TLDW:

  • Don’t trust random USB ports or cables – Public ports can steal your data (juice jacking), and malicious cables like the OMG cable look identical to normal ones but contain a hidden computer that can remotely attack your device.

  • Your car shares more than you’d expect – When you plug your phone into a vehicle, it can pull contacts, messages, and other data, which may then get shared with manufacturers, third-party services, and data brokers.

  • Built-in protections are easy to screw up – Running outdated software makes attacks more likely. Plus, you might accidentally tap “trust” on a prompt, or be too lazy to switch back from “data” to “charge only” mode, leaving you vulnerable.

  • USB data blockers physically sever the data pins – They only pass power, completely blocking any data connection at the hardware level so nothing can flow in or out. Cheap and simple.

  • DiarrheaSommelier@lemmy.ca
    link
    fedilink
    arrow-up
    6
    ·
    2 days ago

    The problem with this solution is that your device will only charge at legacy 5V low power charging. The data pins are used to negotiate charging rates between devices and without this capability the charger will only deliver the known-safe basic low power charging rate.

  • 667@lemmy.radio
    link
    fedilink
    English
    arrow-up
    11
    ·
    2 days ago

    It’s mind-boggling how many people raw dog USB ports in public spaces, airplanes, and Ubers.

  • maus@sh.itjust.works
    link
    fedilink
    English
    arrow-up
    4
    ·
    2 days ago

    While researchers have demonstrated charging-port attacks in controlled settings, as of May 2023, multiple reviews have found no credible reported cases of juice jacking on mobile OSs outside of research efforts, and experts generally assess the risk to typical users as low relative to other threats.

    Its entirely a non-issue until there’s literally any commercially viable real-world application of this. You should be more worried about NFC relay attacks and other real world attack vectors.

  • Gsus4@mander.xyz
    link
    fedilink
    arrow-up
    6
    ·
    2 days ago

    Or just use a power USB cable after testing that it only charges and doesn’t comm with any of your devices.