live Radio
  • Videos
  • About
  • Contact
  • Despite Media
Ghana Election 2020
  • Home
  • Local News
  • Politics
  • Showbiz
  • Sports
  • Business
  • Opinion
  • VIDEOS
  • Media
    • Videos
    • Audio
    • Live Radio
    • Photos
  • Election 2020
Local News
 
 
 
Home News Technology 201408

USB Devices Can ‘Secretly Infect’ PC

08-Aug-2014
/ Technology, News
Email
Print
Comments 0
(0)
Comments
Share on Facebook Share on Twitter
 

USB devices can be used to infect a computer without the user’s knowledge, according to security researchers.

Berlin-based cyber-security experts Karsten Nohl and Jakob Lell demonstrated how malicious code on hardware connected via USB could “hijack” a PC, and gather private data.

The duo said there is no practical way to defend against the vulnerability.

The body responsible for the USB standard said manufacturers could build in extra security.

It is not uncommon for USB sticks to be used as a way of getting viruses and other malicious code onto target computers.

Most famously, the Stuxnet attack on Iranian nuclear centrifuges was believed to have been caused by an infected USB stick.

However, this latest research demonstrated a new level of threat – where a USB device that appears completely empty can still contain malware, even when formatted.

The vulnerability can be used to hide attacks in any kind of USB-connected device – such as a smartphone.

“It may not be the end of the world today,” Mr Nohl told journalists, “but it will affect us, a little bit, every day, for the next 10 years”.

“Basically, you can never trust anything anymore after plugging in a USB stick.”

‘Chip’ exploitedUSB – which stands for Universal Serial Bus – has become the standard method of connecting devices to computers due to its small size, speed and ability to charge devices.

USB memory sticks quickly replaced floppy disks as a simple way to share large files between two computers.

The connector is popular due to the fact that it makes it easy to plug in and install a wide variety of devices. Devices that use USB contain a small chip that “tells” the computer exactly what it is, be it a phone, tablet or any other piece of hardware.

It is this function that has been exposed by the threat.

Smartphone ‘hijack’In one demo, shown off at the Black Hat hackers conference in Las Vegas, a standard USB drive was inserted into a normal computer.

Malicious code implanted on the stick tricked the machine into thinking a keyboard had been plugged in.

After just a few moments, the “keyboard” began typing in commands – and instructed the computer to download a malicious program from the internet.

Another demo, shown in detail to the BBC, involved a Samsung smartphone.

When plugged in to charge, the phone would trick the computer into thinking it was in fact a network card. It meant when the user accessed the internet, their browsing was secretly hijacked.

Mr Nohl demonstrated to the BBC how they were able to create a fake copy of PayPal’s website, and steal user log-in details as a result.

Unlike other similar attacks, where simply looking at the web address can give away a scam website, there were no visible clues that a user was under threat.

The same demo could have been carried out on any website, Mr Nohl stressed.

‘Trust nothing’Mike McLaughlin, a security researcher from First Base Technologies, said the threat should be taken seriously.

“USB is ubiquitous across all devices,” he told the BBC.

“It comes down to the same old saying – don’t plug things in that you don’t trust.

“Any business should always have policies in place regarding USB devices and USB drives. Businesses should stop using them if needed.”

Standard method of connecting devices to computers
Popular due to its small size

Easy to plug in and install a variety of devices

The group responsible for the USB standard, the USB Working Party, refused to comment on the seriousness of the flaw.

But in more general terms, it said: “The USB specifications support additional capabilities for security, but original equipment manufacturers (OEMs) decide whether or not to implement these capabilities in their products.

“Greater capabilities of any product likely results in higher prices, and consumers choose on a daily basis what they are willing to pay to receive certain benefits.

“If consumer demand for USB products with additional capabilities for security grows, we would expect OEMs to meet that demand.”

Mr Nohl said the only protection he could advise was to simply be ultra-cautious when allowing USB devices to be connected to your machines.

“Our approach to using USB will have to change,” he told the BBC.

Source: BBC

 

 
 

 

Comments ( 0 ): Post Your Comments >>

Disclaimer: Opinions expressed here are those of the writers and do not reflect those of Peacefmonline.com. Peacefmonline.com accepts no responsibility legal or otherwise for their accuracy of content. Please report any inappropriate content to us, and we will evaluate it as a matter of priority.
Featured Video
Previous Post

Government Supports Improved Agricultural Technology

Next Post

Google Builds "Faster" Cable Under Pacific Ocean

 
 

More Stories

The Republic Of Ghana Joins The Digital Cooperation Organization
Advisory Firm Innisfree Sues Twitter For $1.9 Million In Unpaid Bills
New Galaxy S23 Series: Designed For A Premium Experience Today And Beyond
IIPGH, AFOS Foundation And Partners Launch Tech Job Fair 2023
Republican U.S. Lawmaker Meets With Tiktok, But Unpersuaded
Boosting Career Readiness Of Ghanaian Youth In ICT
Meta Advertisers Brush Off Trump's Potential Return
Twitter Says Users Will Be Able To Appeal Account Suspension
Samsung Unpacked 2023: Get Ready For The Best Of Samsung Galaxy, Built For Today And Tomorrow
Next Post

Google Builds "Faster" Cable Under Pacific Ocean

  Local News

  • General News
  • Social
  • Health
  • Education
  • Religion
  • Technology
  • Crime & Justice
  • Travel/Tourism
  • Science/Environment


 
 

 

Other Technology Stories

  • The Republic Of Ghana Joins The Digital Cooperation Organization

  • Advisory Firm Innisfree Sues Twitter For $1.9 Million In Unpaid Bills

  • New Galaxy S23 Series: Designed For A Premium Experience Today And Beyond

  • IIPGH, AFOS Foundation And Partners Launch Tech Job Fair 2023

  • Republican U.S. Lawmaker Meets With Tiktok, But Unpersuaded

  • Boosting Career Readiness Of Ghanaian Youth In ICT

  • Meta Advertisers Brush Off Trump's Potential Return

  • Twitter Says Users Will Be Able To Appeal Account Suspension

  • Samsung Unpacked 2023: Get Ready For The Best Of Samsung Galaxy, Built For Today And Tomorrow

  • Australia Regulator To Probe Social Media Influencers For False Endorsements

 

 
 

Popular Videos

Kokrokoo Live On Peace 104.3 FM (06/02/2023)

Kokrokoo Discussion Segment On Peace 104.3 FM (06/02/2023)

Peace Power Sports (06/02/2023)

Akan News @ 6am On Peace 104.3 FM (5/2/2023)

Peace Power Sports (07/02/2023)

The Platform Show With Nana Yaw Kesseh On Peace 104.3 FM (06/02/2023)

Peace FM Online and Despite Media

peacefmonline.com offers its reading audience with a comprehensive online source for up-to-the-minute news about politics, business, entertainment and other issues in Ghana

Follow us on social media:

Category

  • Home
  • Local News
  • Politics
  • Showbiz
  • Sports
  • Business
  • Opinion
  • Trivia
  • Foreign
  • Audio
  • Photos
  • Videos
  • Elections
Decision Time
Ghana Election 2020 2016 Elections
Services
Live Radio Audio on Demand Ghana Elections Advertise with Us
Useful Links
Despite Media About Us Contact Us Feedback Form Terms and Conditions Privacy
Our Brands
Despite Media UTV Peace FM Okay FM Hello FM Neat FM Peacefmonline
  • About
  • Advertise
  • Terms & Conditions
  • Contact
  • Privacy

© 2020 Peacefmonline.com - An online portal owned and managed by Despite Media

  • Home
  • Local News
  • Politics
  • Showbiz
  • Sports
  • Business
  • Articles
  • Trivia
  • Foreign
  • Live Radio
  • Photos
  • Videos
  • Audio
  • Election 2020

© 2020 Peacefmonline.com - An online portal owned and managed by Despite Media