11 ms·
No one, not even the Secret Service, should randomly plug in a strange USB stick
- beamatronic 7y agoI doubt they would release their “real” operational procedures to the press. Surely they attached the USB to some sort of sandboxed environment? On the other hand why would they be carrying around such equipment?
- Something1234 7y agoProbably some over eager and hot headed officer wanting to prove they're hot shit without understanding the dangers.
- meowface 7y agoI can totally buy some low-level Secret Service agent with little tech knowledge plugging it into a machine without thinking twice.
- gowld 7y agoOr a high-level agent. There are many dimensions where level is independent of tech savvy. I'm sure >50% of Fortune 500 CEOs could be tricked in the same way -- at least among the ones who use a computer.
- pryce 7y agoThe only prominent former Secret Service agent I'm aware of is Dan Bongino. After viewing his output over the last couple of years, I have developed a fairly low opinion of whether a Secret Service agent chosen at random is likely to display any real insightfulness. I'm sure they're quite well trained for physical combat though.
- meowface 7y agoAbsolutely. I was just thinking, perhaps naively, that a high-level Secret Service agent would be a bit more cautious and would think "I better report this thing to my superiors and not touch it at all, just in case", even if they know nothing about technology. You want cautious and paranoid people in a job like that.
- waffleguy 7y agoUmm... you can use a raspberry pi as a sandbox. My nephew carries around such equipment. Why wouldn’t the secret service?
- steven777400 7y agoI don't know much about this case but depending on the level of concern, even just plugging the device into a safe, isolated machine and performing an image may be insufficient. You could imagine a USB device that presented as a harmless file store unless certain conditions were detected, in which case the device could re-present as a keyboard (providing pre-programmed keystrokes) or potentially a bluetooth or wireless network receiver that could log or analyze traffic to a hidden partition. I think the question of how to safely analyze suspect USB devices, at the level of potential nation-state actors, needs a lot more consideration and probably some custom tooling.
- jakeinspace 7y agoI can't think of many things more fun than coming up with some clever USB descriptor hacks to allow an innocuous drive full of pictures of grandchildren to carefully switch into an HID device when it thinks the coast is clear. I have to imagine there's a lot of little tricks you could implement which would be difficult to trigger in a sandbox and might require dumping the EEPROM (if that's possible).
- j16sdiz 7y agoThere are quite a few usb descriptor related exploits. e.g. https://www.cvedetails.com/cve/CVE-2013-3200/ https://www.cvedetails.com/cve/CVE-2013-3200/
- exelius 7y ago> I think the question of how to safely analyze suspect USB devices, at the level of potential nation-state actors, needs a lot more consideration and probably some custom tooling. I would be absolutely shocked if the US’ three letter agencies did not have some form of custom tooling to detect this — especially considering the sophisticated multi-vector I/O exploitation they demonstrated a decade ago with Stuxnet and the Equation Group. Regardless of your views on his policy, Trump has demonstrated zero respect for opsec — even in a national security context — so I would also not be surprised if those three letter agencies have decided the White House is untrustworthy with its cyber warfare capabilities.
- jimrandomh 7y agoIt's a severe discredit to the major operating system vendors that plugging in a USB stick can still compromise a system. If a USB device identifies itself as a keyboard, the system shouldn't accept its keystrokes until that keyboard has typed the user's login password (EDIT: or the user explicitly authorizes the device using a different keyboard). If it identifies itself as a storage device, the filesystem driver should be hardened. If it identifies itself as an obscure 90s printer with a buggy driver written in C, it should prompt the user to confirm the device type before it loads the driver. It's 2019. Why the f* haven't Windows, MacOS and Linux all implemented these basic precautions?
- peterwwillis 7y agoBuggy drivers are a problem, but if you control the hardware, it's your responsibility to vet what you plug into it. It's like with door locks: if you need protection from advanced thieves you'll need to go through some extra hoops anyway. You could petition OS manufacturers to focus more on physical security, but there's limits to what you can do without piles of abstractions (ala smart phone security)
- gowld 7y agoA human cannot vet an electronic device. We can only interface to it from another electronic device. The same argument applies to the Internet -- we don't say that it's the human's responsibility to vet every website or email message before we let our computer connect to it. We expect our computer to do that. That's why it was wrong for Outlook to automatically execute every program sent to you via email.
- peterwwillis 7y agoYour computer isn't vetting things it gets from the internet at all, with the exception of TLS certs and anti-virus scanning. Virtually all other operations done with remote content are unvetted; it's play & pray. You clicking a button is the only vetting process.
- TheDong 7y ago
- rblatz 7y agoWilliams said the best way to forensically examine a suspect USB drive is by plugging the device into an isolated Linux-based computer that doesn’t automatically mount the drive to the operating system. “We would then create a forensic image of the USB and extract any malware for analysis in the lab,” he said. “While there is still a very small risk that the malware targets Linux, that’s not the normal case.” That's an ok start, but you not only want to prevent it from auto-mounting the filesystem, you want it to not even auto-configure any USB HIDs presented to the OS. And even then that may not be enough if there are flaws deep in the usb stack that are being exploited. Ideally you'd have an analyzer in the middle that records everything and allows analysis later, think Wireshark or Fiddler.
- AlphaWeaver 7y agoFor people unfamiliar with this strategy, check out a commercialized version, the USB Rubber Ducky. https://shop.hak5.org/products/usb-rubber-ducky-deluxe https://shop.hak5.org/products/usb-rubber-ducky-deluxe
- _rs 7y agoAre there any open-source or commercial systems that do anything close to this? Does there exist such a forensically sound OS that should be used? The best I've found for disk imaging is using Windows Enterprise (or similar, stripped down) with SafeBlock, but that seems less than ideal. I'd love to find a *nix alternative.
- mitchellgoffpc 7y agoNo one, ESPECIALLY the Secret Service, should randomly plug in a strange USB stick.
- siwatanejo 7y agoThat should have been the correct title indeed. I was confused for a minute.
- deleted 7y ago[deleted]
- skywhopper 7y agoit immediately began to install files, a “very out-of-the-ordinary” event that he had never seen happen before during this kind of analysis. The agent had to immediately stop the analysis to halt any further corruption of his computer This makes it sound like plugging USB sticks guests are carrying into a computer is standard procedure for the Secret Service. That might make sense if they have some sandboxed computer designed for this purpose, as suggested by other commenters. But then the rest of the quote makes it sound like the agents were unprepared for files to be copied and they panicked and aborted the "analysis" to prevent "corruption". Which makes it sound like, no, they just plug it into their own computers...
- bdamm 7y agoThe Secret Service as an organization has sophisticated cyber capabilities. That a specific agent within the president's detail didn't is less surprising. Still, I'd expect more from the organization, and I bet that the specific agents involved are getting disciplined and trained.
- lvs 7y agoWell, the head of USSS was fired today. Unclear if it's related.
- untog 7y agoHe was also fired after the Secret Service criticised security at Mar a Lago, so we've got a few candidates to choose from in working out the real reason.
- swamp40 7y agoThe Secret Service reports to DHS. Mr. Alles was an ally of Ms. Nielsen, who just resigned/got the boot. Stephen Miller reportedly got the go-ahead to clean house at DHS, so all the leadership that isn't in line will get cleared out.
- sehugg 7y ago
- Havoc 7y agoMeanwhile even the shittiest hollywood plotline has "we'll infect their systems with this virus - infiltrate and plug it into their servers" narrative. I know secretive service agent =/= computer expert but jesus...both my little sister and 60 year old mother know better.
