• Jessica@lemmy.blahaj.zone
      link
      fedilink
      English
      arrow-up
      43
      ·
      6 days ago

      That is amazing. The x-ray of it is kind of scary, honestly. That little chip could be all it would take to get into an air-gapped machine.

      • Bad_Engineering@fedia.io
        link
        fedilink
        arrow-up
        17
        ·
        6 days ago

        There are a ton of different payloads that can be run on these, for everything from simple keylogging, to root access, to network backdoors. I’ve only recently gotten into pentesting but with something like this there’s no real limit to the damage that could be done with only a few seconds of physical access.

        • thejml@sh.itjust.works
          link
          fedilink
          English
          arrow-up
          22
          ·
          6 days ago

          Honestly, as a Systems/DevOps engineer it’s always been well know that if you have physical access, you have zero chance of security. Sure it might take more time if precautions were followed, but you will be owned eventually, that’s guaranteed.

          • Dubiousx99@lemmy.world
            link
            fedilink
            English
            arrow-up
            10
            ·
            6 days ago

            This is one of our most frustrating fights I have with our security design reviewers. Effectively functionless mitigations that create extra obstacles for our service reps to deal with during troubleshooting. One example is our equipment is installed in access restricted areas, in a locked rack. We don’t need to disable unused Ethernet ports on our networking equipment that exists in a locked cabinet and it will take away our ability to repatch equipment to a different switch in the system to assist in troubleshooting.

    • dance_ninja@lemmy.world
      link
      fedilink
      English
      arrow-up
      23
      ·
      edit-2
      6 days ago

      Crazy that the USB-A housing is big enough for that. Makes me want to avoid anything that’s not C to C.

      Edit: someone pointed out there’s an option for C to C 💀

    • d-RLY?@lemmy.ml
      link
      fedilink
      English
      arrow-up
      4
      ·
      5 days ago

      Came to check if anyone had already linked hak5. Glad to see you had shared the link!