7 ms·
$2.7mm in damages over 6 malware infected parts. That escalated quickly. Where do they get the rationale for the Mice and Keyboards?!
by anujabro 13y ago
$2.7mm in damages over 6 malware infected parts. That escalated quickly.
Where do they get the rationale for the Mice and Keyboards?!
- stfu 13y agoIt is probably just because these are things that get touched by humans so there is a high risk that the virus might jump over and spread ...!
- Groxx 13y agoThe dreaded Trackball Mouse Flu, ready to run rampant now that all the birds caught the flu from us! Only laser mice can save us now!
- binarycrusader 13y agoIf they were programmable keyboards / mice, or they were suspected to be counterfeit or other surreptitiously modified parts, I might understand.
- mindcrime 13y agoRight, if it's a mouse that came from the OEM manufacturer and you know it is truly original, it's probably safe. But if there's any way that an outsider could have snuck a loaded mouse into your environment, then the mouse can certainly be setup to attack your system. See note above about The Glitch.
- mindcrime 13y agoIt's low probability but a mouse can absolutely be an attack vector. See: http://www.kickstarter.com/projects/1186217328/the-glitch http://www.kickstarter.com/projects/1186217328/the-glitch
- yen223 13y agoA paranoid, incompetent IT team plus an opportunistic "cybersecurity" contractor.
- patio11 13y agoIf the brief for the contract includes "We believe we may have been compromised by a nation state. Check for us." then checking keyboards and mice is totally reasonable. Some of them incorporate user-upgradable firmware. Given this, turning the keyboard/mouse into an "advanced persistent threat" is an exercise trivially within the capability of garden-variety security consultants. (Ballpark cost: $20k if you get everything scratchbuilt the first time, assuming you've separately rooted one machine to infect the peripheral.) Nation states can be presumed to have access to garden-variety security consultants, and more elaborate tricks besides.
- rmc 13y agoA lot of threat models that the USA defends against are perfectly legitimate, because the USA has used them against opponents in the past! e.g. US military and embassies always fly in new equipment from the USA, rather than buying local. Why? Because in the cold war, the Soviets got a local photocopier and local repairmen. The USA had a camera in it and the repairman was a spy. These aren't theoretical attacks to the USA.
- mechanical_fish 13y agoYes, even I fell for the "but it's only a stupid mouse!" spin on this story, and I've been shopping for embedded processors recently so you'd think I would know better. If it has a USB port, it contains a tiny computer. One which is probably more powerful than the Commodore PET I learned computing with. Not that you need that much power to log keystrokes. Those of us who were brought up in the 20th century can no longer trust our intuition about where computers might be hiding.
- mattmanser 13y agoIn the article it comes across like the contractor was constantly saying 'no, it's all ok'. It seems to say that he took 2 weeks to do the initial audit and then they got him to do some sort of detailed review of every machine which took months. To which he also then said there was nothing really wrong. To me it sounds like he just did his job while some crazy, incredibly incompetent CIO kept asking for more.