USB Technology Has a Fundamental Security Vulnerability

Future Tense
The Citizen's Guide to the Future
July 31 2014 4:07 PM

USB Technology Has a Fundamental Security Vulnerability

usb
Wipe the flash memory all you want, it won't help with the real problem.

Image from Shutterstock/Ensuper.

Flash drives and USB peripherals—that is, basically every gadget—could be carrying malware without any evidence in their flash memory. According to new research that will be presented next week at the Black Hat security conference, it is possible to hide malware deep within USB technology at the firmware level. Oh, great.

Lily Hay Newman Lily Hay Newman

Lily Hay Newman is lead blogger for Future Tense.

Wired, which first reported on the findings, says that researchers Karsten Nohl and Jakob Lell from the security firm SR Labs can take over and control a PC with the BadUSB malware they developed to lurk in the base-level software that mediates between hardware and higher-level software like an operating system. They’re white hat hackers, trying to find and exploit security flaws as a proof of concept and a way of motivating the tech community to develop fixes.

Advertisement

Wiping a flash drive or scanning it with anti-virus software won’t detect the malware. Only reverse-engineering the firmware the way Nohl and Lell did can expose the foreign code lurking in it, and few consumers have the know-how to do that. Plus, even if you could do that, it might be hard to identify the malware code as malicious, because USB firmware varies and there isn’t a single standard to compare to.

So with BadUSB, or something like it, safely in place, the malware can do pretty much anything, like controlling a keyboard to type commands, leaving backdoors in software, or surveiling Internet use on a device. University of Pennsylvania computer science professor Matt Blaze also told Wired that he suspects the NSA has already developed attacks like this. “I wouldn’t be surprised if some of the things [Nohl and Lell] discovered are what we heard about in the NSA catalogue,” he said referring to Cottonmouth, an NSA malware distribution program that uses USB drives.

There’s no patch for this problem, so the best way to defend yourself for now is to think about how you protect yourself from getting sick and apply the same approach to your computer. Don’t share your thumb drives, don’t plug them into a public or untrusted computer, and don’t plug a USB peripheral or thumb drive that isn’t yours into your computer. It’s difficult to do, because we all use USB technology for easy sharing, but hopefully it’ll just be a stopgap measure while researchers work on long-term fixes. For example, USB firmware could have a signature that indicates if the original code has been tampered with or changed. And companies working on anti-virus for peripherals—like Red Balloon Security, which Slate reported on earlier this year—should be able to detect the changes.

Or what about USB condoms?! For now, you’ll have to practice safe sharing.

Future Tense is a partnership of SlateNew America, and Arizona State University.

TODAY IN SLATE

Politics

The Irritating Confidante

John Dickerson on Ben Bradlee’s fascinating relationship with John F. Kennedy.

My Father Invented Social Networking at a Girls’ Reform School in the 1930s

Renée Zellweger’s New Face Is Too Real

Sleater-Kinney Was Once America’s Best Rock Band

Can it be again?

The All The President’s Men Scene That Captured Ben Bradlee

Medical Examiner

Is It Better to Be a Hero Like Batman?

Or an altruist like Bruce Wayne?

Technology

Driving in Circles

The autonomous Google car may never actually happen.

The World’s Human Rights Violators Are Signatories on the World’s Human Rights Treaties

How Punctual Are Germans?

  News & Politics
Politics
Oct. 22 2014 12:44 AM We Need More Ben Bradlees His relationship with John F. Kennedy shows what’s missing from today’s Washington journalism.
  Business
Moneybox
Oct. 21 2014 5:57 PM Soda and Fries Have Lost Their Charm for Both Consumers and Investors
  Life
The Vault
Oct. 21 2014 2:23 PM A Data-Packed Map of American Immigration in 1903
  Double X
The XX Factor
Oct. 21 2014 3:03 PM Renée Zellweger’s New Face Is Too Real
  Slate Plus
Behind the Scenes
Oct. 21 2014 1:02 PM Where Are Slate Plus Members From? This Weird Cartogram Explains. A weird-looking cartogram of Slate Plus memberships by state.
  Arts
Brow Beat
Oct. 21 2014 9:42 PM The All The President’s Men Scene That Perfectly Captured Ben Bradlee’s Genius
  Technology
Technology
Oct. 21 2014 11:44 PM Driving in Circles The autonomous Google car may never actually happen.
  Health & Science
Climate Desk
Oct. 21 2014 11:53 AM Taking Research for Granted Texas Republican Lamar Smith continues his crusade against independence in science.
  Sports
Sports Nut
Oct. 20 2014 5:09 PM Keepaway, on Three. Ready—Break! On his record-breaking touchdown pass, Peyton Manning couldn’t even leave the celebration to chance.