- deleted 7y ago[deleted]
- deleted 7y ago[deleted]
- elagost 7y agoSimilar concerns should be made for Thunderbolt devices, which have direct PCIe access - much more low-level and dangerous than USB could be. The only system I've seen implement this is Gnome3 - it has a section in its system preferences for configuring Thunderbolt devices[0] and the Bolt daemon.[1] [0] https://wiki.gnome.org/Design/Whiteboards/ThunderboltAccess https://wiki.gnome.org/Design/Whiteboards/ThunderboltAccess [1] https://www.phoronix.com/scan.php?page=news_item&px=Bolt-Project-Thunderbolt-Secure https://www.phoronix.com/scan.php?page=news_item&px=Bolt-Pro...
- gruez 7y agoApparently windows has this too: https://www.startech.com/faq/thunderbolt-3-authentication-pop-up-messages https://www.startech.com/faq/thunderbolt-3-authentication-po.... Not sure whether that's the default behavior or how to enable it.
- verst 7y agoI have a mysterious USB stick I received as a thank you from a delegation of the Chinese department of Customs (中华人民共和国海关总署) after presenting to them in Palo Alto. The USB is branded with the Chinese Customs logo and their slogan. I haven't dared plugging this in. First and foremost I'm afraid it isn't standards compliant and will somehow fry my motherboard, secondly I don't have a burner device and the necessary knowledge to determine if anything suspicious is happening. So for now my USB stick and its decorative case in Chinese art style are purely for display.
- depressed 7y agoOn the "determine if anything suspicious is happening" front, you can configure Wireshark to capture USB packets and show you what is going over the wire.
- verst 7y agoOh nice! I've used Wireshark for TCP / UDP captures before but that's about it. Maybe I can use a raspberry pi as burner device and check it out.
- justwalt 7y agoThat sounds really interesting. You should post later if you go through with your plan!
- NikkiA 7y agoA pi zero would do the job and only risk about $5 to find out what's on the stick.
- ovi256 7y agoNice idea. Start a service where people mail unknown USB devices to you and you email back a disk image.
- pryce 7y agoGiven what happens to USB sticks in my household (needed fairly often), you may still be at risk of a family member opening it and using it should they need one in a pinch.
- Taniwha 7y agoThe thing that no one seems to point out is that just about any normal person carrying around a windows USB stick is likely to have malware on it. Just possessing a bad USB stick doesn't seem to be particularly incriminating by itself.
- ceejayoz 7y agoTrue, but there's a lot more going on here than "had a USB stick". > She was caught by the Secret Service with four cellphones, a laptop, cash, an external hard drive, a signals detector to spot hidden cameras, and a thumb drive.
- joering2 7y agoThat's exactly how I travel to tech-related summits around the world, and I have nothing to do with espionage I assure you. I have 3 cellphones - one private (family calls, face time etc), one CDMA phone and one separate GSM for the most of EU countries. And external SSD drive with all my important backups and projects that would take forever to download off of DropBox. And yes - recently even cheap signal detector, as I don't want to be watched in my hotel room, even only for "security reasons" as to whether I will demolish the room or not. (call me paranoid but so was I before Snowden files and I was proven right) I usually carry about $3,000 USD total in different currency - usually 20% AUD, 20% CAD, 30% USD and rest EUR/GBP. Trust me so many times paying with cash comes to be much cheaper, and at some occasions the only way to go! Yes, thumb drive too; usually empty so that if I am at the meeting and someone wants to send me some heavy files, I can give them my thumb and viola! If all this makes me a spy then I definitely need to change my profession :|
- ceejayoz 7y ago> That's exactly how I travel to tech-related summits around the world, and I have nothing to do with espionage I assure you. Do you typically sneak into these summits, telling the security staff a variety of lies to do so?
- 7y ago
- sandov 7y agoThis whole situation is absurd on so many levels.
- depressed 7y agoShouldn't preventing this be as easy as turning off autorun? In fact, I thought Windows had that off by default for USB devices. (Of course, I'm assuming we're not dealing with a zero-day in the USB stack or filesystem drivers. But that probably is something that the Secret Service should be on top of, as well.)
