Someone Is Putting Malicious USB Sticks in Australian Mailboxes: “The USB drives are believed to be extremely harmful and members of the public are urged to avoid plugging them into their computers or other devices,” the announcement from the Victoria Police reads.

Oh, I'm so sorry. My mistake. I guess it's only ok to to not refute what someone says and attack them directly if you're the one doing it. Truly your hypocrisy is boundless. How incredibly narrow minded are you where you think that just because you presumably have some cursory knowledge of the usb protocol that you can speak to the impossibility of doing something that has actually been proven to be possible on many many occasions over the years just because your idea of attacking a system is limited to going after the communication protocol itself rather than the systems that use it. Breaking the front door is never the easiest or best way to get in somewhere and only a fool would attempt to do so outside of academic exercises.

Seriously, what kind of half assed security 101 articles did you skim through and limit yourself to such that you would assume thumbdrives are safe just because the usb specification isn't completely worthless? Beyond the fact that there are implementations of metadata exploits that will own a system as soon as an indexer crawls the contents there are also firmware exploit avenues that will happily bypass any standard desktop os security settings, such as emulating input devices to enter commands on the host or injecting payloads into files put on the drive so that it will initially appear clean and only after someone starts using it do they get owned or even go on to inadvertently infect other machines they transfer files to.

There's a reason why every company that takes information security seriously will set policies to disable everything except hid for usb or in some cases even that and why if you look in the bios/uefi settings for thinkpads and other business oriented laptops you will find options to disable usb ports. Here's a hint: It's not because they're as uninformed and dangerously arrogant as you or because they were bored did it for shits and giggles.

Now stop projecting, and more importantly stop making an ass of yourself when you have no idea what you are talking about. Or hey, keep doing what you're doing and learn the hard way just how wrong you are. I just hope you don't cause too much collateral damage to whoever was unfortunate enough to hire you.

/r/worldnews Thread Parent Link - motherboard.vice.com