Wired: Wickedly Clever USB Stick Installs a Backdoor on Locked PCs

Ugh. Raspberry Pi Zeroes can be used for very scary things. “Today [Samy] Kamkar released the schematics and code for a proof-of-concept device he calls PoisonTap: a tiny USB dongle that, whether plugged into a locked or unlocked PC, installs a set of web-based backdoors that in many cases allow an attacker to gain access to the victim’s online accounts, corporate intranet sites, or even their router. Instead of exploiting any glaring security flaw in a single piece of software, PoisonTap pulls off its attack through a series of more subtle design issues that are present in virtually every operating system and web browser, making the attack that much harder to protect against.”

%d bloggers like this: