USB Technology Has a Fundamental Security Vulnerability

The Citizen's Guide to the Future
July 31 2014 4:07 PM

USB Technology Has a Fundamental Security Vulnerability

usb
Wipe the flash memory all you want, it won't help with the real problem.

Image from Shutterstock/Ensuper.

Flash drives and USB peripherals—that is, basically every gadget—could be carrying malware without any evidence in their flash memory. According to new research that will be presented next week at the Black Hat security conference, it is possible to hide malware deep within USB technology at the firmware level. Oh, great.

Wired, which first reported on the findings, says that researchers Karsten Nohl and Jakob Lell from the security firm SR Labs can take over and control a PC with the BadUSB malware they developed to lurk in the base-level software that mediates between hardware and higher-level software like an operating system. They’re white hat hackers, trying to find and exploit security flaws as a proof of concept and a way of motivating the tech community to develop fixes.

Advertisement

Wiping a flash drive or scanning it with anti-virus software won’t detect the malware. Only reverse-engineering the firmware the way Nohl and Lell did can expose the foreign code lurking in it, and few consumers have the know-how to do that. Plus, even if you could do that, it might be hard to identify the malware code as malicious, because USB firmware varies and there isn’t a single standard to compare to.

So with BadUSB, or something like it, safely in place, the malware can do pretty much anything, like controlling a keyboard to type commands, leaving backdoors in software, or surveiling Internet use on a device. University of Pennsylvania computer science professor Matt Blaze also told Wired that he suspects the NSA has already developed attacks like this. “I wouldn’t be surprised if some of the things [Nohl and Lell] discovered are what we heard about in the NSA catalogue,” he said referring to Cottonmouth, an NSA malware distribution program that uses USB drives.

There’s no patch for this problem, so the best way to defend yourself for now is to think about how you protect yourself from getting sick and apply the same approach to your computer. Don’t share your thumb drives, don’t plug them into a public or untrusted computer, and don’t plug a USB peripheral or thumb drive that isn’t yours into your computer. It’s difficult to do, because we all use USB technology for easy sharing, but hopefully it’ll just be a stopgap measure while researchers work on long-term fixes. For example, USB firmware could have a signature that indicates if the original code has been tampered with or changed. And companies working on anti-virus for peripherals—like Red Balloon Security, which Slate reported on earlier this year—should be able to detect the changes.

Or what about USB condoms?! For now, you’ll have to practice safe sharing.

Future Tense is a partnership of SlateNew America, and Arizona State University.

Lily Hay Newman is lead blogger for Future Tense.

TODAY IN SLATE

Politics

The Democrats’ War at Home

How can the president’s party defend itself from the president’s foreign policy blunders?

Congress’ Public Shaming of the Secret Service Was Political Grandstanding at Its Best

Michigan’s Tradition of Football “Toughness” Needs to Go—Starting With Coach Hoke

Windows 8 Was So Bad That Microsoft Will Skip Straight to Windows 10

Homeland Is Good Again! For Now.

Politics

Cringing. Ducking. Mumbling.

How GOP candidates react whenever someone brings up reproductive rights or gay marriage.

Building a Better Workplace

You Deserve a Pre-cation

The smartest job perk you’ve never heard of.

The Ludicrous Claims Women Are Pitched at “Egg Freezing Parties”

Piper Kerman on Why She Dressed Like a Hitchcock Heroine for Her Prison Sentencing

Behold
Oct. 1 2014 11:48 AM An Up-Close Look at the U.S.–Mexico Border
  News & Politics
The World
Oct. 1 2014 12:20 PM Don’t Expect Hong Kong’s Protests to Spread to the Mainland
  Business
Business Insider
Oct. 1 2014 12:21 PM How One Entrepreneur Is Transforming Blood Testing
  Life
The Eye
Oct. 1 2014 1:04 PM An Architectural Crusade Against the Tyranny of Straight Lines
  Double X
The XX Factor
Oct. 1 2014 1:01 PM Can Activists Save Reyhaneh Jabbari?  
  Slate Plus
Behind the Scenes
Oct. 1 2014 10:54 AM “I Need a Pair of Pants That Won’t Bore Me to Death” Troy Patterson talks about looking sharp, flat-top fades, and being Slate’s Gentleman Scholar.
  Arts
Brow Beat
Oct. 1 2014 12:26 PM Where Do I Start With Leonard Cohen?
  Technology
Future Tense
Oct. 1 2014 11:48 AM Watch a Crowd Go Wild When Steve Jobs Moves a Laptop in This 1999 Demonstration of WiFi
  Health & Science
Bad Astronomy
Oct. 1 2014 12:01 PM Rocky Snow
  Sports
Sports Nut
Sept. 30 2014 5:54 PM Goodbye, Tough Guy It’s time for Michigan to fire its toughness-obsessed coach, Brady Hoke.