DATA DOCTORS

Beware of rogue USB devices!

Oct 9, 2014, 2:44 AM | Updated: 2:44 am

What can you tell me about the new USB drive exploit that I’m hearing about?

The ubiquitous USB drive has always been a potential threat to any computer that it plugs into, as malware can live on it just as easily as it can on a hard drive.

What makes the most recent news disconcerting is that an attack being called BadUSB is both undetectable and relatively unpatchable, meaning there is no easy way to fix it.

Traditional security scans, such as an anti-virus program are completely useless against this threat because the infection is in the device itself, not the storage area.

The original security researcher that demonstrated the attack at this year’s Black Hat security conference chose not to release the code to give USB manufacturers some time to come up with a fix.

This fix would require manufacturers to fundamentally change how they create devices, which would likely take a while.

A couple of other researchers felt that without extreme pressure on the manufacturers, most of which focus on creating the cheapest devices possible, nothing would happen, so they chose to reverse-engineer the firmware exploit to reproduce the hack and publish the code for anyone to use.

“If this is going to get fixed, it needs to be more than just a talk at Black Hat” the researchers told WIRED magazine.

They are also working on a method that could allow an infected USB device to infect a computer, which would, in turn, infect any future devices that are plugged in, making this exploit really dangerous.

For anyone that lived in the floppy disk era, this is akin to all of the boot-sector infections, such as the infamous Michelangelo Virus, that spread from machine-to-machine as users went about their normal business.

Most people that use USB flash drives don’t really think about them as anything more than a storage device, but they are completely capable of being programmed to wreak havoc.

This particular exploit would allow a hacker to plant virtually any instructions they wanted on the device itself that would automatically run when it gets plugged in.

Since this is a fluid situation, here are some tips for reducing your chances of unknowingly becoming a victim:

• Avoid plugging any USB drive into your computer that you don’t personally own. This means friends, associates or anyone else that might want to transfer files to your computer via USB drive should be encouraged to use Google Drive, Dropbox or other cloud-based file-sharing services.

• If you are a business, you should immediately instruct all employees that no USB drives are to be plugged into any computer without prior approval. This may seem a little over the top, but since the code has now been made public, working with trusted drives only is the only safe procedure.

• DO NOT use any USB flash drive that looks like it was lost by someone else. If you think like a hacker for a minute, the easiest way to start infecting people is drop infected USB drives around college campuses and large businesses. Most people will think that they have found a free storage device and have no way of knowing that it’s infected.

• Stick to using USB devices that you purchased as new and have never left your possession.

This is a fluid situation, so stay tuned for more information as it becomes available.

Data Doctors

Many of the fake videos you’ll encounter are likely to be viewed on your smartphone, which can ma...

Data Doctors

Here are all the tips we know regarding how to spot deep fake videos

Many of the fake videos you’ll encounter are likely to be viewed on your smartphone, which can make detection a bit more difficult.

4 days ago

Patrick Mahomes #15 and head coach Andy Reid of the Kansas City Chiefs are recorded on a phone as t...

Data Doctors

Handy tech tips all Valley residents should use to find lost phones in a snap

Q: My phone went missing, and I haven’t been able to locate it using the Find My service, so what should I do next?

11 days ago

(Pexels Photo)...

Ken Colburn, Data Doctors

Here are tips for freeing up Google storage space

Google provides a generous amount of free online storage but it can fill up quickly depending on how many of its resources you use.

18 days ago

Discover how to assess, estimate, and shop for the right battery pack with this concise guide. (Pex...

Data Doctors

Here is everything you need to know for testing and buying battery banks

Discover how to assess, estimate and shop for the right battery pack with this concise guide.

25 days ago

(Pexels Photo)...

Ken Colburn, Data Doctors

Here are the truly free smartphone video editing apps

The processing power on our smartphones has grown exponentially, allowing anyone to perform sophisticated video editing easily.

1 month ago

Google Maps app....

Data Doctors

How to rediscover places visited years ago on Google maps

Whether you're an Android or iOS user, or prefer accessing Google Maps on your computer, you'll find step-by-step instructions to unlock your travel memories effortlessly.

1 month ago

Sponsored Articles

...

Condor Airlines

Condor Airlines can get you smoothly from Phoenix to Frankfurt on new A330-900neo airplane

Adventure Awaits! And there's no better way to experience the vacation of your dreams than traveling with Condor Airlines.

...

COLLINS COMFORT MASTERS

Here are 5 things Arizona residents need to know about their HVAC system

It's warming back up in the Valley, which means it's time to think about your air conditioning system's preparedness for summer.

...

Collins Comfort Masters

Avoid a potential emergency and get your home’s heating and furnace safety checked

With the weather getting colder throughout the Valley, the best time to make sure your heating is all up to date is now. 

Beware of rogue USB devices!