• chevron_right

      LitterDrifter USB Worm

      news.movim.eu / Schneier · Wednesday, 22 November - 21:47

    A new worm that spreads via USB sticks is infecting computers in Ukraine and beyond.

    The group­—known by many names, including Gamaredon, Primitive Bear, ACTINIUM, Armageddon, and Shuckworm—has been active since at least 2014 and has been attributed to Russia’s Federal Security Service by the Security Service of Ukraine. Most Kremlin-backed groups take pains to fly under the radar; Gamaredon doesn’t care to. Its espionage-motivated campaigns targeting large numbers of Ukrainian organizations are easy to detect and tie back to the Russian government. The campaigns typically revolve around malware that aims to obtain as much information from targets as possible.

    One of those tools is a computer worm designed to spread from computer to computer through USB drives. Tracked by researchers from Check Point Research as LitterDrifter, the malware is written in the Visual Basic Scripting language. LitterDrifter serves two purposes: to promiscuously spread from USB drive to USB drive and to permanently infect the devices that connect to such drives with malware that permanently communicates with Gamaredon-operated command-and-control servers.

    • chevron_right

      Right-to-repair rules for electronics, appliances targeted for 2024, Canada says

      news.movim.eu / ArsTechnica · Friday, 31 March, 2023 - 19:22 · 1 minute

    Mobile phone repair, closeup

    Enlarge (credit: Getty )

    Like in other parts of the world, Canada is working out what the right to repair means for its people. The federal government said in its 2023 budget released Tuesday that it will bring the right to repair to Canada. At the same time, it's considering a universal charging port mandate like the European Union (EU) is implementing with USB-C.

    The Canadian federal government's 2023 budget introduces the right to repair under the chapter entitled “Making Life More Affordable and Supporting the Middle Class." It says that the "government will work to implement a right to repair, with the aim of introducing a targeted framework for home appliances and electronics in 2024." The government plans to hold consultations on the matter and claimed it will "work closely with provinces and territories" to implement the right to repair in Canada:

    When it comes to broken appliances or devices, high repair fees and a lack of access to specific parts often mean Canadians are pushed to buy new products rather than repairing the ones they have. This is expensive for people and creates harmful waste.

    Devices and appliances should be easy to repair, spare parts should be readily accessible, and companies should not be able to prevent repairs with complex programming or hard-to-obtain bespoke parts. By cutting down on the number of devices and appliances that are thrown out, we will be able to make life more affordable for Canadians and protect our environment.

    The budget also insinuates that right-to-repair legislation can make third-party repairs cheaper than getting a phone, for example, repaired by the manufacturer, where it could cost " far more than it should.”

    Read 11 remaining paragraphs | Comments

    • chevron_right

      Exploding USB Sticks

      news.movim.eu / Schneier · Thursday, 23 March, 2023 - 15:09

    In case you don’t have enough to worry about, people are hiding explosives —actual ones—in USB sticks:

    In the port city of Guayaquil, journalist Lenin Artieda of the Ecuavisa private TV station received an envelope containing a pen drive which exploded when he inserted it into a computer, his employer said.

    Artieda sustained slight injuries to one hand and his face, said police official Xavier Chango. No one else was hurt.

    Chango said the USB drive sent to Artieda could have been loaded with RDX, a military-type explosive.

    More :

    According to police official Xavier Chango, the flash drive that went off had a 5-volt explosive charge and is thought to have used RDX. Also known as T4, according to the Environmental Protection Agency ( PDF ), militaries, including the US’s, use RDX, which “can be used alone as a base charge for detonators or mixed with other explosives, such as TNT.” Chango said it comes in capsules measuring about 1 cm, but only half of it was activated in the drive that Artieda plugged in, which likely saved him some harm.

    Reminds me of assassination by cell phone .

    • chevron_right

      Journalist plugs in unknown USB drive mailed to him—it exploded in his face

      news.movim.eu / ArsTechnica · Wednesday, 22 March, 2023 - 18:35 · 1 minute

    Ecuadorian police in a media station with a shield

    Enlarge / Ecuadorian police tweeted this picture of officials investigating a drive mailed to a journalist in Guayaquil. (credit: Policía Ecuador/Twitter )

    It's no secret that USB flash drives, as small and unremarkable as they may look, can be turned into agents of chaos. Over the years, we've seen them used to infiltrate an Iranian nuclear facility , infect critical control systems in US power plants, morph into programmable, undetectable attack platforms , and destroy attached computers with a surprise 220-volt electrical surge . Although these are just a few examples, they should be enough to preclude one from inserting a mysterious, unsolicited USB drive mailed to them into a computer. Unfortunately, one Ecuadorian journalist didn't get the memos.

    As reported by the Agence France-Presse (via CBS News ) on Tuesday, five Ecuadorian journalists have received USB drives in the mail from Quinsaloma. Each of the USB sticks was meant to explode when activated.

    Upon receiving the drive, Lenin Artieda of the Ecuavisa TV station in Guayaquil inserted it into his computer, at which point it exploded. According to a police official who spoke with AFP, the journalist suffered mild hand and face injuries, and no one else was harmed.

    Read 12 remaining paragraphs | Comments

    • chevron_right

      Passe-câble pas très pratiques

      Mathias Poujol-Rost ✅ · Wednesday, 10 January, 2018 - 09:25 edit

    Les protections (#skins) de claviers #Typematrix comportent un trou pour faire passer le câble #USB vers le #PC, mais du coup si tu veux changer de « peau » il te faut retirer le #câble TOUT LE LONG… Imagine à tes débuts tu hésites et voudrais fréquemment changer…

    Du coup j'ai préféré couper pour faire une « découpe ».