Forgot your password?
typodupeerror
Cellphones Handhelds Power Security

Jailbroken Devices Compromised By Charging Stations 93

Posted by Soulskill
from the charged-with-computer-fraud dept.
mask.of.sanity writes "Data can be stolen from Windows, Android and Apple devices by unassuming power charging towers. In an attack demonstrated at the Defcon hacking conference, mobile phone charging units were rigged to pull data from phones plugged into them. Researchers found many jailbroken and modified devices activated USB functions when they were plugged in, or simply rebooted."
This discussion has been archived. No new comments can be posted.

Jailbroken Devices Compromised By Charging Stations

Comments Filter:
  • by mpoulton (689851) on Saturday August 20, 2011 @03:20PM (#37156160)
    I flew on Air Canada a few weeks ago and they had USB ports for charging integrated into the seatback touchscreen displays. When I plugged my phone (HTC Incredible running CM7 nightlies) into it with a USB data cable, it indicated a valid data connection to a host controller! I was surprised and thought the seatback device probably contained a small PC to handle the interactive display. I tried to poke around on the host device to see what I could find, but didn't get anywhere with it. For some reason it didn't even occur to me that the "poking around" could be going the other way. If someone could compromise those seatback devices, the phone contents of thousands of passengers could be automatically collected...
  • Re:Duh (Score:5, Informative)

    by Miamicanes (730264) on Saturday August 20, 2011 @03:56PM (#37156382)

    What you need is a USB CondomCable with the D+ and D- pins shorted together. No data can flow, and if the bad guys didn't bother to try and implement proper power protocol, you'll get the added satisfaction of frying THEIR hardware when your phone cranks up the juice and tries to suck down 1.7A instead of politely sipping 100mA. Just don't ever use such a cable by mistake to connect your phone to a pc or laptop belonging to yourself or a friend.

  • by Anonymous Coward on Saturday August 20, 2011 @04:10PM (#37156468)

    AC Chargers that can supply up to 1000ma short the two data pins together to tell the phone it can draw that high amount of current.
    USB devices connected to a controller are only allowed to draw 500ma, and only after negotiation with the host.
    A USB connected to a port where the data pins are not shorted AND cannot negotiate a higher current with the host is only allowed to draw 100ma.

    So removing the data pins from a USB port will prolong charge duration 5x or 10x

  • Re:Duh (Score:4, Informative)

    by Kookus (653170) on Saturday August 20, 2011 @04:44PM (#37156694) Journal

    I don't think he meant that the d+/- lines were what fries the host, he was indicating that the phone wouldn't think it's connected to a computer and it would draw higher amps because it thinks it's hooked up to just a charger. So if the host didn't limit amps and it's wires weren't rated for 1.7A, then it would result in them overheating and hopefully damaging something.
    The whole purpose was to make a connector that actually works, not something to destroy the host. The ancillary prize was damaging hosts if they were advertised as just a charger and they really weren't.

  • Told you so (Score:4, Informative)

    by Animats (122034) on Saturday August 20, 2011 @05:31PM (#37156932) Homepage

    Told you so on February 6, 2009. [slashdot.org]

    Back in 2009, it was just a Windows autorun problem. Since then, Google and Apple have been able to screw up in the same way.

    Coming soon, I suppose, attacks on appliances via "smart meter" data links. Not everything should have a data link.

The most exciting phrase to hear in science, the one that heralds new discoveries, is not "Eureka!" (I found it!) but "That's funny ..." -- Isaac Asimov

Working...