The USB Keyboard We're Never Allowed to Plug In

The USB Keyboard We're Never Allowed to Plug In

Adam Savage’s Tested

0:00 Hey everybody, Adam Savage here and today

0:02 in partnership with our friends at Threat Locker,

0:04 we are taking another look at malicious devices hiding in plain sight.

0:09 They have brought to the cave examples

0:11 of compromised hardware that they've encountered in the field

0:14 and we're going to get a look and a demonstration of how they actually work.

0:19 Last time we did a video,

0:21 we were talking about the threat vector of USB drives and just

0:25 how much nefarious stuff they can pack into such an innocuous thing.

0:30 But now you guys have come back with a different

0:31 threat vector that's even hiding more in plain sight.

0:35 Absolutely.

0:35 So we're going to talk about keyboards.

0:37 We're going to talk about cameras.

0:38 I'm going to use the OMG cable to make

0:41 that camera start recording you on a continuous loop.

0:44 So uh this is just a cable, isn't it?

0:47 This is a phone charger.

0:48 So,

0:49 this is a phone charger.

0:50 And how does this give you access to the camera?

0:53 So, so this here has a Wi-Fi antenna built into it.

0:56 Um, it has a keyboard built into it.

0:58 So, we can pretty much do anything on a computer

1:00 that this is plugged into as if we were at the computer.

1:03 It comes in different colors, shapes, sizes, can look like an iPhone cable.

1:06 It will actually charge your phone so it functions fully.

1:10 So bad actors can create a cable that looks completely innocuous but has

1:15 a working computer inside that only wants to compromise me and all my data.

1:20 Yes.

1:20 And it will charge your phone.

1:21 It will function.

1:22 So if they switch your phone cable, you would never know any difference.

1:25 I This is why I So I consider it a reasonable practice.

1:28 I never plug my phone into anybody else's charging cable.

1:31 Is that a good security?

1:33 That's a really good practice.

1:34 Just make sure you treat your phone cable like

1:37 it's sacred because if someone comes and just swaps it,

1:43 it actually works great for me because my phone cable is

1:44 Apple and it's white and it's filthy and you can only Yeah,

1:48 that's what you want to keep it really really dirty.

1:50 If suddenly your cable gets clean one day, throw it away.

1:53 Okay, so talk to me about how this threat vector works.

1:56 Okay, so this is basically a keyboard.

1:58 Looks like a regular keyboard branded.

2:00 They come in different models,

2:01 but when we plug this in, this essentially will log all keys.

2:05 And it has the same thing, a wireless antenna built into it.

2:07 So, oh, into the cable.

2:09 Into the cable or into the keyboard.

2:11 Yeah.

2:12 So, so once I plug this in, Kwan could connect

2:14 to this and capture my keystrokes from sitting outside the office.

2:19 Okay.

2:19 So, IT departments are famously cranky about you bringing in your own hardware.

2:24 This is the greatest argument they have about why that's bad.

2:27 Yeah, absolutely.

2:28 is that they you could bring a keyboard from home,

2:31 plug it in, and it could have hidden antenna built

2:33 into it that allows somebody to see all your keystrokes.

2:36 Or if you want to be a really sophisticated attacker,

2:38 and we think about most businesses,

2:40 the a sophisticated attacker isn't going to go mail them a $150 keyboard.

2:44 It's not that nice and hope they plug it in

2:46 and hope they plug it in.

2:47 However, when you think about someone who's trying to get into, say,

2:50 big companies like Tesla,

2:51 they're willing to do a lot more cuz the reward is much bigger.

2:54 And and there was a story where someone had offered

2:56 a Tesla employee $500,000 to plug in a USB device.

2:59 So if you think they're willing to offer that, just think how

3:02 hard it would be to intercept a delivery and switch the keyboard out.

3:07 Not that hard at all.

3:09 No.

3:09 If you're willing that one through if you

3:12 wanted to if you're willing to pay someone $500,000,

3:15 it doesn't seem like it's particularly

3:17 difficult to switch somebody's keyboard out.

3:18 And this will give you full visibility

3:21 of everything they're typing on their computer.

3:23 Can we watch that happen?

3:24 Can we watch this happen?

3:25 Okay, so we're going to plug this one in.

3:27 Oh my god, this is terrifying.

3:29 Well, you don't think of keyboards as that famous way into your data.

3:36 Okay.

3:36 And uh well, essentially what Kieran's going to do is he's

3:38 going to connect to this as if it's a Wi-Fi device.

