Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

If power is all you are looking for you can always play it safe with a USB Condom.

e.g https://www.amazon.com.au/s?k=PortaPow



Keep in mind that this will limit you to 5V at 0.5A, if I'm not mistaken.


And realize that if you're distrustful of the cable, you should be even more distrustful of that gadget which has even more space to add malicious parts and you're still unable to check it.


https://mg.lol/blog/data-blocker-teardown/

The normal PortaPow tells the device that it's a charger.

The extra paranoid version with no components on the board will often limit charging, it depends on how the device treats a complete lack of data pins.


Yes, but if you use a data blocker with a microcontroller on it, you've just exchanged one company you need to trust for another.


Not exactly. You now have to trust one entity instead of many, and it's an extremely small chip that can't do much, and the hack would have to be built in at purchase time, and the hack would have to take over your phone to exfiltrate.

But if you're worried then get one that has a resistor and only a resistor.


Aren't all these considerations exactly the same as for the cable with the screen?


It depends on what kind of attack you're trying to block.

If you want to block attacks that use the external data pins, then a USB condom will keep you safe. Regardless of whether it has a chip in it.

If you want to block standalone attacks from a malicious cable, then a USB condom wasn't going to help in the first place. For standalone attacks in particular, the risk from a chip-having condom is similar to the risk from a cable, but a cable can use bigger and scarier chips than the one in the PortaPow.


Assuming you trust that device to not be malicious. It's turtles all the way down.


Minimal Portapow for visual verification, https://www.amazon.com/PortaPow-Pure-USB-Data-Blocker/dp/B07...

  Transparent casing, no-chip design and custom made USB connector with data pins visibly removed means you can be sure the blocker is secure.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: