Monday, July 05, 2010

Stealing information via USB devices

I know it had been known for a long time. But does anyone cares? You should. That innocent looking China-made hello kitty cup warmer or the free thumbdrive from some company in Blackhat. Are they really as innocent as they look? How can you be sure that those are not just means to obtain information by other entities?

In short, devices can "mimic" any other devices by coding in the ID into ttheir chip while in fact they are totally not that device and can be performing other functions such as storing keystrokes or send out files to nearby wifi devices etc. Its all up to the maker to create.