3:42 So he can see this here.

3:43 So he could be the threat actor in another building next door.

3:46 Uh just taking a look at what this is telling him.

3:50 So we can see here.

3:50 So I I can say comes up.

3:58 No way.

3:59 Oh my gosh.

4:05 Um what possible protection is there against a device like this?

4:11 This it really comes back down to we have

4:13 to assume the user is going to be compromised.

4:15 So obviously normal protections are making sure you source

4:17 things and you know where it comes from but we

4:19 have to assume the device or the or the password

4:22 the thing the user knows is compromised.

4:24 So it comes back down to you have you knowing the password shouldn't be enough.

4:28 So if I logged into my if I logged

4:30 into my Office 365 account from here right now.

4:32 Yeah.

4:34 Um

4:34 K would have my password.

4:35 He would not be able to get into my account from anywhere

4:38 else in the world because he wouldn't have one of my devices.

4:41 And that it comes back down to zero trust.

4:43 to make sure we're validating the computer

4:44 and the phone because there are always

4:46 going to be ways that the user will give you their password, their credentials.

4:50 Maybe through chipping you a keyboard,

4:52 but maybe just calling you and saying, "You're in the IT department.

4:54 Can I get your password?"

4:55 So, this is the polar opposite of security through obscurity where

4:58 you just hope that you're not very interesting to a bad actor.

5:01 This is making the assumption that every device you're going to plug

5:05 in is somehow going to compromise you and working around that with permissions.

5:10 Absolutely.

5:10 every every device, every piece of software you run,

5:13 whether you download a game, whether you're running Zoom.

5:14 I mean, think about all of the cyber attacks we've seen with common software,

5:18 Microsoft Office, Exchange, Solar Winds, uh Zoom,

5:20 all of these have had massive vulnerabilities.

5:23 So, when you build your security,

5:25 assuming that you have a bad actor already

5:28 in or accessible to some of your system,

5:31 then you win because it means yes, they get something,

5:33 but they can't get any more than that.

5:35 Um, this just occurred to me while you were

5:37 talking because I realized that actually being a security company,

5:39 you are a very highly I would imagine a highly valued target for bad actors.

5:44 Absolutely.

5:44 We're terrified of this stuff.

5:47 And so, uh, how I'm just curious about your level

5:52 of of of comfort like you build this stuff.

5:57 Are you up every night worrying about bad actors coming at you guys?

6:01 So, I'm up every night regardless.

6:03 So, so I I I think what we do

6:05 is make sure that everything has checks and balances.

6:07 So, one of the things that scares me is there was

6:10 another Florida security company that hired a North Korean spy by mistake.

6:14 Uh so, we are very conscious about okay,

6:16 even we hire people, how much data do they have access to?

6:20 How far can they go with that data?

6:22 Where if they write code, who's reviewing that code?

6:24 Who's checking that?

6:25 For example, when we do a update,

6:27 it gets validated by three separate departments

6:30 before it can be pushed out.

6:31 Oh wow.

6:32 So we have to have those checks and balances cuz

6:34 we have to assume I mean we're obviously a big target.

6:37 We're protecting federal government, international airports,

6:41 uh lots of critical infrastructure.

6:43 So we would be a very very big target.

6:45 Uh so we have to really be vigilant but we

6:48 also have to assume that everybody in the company is compromised.

6:52 Wow.

6:52 And there has to be a check and balance for what they do.

6:55 Okay.

6:55 So you showed me some keystrokes being logged right

6:58 away but you promised me access to a webcam.

7:00 Okay.

7:00 Okay.

7:00 So, let's get access to a webcam.

7:02 So, I'm going to switch out this keyboard.

7:04 Um I think we we're done with this one.

7:06 Um and we're going to plug in.

7:08 Now, do you like when you're traveling around with that stuff,

7:10 do you ever like some of the stuff is compromised?

7:13 Do you have some secret UV symbol on it?

7:15 So, you know what stuff is?

7:16 That's why we're using the black cable, not the white cable.

7:19 Oh, like black hat hacking and white hat.

7:22 So, because the white cables are what we use to charge our phones.

7:24 The black cables are the bad ones.

7:26 However, some of these devices cannot cross into Canada.

7:29 And I was in the Middle East with some of them and I was like,

7:32 "Am I allowed this in this country?" And the guy was like,

7:34 "No, this is not legal here." And I was like, "Anander, you can fly that home."

