The Most Important Factor in Security

I am going to drop a video, here. This is Adam Savage on "Tested!" talking about some very scary devices that are used for remote monitoring, "hacking" and data or identity theft.
They demonstrate simple USB Cables and even a USB Keyboard, that contain their own wifi transmitter and keylogger. One of the USB Cables includes keyboard operations in code (Not physically), allowing it to send HID commands from a remote user.

Tested! Discusses Access Devices

One thing that is demonstrated in this video, is how ordinary and innocuous this device is and how frightening it is to consider how easily a nefarious actor could gain access to your most sensitive data.
Security is something all computer users must manage but that most know very little about.

And what I like so much about this particular video is that they openly discuss the Most Important Factor:

"Am I a target?" "Am I at risk?"

One of the examples they give is a Tesla employee being offered $500,000 to plug in a USB monitoring device within the Tesla company.
That the remote operator must be following in a vehicle, within range.

There is a broader truth here: All of the hardening on Ubuntu, all of the changes lately in Grub, all of the security measures touted across the board: Not one bit of it is effective against strategies and devices like this. As long as there is human interface; there is an opening.
Sound scary?
You are a not a target. Is what is on your computer worth a few million dollars?
Half a million?
Humans in general like to assign themselves greater importance than they have. A more elevated place of Special; Above Average.
We are already predisposed to think we are some kind of target; before some scary exploit is found.

And this is exploited by companies more than hackers sitting in dark smoke filled rooms.
"Military Grade."
"Clinically Tested"
"Premium"
Marketing is all about telling you what you want or need, then dropping the implication, without making a claim that needs to be supported.
And I can fathom how advertisers in a meeting might cover these basics. But developers and software engineers?
Security has become the latest buzzword in GnuLinux and is being used to Exploit the End Users into sacrificing their ownership and their control over their own computers.
Over nebulous claims of if's and maybe's that suggest that we are targets even when we simply are not.
Do you need to key a badge to access parts of your home? Do you have security personnel at the front door doing bag checks?

9 Likes

*personnel. :wink:

1 Like

Thank you for this post, @Aravisian , I've found it to be a useful refresher. I think everyone should ask themselves: “am I at risk?”, to what degree and which vectors are points to contemplate. The answers are going to be different, depending on where you live and what you do in your daily life.

The very last time I was in a physical classroom, doing cover lessons for a sick teacher, a student asked me if I had a phone charger as his phone was running out of battery. The wall charger that had been in the socket last time I looked had gone. I had the cable I use to charge my Bluetooth keyboard, so I took his phone and plugged it into my laptop so it would charge.

I didn’t know the student. All I know is that he is 18 and recently passed his motorbike test and got a new motorbike. I also think he has ADD, or similar. He’s highly intelligent but struggles to focus, and needs constant stimulation to prevent him subverting the class, and to make sure he learns something useful. He could have been a drug addict, up to his neck in blackmail and in need of a fix. Fortunately, I don't think he was.

Where I live there are Chinese hypermarkets on almost every-other corner. They’re piled high with millions of Euros worth of stock, the owners are usually very young, up to their eyeballs in debt, and tied into Chinese mafia. Don’t believe me, do some research into it, you’ll be shocked!

Drugs, counterfeit goods and gambling. How do I know my student hasn’t been hooked up? It isn’t known as “the state within a state” for nothing! Here is one small example:

Anyway, I did a silly thing. I should have thought first. As the cable I used was my own there was less risk but… …. From people having their cards cloned with “shimming devices”, to SMS, WhatsApp and email-dangerous links, to cold calls from “your bank”, eBay or PayPal, it is safer to assume that everyone is out to get you and part you from your hard earned money.

I really wanted to get a full time position off the back of that temporary cover work, so I was careless. Not just with the cable either. The WiFi router is at waist-height, right next to the open main door. When I had trouble connecting to the WiFi, the students from that class knew all about how to play around with it to try and get my laptop to connect. It was Windows security that prevented that, determining that the router wasn't up to date with security and just pont blank refused the "handshake" to connect. That was my last day. :woman_shrugging:

We are all vulnerable, we're all worth something to some crook. Be aware and be careful. Keep up to date with what is happening out there, because scammers and criminals are just waiting to expliot us.

1 Like

See, there must be clarity between a Scammer and a hacker.

We have all gotten emails claiming to be heirs to some deceased princes estate.
That is not a hacker - nor are You a target.
That is General Phishing looking for a bite.

A bit of fearmongering and paranoia is far better for business that wants to part you from your hard earned money than it is for scammers.

Scammers might call random phone numbers, send out blanket emails; They lack the means, the resources or the know-how to do Hacking.

Knowing you may get caught in a net from a Scammer is not the same as being wary of Hackers.
But if companies can ride on the already present human need to believe we are special; they can make Legitimate Profits off of anyone. The problem is: Scammers are Not Hackers. And So, there is very little security that can be applied to Scammers outside of the user showing Common Sense.