- analog31 7y agoGood question. As I understand it, the USB stick can present itself as a keyboard, which is automatically mounted, and begins entering a series of keystrokes that program the system to compromise itself. In essence, modern OS's give "autorun" privilege to keyboards and mice. That's the HID in this discussion -- Human Interface Device.
- depressed 7y agoAha, I missed that piece of the puzzle. Thank you.
- darkarmani 7y ago> this be as easy as turning off autorun What does autorun have to do with a mouse or keyboard device? The problem with USB is that you don't know if it is a "mass storage device" or any of the other kinds of devices that can start interfacing with your computer. If it is an (automated) keyboard device (HID), it will immediately start "typing" which means it can open a terminal window and start executing things.
- zzo38computer 7y agoYou can avoid software issues by proper configuration (I want to configure Linux not to automatically enable USB input devices). Of course hardware issues such as damaging the computer is different, but there may be another way to mitigate that. (For several reasons I also do not like the USB so much, though)
- gbrown 7y agoI hate it when colleagues and students hand me a USB stick to use. We have great file sharing infrastructure, there's no reason for me to plug in your USB stick to access some powerpoint you want me to look at. Now get off my lawn.
- deleted 7y ago[deleted]
- deleted 7y ago[deleted]
- runciblespoon 7y agoHa haa haaaa .. you can not be serious :] ‘Secret Service agent. Samuel Ivanovich, who interviewed Zhang Mar-a-Lago, testified at the hearing. He stated that when another agent put Zhang's thumb-drive into his computer, it immediately began to install files, a "very out-of-the-ordinary" event that he had never seen happen before during this kind of analysis. The agent had to immediately stop the analysis to halt any further corruption of his computer, Ivanovich said. The analysis is ongoing but still inconclusive, he testified.’
- gowld 7y agoThat's the new go-to for asking embarassing questions. "How do I fix my computer after I plug in a malware USB device? I meant, I didn't do that, I'm asking for a f-- another agent."
- ineedasername 7y agoThe article assumes (or at least implies) the secret service member was plugging it into his own personal laptop or something. Why? It may very well be a computer specifically setup to screen devices, including USB drives. It may be a sandboxed and sanitized environment. Or not, but we just don't know, and this article seems a little sensationalist in casting a negative light in the secret service absent details.
- eckza 7y agoIf it were set up for this purpose, they wouldn’t have ripped it out in a panic.
- ineedasername 7y agoIt sounds like they had a computer specifically configured for analysis of drives. I'm going to guess that's not just Agent Smith's normal computer he/she uses to write reports, email, etc. In which case, taking out the drive was an unnecessary reflex as the malware wouldn't get much traction on a system isolated from others and not used for much else. But I could also be wrong, I'm just speculating. Which is my point-- that's all the article was doing too, speculating.
- redleggedfrog 7y agoMan, good thing he was working from a virtual machine...
- aaron695 7y agoThis is the most ridiculous pile of rubbish I've ever read. Do we serious think every time the Secret Service comes across a person they should spend hundreds of thousands of $ forensically analysing all their electronics? This was a random person who was in a resort. Nothing more. You check them out, open their phone, check their usb, check their laptop and move on, or investigate further if they seem suspicious. The total lack of computer literacy here is amazing. Garbage like this is straight out of a hollywood movie "threatened his own computing system and possibly the rest of the Secret Service network." The Secret Service are human beings their kids will use their laptops, do we understand this as IT professionals? Or we living in gaga land of Hollywood? It's up to their experienced network IT staff to contain their network at differing levels and a laptop in the field should be considered compromised. Should they also have locked this lady down in a bio security suit in case she was carrying biological weapons? Is any other field as stupidly impractical as computer security 'experts'?
- netwanderer3 7y agoMany voting machines being used still have USB ports wide open. It's absolutely horrifying! I also don't like the new design of Macbook in which they merged the USB port and charging port into one. This really opens up huge security risks in my opinion.
- anonoholic 7y agoI was surprised from the get-go that no-one seem to be talking about the legality of an ad-hoc search of a USB thumb-drive. The stupidity of it (from an infosec standpoint) should be a given, yet this aspect appears to be the focus of the debate. Am I missing something?
- csours 7y agoThe Secret Service is charged with securing any Presidential residence, so I'm sure there are statutes that let them do that. Totally aside from that, all of Florida is in the 100 mile civil rights suspension zone: https://www.aclu.org/other/constitution-100-mile-border-zone https://www.aclu.org/other/constitution-100-mile-border-zone
- salgernon 7y agoFor all the complaining about usb devices, the agent behaved recklessly in trying to handle the device. If the person of interest had instead been carrying a quantity of unlabeled pills, the agent would be as wrong to gulp them down. I would think the secret service would have a policy in place for handling unknown media already, and I’m sure a Very Urgent Memo is wending it’s way from division headquarters as we speak.
- ct520 7y agoJust another Chinese national looking to steal secrets nothing to see here folks. And down ranks in 3-2-1
- _bxg1 7y ago[gets apprehended by Secret Service] "And what do we have here?" [holds up thumb drive] "That? Uhh, that's, my secrets! Don't look at my secrets! Please don't plug them into your Microsoft Windows® computer!"
- NoPicklez 7y agoNo one, especially the Secret Service should randomly plug in a strange USB stick. It blows my mind that someone from the secret service wasn't informed that they shouldn't plug evidence from a suspected spy into their laptops.
- adrianmonk 7y ago"Not even", TechCrunch? I think the word you're looking for is "especially".
- fulafel 7y agoIsn't the whole premise of the discussion jilted? This is a security person doing forensics on the USB stick. Why should he not examine it (if lawful) and why would you call this "random"?
- deleted 7y ago[deleted]
- Mikho 7y agoRemember reading a story about Russian agents organizing for USB sticks with spyware were sold in every kiosk selling gadgets around a US military base.
- bubblewrap 7y agoLast time I found a memory stick on the street, in the end I tested it with of these "print your own photos" machines in a drug store. I hope they had good security :-/ (stick was unreadable).
- dTal 7y ago>it immediately began to install files, a “very out-of-the-ordinary” event that he had never seen happen before during this kind of analysis. The agent had to immediately stop the analysis to halt any further corruption of his computer I've seen some versions of Windows present a conspicuous file copy dialog box when it sees a new flash drive plugged in (or even the same flash drive plugged in to a new port) - some song and dance about copying *.INF driver files. On the other hand I would expect a malicious flash drive to be as silent as possible. What are the odds the agent was just misinterpreting this?
- deleted 7y ago[deleted]
- rootlocus 7y ago> “It’s entirely possible that the sensitivities over determining whether Zhang was targeting Mar-a-Lago or the president — or whether she was a legitimate guest or member — may have contributed to the agent’s actions on the ground,” Plot twist: she was a legitimate member with a personal malware ridden usb stick she wasn't aware was infected. /joke
- fghtr 7y agoQubes OS has a defense agains USB attacks. It just reads the USB stick inside a dedicated VM and then, if necessary you attach it to another VM.
- grifball 7y agocan't ctrlf on my phone, but I didn't see usbfilter yet https://davejingtian.org/2016/08/04/making-usb-great-again-with-usbfilter-a-usb-layer-firewall-in-the-linux-kernel/ https://davejingtian.org/2016/08/04/making-usb-great-again-w... might take some advanced tech skills to install, but this is the only way to be theoretically secure against the most powerful attack vector of these types of attacks, which is to act as an HID and input malware into the computer. basically, you flag a physical USB port as being data-storage-only and your os will prevent any device being plugged into that port as being recognized as a mouse or keyboard or any other powerful USB device.
- Communitivity 7y agoI think it's important to note that I always consider even a USB stick fresh out of the packaging to be a 'strange USB stick', because I've seen cases of USB sticks being infected at the factory.