7:39 Uh, so, uh, I'm going to plug this one in.

7:42 Now, again, I can charge my phone.

7:43 It's a real But you haven't plugged anything into this cable.

7:46 I It's literally just plugged in so I can charge my phone.

7:49 It's now presented as a Wi-Fi for Kira.

7:52 Oh my gosh.

7:54 And in a few moments, he'll be able to connect to it.

7:57 And he

7:58 this looks like the most unthreatening thing in the world

8:00 is a cable not plugged into anything on the other side.

8:04 And yet here it is.

8:05 And what what Kieran's going to do now is literally send

8:08 a payload same way we did before with with the the USB device.

8:13 But now it's just I'm not touching anything just wirelessly.

8:17 What it goes and I can have payloads saved or I can

8:19 type them and make them at any time completely remote.

8:25 Terrifying.

8:25 And this is a really high use in things like hospitals because

8:28 you going to a do an office you can plug something in.

8:31 Hospitals are high targets for ransomware.

8:33 Tons of Bluetooth going on.

8:34 Tons of Bluetooth.

8:36 Computers often left unattended.

8:38 Patients left in rooms.

8:39 You can you leave one of these in there and you can go in two hours later.

8:43 And of course they're more likely to pay

8:45 ransoms because they you're stealing customer data.

8:48 Oh, that's terrible.

8:49 Yes.

8:49 Cuz every computer has access to all of this patient information.

8:53 Yes.

8:53 Oh my gosh.

8:54 So, we see here now, again, we've left it on the screen so you can see it,

8:56 but we can drag it out the way.

8:58 This camera is now recording you

9:00 really.

9:00 And and it's uploading to our Google and there's no light.

9:02 I don't see any indication that it's recording.

9:05 No indication whatsoever.

9:06 And we have here every 10 seconds it'll upload that video to our Google bucket.

9:11 Uh I can download it here.

9:14 Oh, let's watch.

9:16 We're using Google because Google's less likely to trigger

9:18 talking to a ransomware GOING ON.

9:23 ENDED.

9:25 That's absolutely

9:26 I think you're going to be sweeping this place when we leave, dude.

9:30 And we can make it persistent as well,

9:32 just like the other scripts that we have with the screenshotting.

9:34 So, your camera is set up on your computer.

9:36 Yeah.

9:37 You come back, you log in in the morning,

9:40 I just get a full video.

9:41 I can even pair that with the screenshot.

9:43 So, I can get a screenshot of your computer

9:45 every 10 seconds and the video along with it.

9:48 Oh my gosh.

9:49 Um, what do you say to like I you're at a holiday dinner,

9:53 you're talking to your grandmother, you're telling her about what you're doing,

9:55 and she says, "It sounds like the world is a super dangerous place."

9:58 How do you manage like what do you what do you tell her?

10:02 Um, well, at this point, the the question that normally comes up is,

10:06 "Is my data stolen?" So, your data is already gone.

10:09 Don't worry about it.

10:09 Like, just it's already been stolen.

10:11 Everyone knows everyone knows your medical records.

10:14 Everyone knows your credit.

10:15 just lock I just say just lock your credit report and accept

10:18 the fact that everyone knows every time we went to the doctor.

10:21 That's kind of like as an individual because

10:23 the problem is as individuals we rely on businesses.

10:25 I can talk to businesses and I can

10:26 help businesses make sure they don't get destroyed.

10:29 But you go to a car dealership, you buy a car,

10:32 you don't really have any choice as to how they process you and treat your data.

10:35 You go to the hospital,

10:36 you give them your medical records, you don't have any choice.

10:39 So I will say to people, individuals, I'll say just lock your credit report.

10:42 Unlock it when you want to get credit.

10:44 monitor your credit and just accept that every time you've been to the doctor,

10:47 the it's the whole world knows about it.

10:50 Wow.

10:50 Most people put on Facebook now anyway.

10:51 So, and the method you guys bring to your clients

10:55 is a zero trust environment where you're

10:59 always assuming that every ingress into the computer

11:02 is a is a vector for something bad.

11:05 Yeah.

11:05 And just make it harder like in this case,

11:07 why would PowerShell need to reach out to the internet?

11:09 Just don't let PowerShell reach out to the internet.

11:12 And it would and look, it's still taking the pictures, but it can't upload them.

