Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Or shut down when any USB device is attached while the phone is locked/inactive?

It'd work like this: Unlock phone, plug in USB widget; it works.

Or: Plug in USB widget without first unlocking phone; phone shuts down.

 help



That's a great option.

I just wonder whether that could be too annoying for Android Auto / Car Play. But to be fair wireless is an option.

The other downside I guess is that a thief would just plug a USB drive in to disable device tracking. But they could just wrap the damn thing in foil so dunno if that should matter.


It's either that, or maintain a database of trusted USB devices...which seems iffy, at best.

And by that I mean, using the database itself is simple. But when it exists, then a list of targets for an attacker to emulate also exists.

Those boys at Cellebrite aren't dummies, at all, and they've been doing this stuff for quite a long time. They're a formidable opponent.

We used to use their kit to clone personal data between very different devices back in the dumb phone days. They were the only ones to get it right out of a sea of others that were also evaluated.


I should mention: Cellebrite's methods would tend to walk completely around whatever the phone thought was a normal, good idea.

When the usual manufacturer-prescribed method for reading contacts said to take some long-winded steps to put the phone into a special mode, Cellebrite's hardware just usually skipped that shit and read the data very directly without any fuss.

Plug it in, push the button, and the Cellebrite box just did the appropriate magic. It then interpreted the data and munged it into a useful form to shove into the next phone.

After that: The recovered personal data was pushed right up into the ass of the next phone with the same lack of consent. It was succinct and brutal in operation.

And: It worked. It was so dead-nuts simple that a cell phone salesperson could run it with ease. I stopped getting phone calls from the field about transfer problems when we started using Cellebrite kit.

Nothing else did this stuff with that measure of resolute nonchalance.

So at this point they've been uniquely hooning with cell phones for decades. It's kind of their schtick.

If we can speculate that something like the the USB-C charge rate negotiation on a given phone can open a pathway into the system, then it can be safe to say that Cellebrite is already using that method to get things done -- and that a person at the border can exploit it even if they're "not a tech person".

Simplifying these kinds of hacks is what they do.


> And by that I mean, using the database itself is simple. But when it exists, then a list of targets for an attacker to emulate also exists.

Recognize USB devices by serial numbers, not the manufacturer ID. Even if they could get their hands on the serial number of my car stereo, that's going to be after the same warrant delay this thing protects against.


The car stereo that's in the car parked just outside the airport, in the long-term lot, which is conveniently within 100 miles of a border crossing?

The lot they tracked you going into? The lot that gets scanned by mobile ALPRs on the regular?

Yeah, so. About that... :-/




Consider applying for YC's Winter 2027 batch! Applications are open till November 2.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: