Good thing I only buy cheap cables on aliexpress these days lmao
the Chinese government did it to those
As for now they are welcome to my data more than Palantir lol.
You can just buy them
I knew about these, but always thought I could spot them.
I wouldn't!!!

Ya no definitely. Anything just not a health care for people
The government is that dude who'll talk a big game about how great he is, get ya in bed, fuck you and not even finger blast ya to the finish.
This is pretty much the reason I exclusively use dollar store cables and/or dedicated chargers. Saw a yt video about these things at an airport. The more I learn about tech, the more it makes me wanna uncle Ted the fuck out.
all my family thinks I'm overzealous against tech. I work in tech industry, I know security and vulnerabilities. I know software and hardware.
if anything, I'm underzealous.
I'm actually looking at deep woods properties to build an off-grid home. somewhere I can take the family to get away from everything and just disappear into a void for vacations.
I do call center work in a health care environment. We get lots of scams. Most of them are bad and obvious but someone recently did the math and figured out the don’t need to be good to work.
Follow me for a moment.
Call comes in. It’s a recording. You know this recording. It’s a busy office environment. Paper rustling, typing, annoyed sigh exactly the same number of seconds in every call.
There is no response to your voice. But you have to say the same thing 3 times with no response before you can disconnect the call. So the recoding loops and you continue talking to the bot.
Why?
Well on my side, I know it’s dumb but I have to do it because metrics mean I can continue to almost afford to do things like eat food or masturbate in a warm house in the winter.
They do it because this bot lets them map out our IVR (whatever, it sucks now that it’s AI) and capture voice samples from people who are forbidden to hang up.
Now in years past this wouldn’t be all that useful. The samples are of reps saying basically the same damn thing. But we now live in the era of lifeless AI. So the bar has been lowered for what a legit interaction is. (Seriously, some places paid extra for a more “lifelike” AI that did everything the old EVA bot did but in an Indian accent with the sound of crumpling paper in the background and the occasional “um” thrown in.)
So those voice samples can be used to create a fake call center based on real employee voices. This is a known attack vector that is being used against us in health care right NOW.
But AI needs to profitable so nothing is done about it.
Seriously, they protect AI to such a ridiculous extent they know the scam is happening from the same phone number and they won’t block it or even issue it a challenge.
Yachts at sea.
Yas Queen!
You can now buy one for yourself online. https://shop.hak5.org/products/omg-cable
That is amazing. The x-ray of it is kind of scary, honestly. That little chip could be all it would take to get into an air-gapped machine.
There are a ton of different payloads that can be run on these, for everything from simple keylogging, to root access, to network backdoors. I've only recently gotten into pentesting but with something like this there's no real limit to the damage that could be done with only a few seconds of physical access.
Honestly, as a Systems/DevOps engineer it's always been well know that if you have physical access, you have zero chance of security. Sure it might take more time if precautions were followed, but you will be owned eventually, that's guaranteed.
Crazy that the USB-A housing is big enough for that. Makes me want to avoid anything that's not C to C.
Edit: someone pointed out there's an option for C to C 💀
C-to-C is even worse because Usb-C requires a chip in the connector, and you never know what that chip is capable of. Usb-A would only have a chip in it if it's been tampered with.
Came to check if anyone had already linked hak5. Glad to see you had shared the link!
Dude, we’ve been able to do that with a fucking arduino for years.
You might be interested in the full Snowden leak
Yeah, it's scary how much people don't remember/don't know
And don't care.
Maybe, might also be that since tech literacy has degraded since his leak. Which means that they don't care because they are overwhelmed with the information that they don't understand. Hell, I imagine that a lot of the press that where sent the information didn't fully understand.
The average person likely defaulted to what they always do, and just assumed that the leak meant the feds had to stop and treat it like any other historic reveal (example being stuff like COINTELPRO and believing that it was bad but isn't done anymore). Hell, a shocking amount of libs honestly thought that Biden was going to bring Medicare for All (even though he said he wasn't) just because he said "the Democratic Party is the party of healthcare" a few times.
I'm sure it's a spectrum, and some people may legitimately not be aware, but its been 13 years. As a society, we've had ample time to get literate and develop knowledge. Instead we've had three presidents from both major parties hold the line that Snowden was a criminal for blowing the whistle on rampant illegal surveillance, and all 3 of them just stepped on the gas.
Voters don't even see the irony in the pedophiles' ramping up the surveillance apparatus in the name of protecting the children.
Not just the US government, anyone has been able to do this for years
This is rather trivial to do. Micro chips are small.
Joke's on you, I still use Firewire.
yeah that's a good joke
Anyone can do this.
Any government and crooks as well. Its been possible a lot longer than fifteen years.
Compromising computers with tech is nearly as old as computers themselves. The wireless aspect makes it more convenient but in no way is doing so new.
You can see a CT scan of one of these
https://www.techspot.com/news/105863-usb-c-cable-can-hide-lot-malicious-hardware.html
Pro Tip: Leave a unique mark somewhere on the cable so if someone switches it, you can tell it apart. Always check for the mark before you use the cable, every time.
(Yes I actually do this, I'm paranoid)
Don't worry, I'm pretty sure TAO won't bother to bug your cables since the NSA already has the data they want on you anyway lol
We found out 15 years ago the hardware is probably older
USB condoms for charging exist for a reason.
I am not terribly worried about USB/thunderbolt attacks since Android requires authentication before it does anything.
Lol, plug a usb mouse or keyboard into your android and it will just work. Anything you can do these things can do.
My phone still requires auth to use plus there is no way for them to get what's on the screen. I'm also pretty sure that typing a pin requires the screen but I could be mistaken.
Even if there was a way to attack from USB, I still wouldn't be that worried. USB attacks typically are only used against targeted individuals not some rando. The reason why you see warnings about chargers is because it makes easy clickbait.
No permission needed for a keyboard to open up a malicious webpage.
Yes a keyboard. Your USB cable wears a trench coat that says "Hey I'm a Keyboard, lemmy in"
I've been using wireless chargers for years. I find it "more secure" in the sense that my phone's port is full of gunk and if I want to wake up with full batteries I can count on wireless a lot more.
Today I Learned
What did you learn today? Share it with us!
We learn something new every day. This is a community dedicated to informing each other and helping to spread knowledge.
The rules for posting and commenting, besides the rules defined here for lemmy.world, are as follows:
Rules (interactive)
Rule 1- All posts must begin with TIL. Linking to a source of info is optional, but highly recommended as it helps to spark discussion.
** Posts must be about an actual fact that you have learned, but it doesn't matter if you learned it today. See Rule 6 for all exceptions.**
Rule 2- Your post subject cannot be illegal or NSFW material.
Your post subject cannot be illegal or NSFW material. You will be warned first, banned second.
Rule 3- Do not seek mental, medical and professional help here.
Do not seek mental, medical and professional help here. Breaking this rule will not get you or your post removed, but it will put you at risk, and possibly in danger.
Rule 4- No self promotion or upvote-farming of any kind.
That's it.
Rule 5- No baiting or sealioning or promoting an agenda.
Posts and comments which, instead of being of an innocuous nature, are specifically intended (based on reports and in the opinion of our crack moderation team) to bait users into ideological wars on charged political topics will be removed and the authors warned - or banned - depending on severity.
Rule 6- Regarding non-TIL posts.
Provided it is about the community itself, you may post non-TIL posts using the [META] tag on your post title.
Rule 7- You can't harass or disturb other members.
If you vocally harass or discriminate against any individual member, you will be removed.
Likewise, if you are a member, sympathiser or a resemblant of a movement that is known to largely hate, mock, discriminate against, and/or want to take lives of a group of people, and you were provably vocal about your hate, then you will be banned on sight.
For further explanation, clarification and feedback about this rule, you may follow this link.
Rule 8- All comments should try to stay relevant to their parent content.
Rule 9- Reposts from other platforms are not allowed.
Let everyone have their own content.
Rule 10- Majority of bots aren't allowed to participate here.
Unless included in our Whitelist for Bots, your bot will not be allowed to participate in this community. To have your bot whitelisted, please contact the moderators for a short review.
Partnered Communities
You can view our partnered communities list by following this link. To partner with our community and be included, you are free to message the moderators or comment on a pinned post.
Community Moderation
For inquiry on becoming a moderator of this community, you may comment on the pinned post of the time, or simply shoot a message to the current moderators.