11:15 And that's the difference between, hey, you actually delivered a payload,

11:18 but it's useless, or you delivered a payload,

11:20 and now you've got a video of me scratching my face all day long,

11:23 which is really not that interesting.

11:25 Enjoy that.

11:28 Yeah.

11:27 Now, you said that um that smaller companies were

11:30 being more highly targeted for ransomware than giant organizations.

11:35 Um that seems like a new development over the last few years.

11:38 Yeah, it's it's got I mean it's I think since 2017

11:41 it really exploded and it's just got worse and worse and worse.

11:44 The payments are getting bigger and bigger and bigger and quite often the bigger

11:48 companies are starting to be sophisticated enough

11:51 that they're they're implementing zero trust controls.

11:53 They're putting things on the network so

11:54 it's getting harder and harder to target them.

11:56 Uh smaller companies have this mentality that who would care about my stuff.

12:00 Right.

12:00 Right.

12:00 I'm just a tire repair shop.

12:02 Right.

12:02 But what they don't realize is you care about it.

12:04 So, if they can take your systems offline,

12:06 encrypt your databases, upload your customer data, you're willing to pay.

12:09 And sometimes it's you'll pay me $20,000 and sometimes it'll

12:12 pay pay me half a million dollars or a million dollars,

12:14 whatever they think they can get.

12:15 They'll take your financial information and then use

12:18 that to estimate how much they can steal from you.

12:20 Peg butchering.

12:21 They're just going to get everything.

12:23 So, and that the first things they'll look at when they get in there is

12:25 find the cyber insurance policy and find out

12:27 how much you have in your bank account.

12:29 OH, NO WAY.

12:30 So once they know those two things,

12:31 they can come in and you'll literally see if you see

12:34 the the negotiations with these hackers to get your data back,

12:37 you'll see, oh, we don't have much money.

12:39 And they'll just send back your bank statement and say, yes, you do.

12:44 That's terrible.

12:45 So, and yes, you do.

12:47 We're only asking for 300,000.

12:49 You have a million in your bank.

12:50 And they'll they'll just apply with that.

12:53 It's a whole business.

12:54 It really is.

12:55 They run it just like a business.

12:56 They run it just like a like an actual business.

12:58 Yeah.

12:58 And I think the report I saw yesterday

13:00 was $1.5 trillion dollars the cost of cyber crime.

13:03 It's currently going and it's only rising.

13:06 It's only rising.

13:06 Every year it rises over and over again.

13:09 And these are some of the cool tools,

13:10 but it's again we're just using a computer here.

13:14 My takeaway from this is the frame why would I be interesting

13:19 to a bad actor is one we should all remove from our brains.

13:23 Again, it comes down to one employee,

13:25 one user doing that and then you've got access to this.

13:27 And you only need one to get into the Oh my god, that's terrifying.

13:31 You got 10 employees, you'll probably get three.

13:35 Like, I mean, that's the reality of it, right?

13:37 I mean, we're a cyber security company.

13:38 We do training with our users every single month,

13:40 and our users still fall for those scams.

13:42 Do you do So, you guys do pen testing,

13:45 penetration testing, and fishing for your clients?

13:48 So, we do penetration No, penetration testing on our own infrastructure.

13:51 Gotcha.

13:52 So because we have to it's part of our compliance

13:54 but I feel like it's a waste sometimes because

13:57 we teach we say look you got fished go

13:59 through training and then next month they get fished again.

14:02 So uh so then we just take away all their access so they

14:05 can only access exactly what they need and nothing else and we accept

14:08 and then they're safe and then so you just eliminating choice.

14:14 Yes.

14:14 Remove the human element as much as possible.

14:16 Right.

14:17 And at the end of the day, most people need to come into their office,

14:19 open the browser, go into Zoom, open the finance software.

14:22 They don't need to be able to do all these things.

14:24 They don't need to be able to upload things in PowerShell.

14:26 It's funny.

14:27 I think of my computer, I think of my laptop because I've had one since 1993.

14:31 I think of it like a Swiss Army knife,

14:32 but I realize that's a poor frame to think about it

14:36 in because this every tool that it can use is a vulnerability.

14:41 Absolutely.

14:41 Wow.

14:41 You guys have really reset my head on this.

14:43 Thank you for taking nefarious screenshots and

14:45 you should probably stop recording now.

14:49 Guys, you really reset my head on this.

14:50 Thank you for this terrifying education.

14:53 I really appreciate it.

14:54 Thank you.

Study with Looplines Download Captions Watch on YouTube