Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Is it still true that USB devices can be used to execute code on a target's system without user interaction?

I thought this behavior disappeared ~10 years ago.



They shouldn't be able to. Firewire devices can because they used DMA without memory protection. I don't think Thunderbolt has the same flaw.

However there are bugs in USB stacks, especially now you can do so many alternate protocols over USB-C.

https://www.jefftk.com/p/malicious-usb-sticks

There's nothing fundamental in the USB spec that lets devices execute code on the host.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: