Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

They bill it for “pen testers and police” so I would guess it’s really for people who imagine themselves / want to be within that audience. Not to be overly cynical.

I suppose some pen testers, or actual CIA type folks might have some need of this type of device... but is that a large enough market?



I don't buy the pen testing part. I might as well sell a hammer and call it a pen testing device. Funny enough they have the following on their website:

"A hammer used maliciously can permanently damage to a third party's device. The USB Killer, used maliciously, can permanently damage a third party's device."

Contrary to this device a hammer can be used a useful tool too.


It's designed to prove a point.

To prove that USB devices can be malicious.

It's probably most useful as an education tool, training staff not to plug random USB devices they find lying around the parking lot into their computers.


It's like hiring a gunman to start shooting up your office to train people about the dangers of social engineering, to prove that some people shouldn't be trusted.



Actively using it to harm others is different than just creating it.


Creating it and selling it is an obvious attempt to profit from the custom of those who wish to use it to actively harm others. There's literally no other reason for anybody to buy an "anonymous" one over a standard one which says what it does on the stick, and yet they're charging $5 more for the anonymous one...


It's a curiosity item. I would buy an anonymous one if they were $30 or less. It's interesting to have around, a conversation piece. The anonymous one increases the interest, because it better demonstrates the danger, the precariousness.


Bad choice as an example of social engineering, not funny, and doesn’t make sense at all.


I don't think that it was a joke or made in bad faith - rather to demonstrate the logical extreme.

Essentially that the logical extreme of dropping computer-destroying USBs to demonstrate that one shouldn't plug strange USBs in the first place is akin to destroying an office that you talked yourself into to prove that you shouldn't have been let in in the first place. Perhaps "shooting up" was a tad too far, but with charity it's a reasonable point nonetheless.


Right, it wasn't supposed to be a joke, and the intended argument was that hiring a gunman as social engineering training makes as much sense as using a computer-destroying USB stick as physical security training—so yes, it was supposed to be a bad example of social engineering.

Using a computer-destroying USB stick as an example of physical security threats misunderstands the nature and motivations of attackers. Everyone past childhood (and some in childhood, sadly) understands that there are a few people in this world whose motivation is to cause destruction and hurt simply because they find destruction and hurt enjoyable in themselves. They also understand that such people are rare, and that their threat modeling (which everyone does, even if they don't call it that) should rationally respond to such people by almost ignoring them—otherwise you find yourself not leaving your house for fear that there's a gunman on your block.

The motivations of people who want to actually get something out of you are quite different. They're not interested in destruction, because that would harm their target. They're usually interested in being undetectable. A social engineer will pretend to be locked out, ask meekly to be let in, and behave like a normal employee until they get what they need and leave normally. Defenses like "don't let people tailgate" work for those people. A gunman will just shoot you, break the door, ignore the alarm, and keep shooting until the cops kill them.

Similarly, someone who's trying to attack your business with a malicious USB drive will give you a USB drive that appears to be a normal one, that maybe pops up a terminal window very briefly and then disappears. You likely won't notice that you made a mistake, and you'll probably see an actual drive pop up on screen. Someone who's trying to attack your business will generally not give you a USB drive that destroys your computer immediately. (For most businesses, computers are not worth much compared to the secrecy of the data they contain, anyway, which is why full-disk encryption is a reasonable defense; it assumes that a computer might be lost and that this is recoverable.)

So a good security training program should say "These are ways where people might try to subtly break in to gain access that you might not have thought of before," not "Sadistic sociopaths exist, wear plate armor at all time."


Might make sense, yeah. How many computers would get blown up during such a test, and how much productivity would be lost and how much money would it cost? What is the expected cost of a major breach or malware infection? How much less likely does a breach or malware infection become as a result of leaving one of these laying around? I actually wouldn't be surprised if leaving these did come out positive, in much the same way that regular fire drills come out positive.


I would think a USB containing an info graphic about the dangers of plugging in random USBs is a far more efficient education tool than one that destroys the hardware of your staff. Worse, what if they took it home and used it on a personal device?


>> training staff not to plug random USB devices...

Nothing like some high-consequences IRL training!

Perhaps curricula for the Inspector Clouseau police academy?


When you're holding a hammer, everything looks like a nail!


I can't even imagine a situation where police would want to destroy a running device that could likely have evidence stored in volatile memory. Even if it was their own device that they were retiring, it doesn't even wipe data, it just destroys the logic/motherboard.

Hardware designers might want one to test out their mitigation circuit but once your design, why do you need a USBkill anymore?

This thing just seems like a destructive version of those annoyance toys like a TV-B-Gone.


I've never heard of TV-B-Gone.

> During the 2008 Consumer Electronics Show, an individual associated with Gizmodo brought a TV-B-Gone remote control and shut off many display monitors at booths and during demos affecting several companies. These actions caused the individual to be banned for life from future CES events.

https://en.wikipedia.org/wiki/TV-B-Gone


The innocuous use of TV-B-Gone devices was to shut off at once all TV sets at malls; it was rather a prank than a destructive act, with the added benefit of getting some peace.


Back in the day you could turn a HP-48 into a universal remote control. Oh, the pranks we pulled on an unsuspecting teacher (the teacher was the worst kind ever of know-it-all prick, and duly deserved it).


Was there a TV-come-on to turn on the mall TVs in the morning?


Not that I know of, but technically doable since all it needs is transmitting through infrared the corresponding signal variants according to different brands. By modifying the source one could for example set all TVs to maximum volume, or tune them to channel 666, or even give different commands to different brands as they share the same IR codes.


Mitch open sourced the entirety of tv b gone from the start. It's pretty easy to make this tv-come-on. The tvbg is just a ir driver and:

    foreach offcode in list_of_offcodes:
        transmit(offcode)


You need the TV-B-ON version


"I can't even imagine a situation where police would want to destroy a running device that could likely have evidence stored in volatile memory."

Exactly. That device has nothing to do with police or testing. The politically correct name is a way to avoid filters or to claim ignorance in case some customers do nasty thing with them. Not different from cellphone/gps jammers sold under the "signal/field generator" name.

"Even if it was their own device that they were retiring, it doesn't even wipe data, it just destroys the logic/motherboard."

And it's even very bad at it: most computers have internal usb hubs that would act as a (weak but sometimes successful) defense against these devices.


My business partner is a supplier to LEA / Government for intrusion / pentest / physical and electronic security. He has sold over 600 units to legitimate government and police entities.

Likewise, the USBKill suppliers had shown confirmed clients from all large SV companies, and all major hardware manufacturers.

It definitely is a malicious device in the hands of someone malicious, no doubt... But it most definitely serves a purpose to government and LEA apparently ..


TV-B-Gone has many practical uses, especially in public places where TV is foisted upon the general public


I could see this being used to check USB chargers to make sure they don't catch fire when weird things happen


I mean, it's not like it's expensive to manufacture! One person soldering and maybe a single board and usb plug, its probably easy to make money if you can sell them for $30 or so in the volumes of 100's.


Also activists / journos in some countries. I know we have looked at various emergency destruction techniques over the years.


USB killer would not be an appropriate way to do that, it'd just give a false sense of security.


I wouldn't be so sure. Frying an SSD efficiently is a good use.


Yes, efficiently frying an SSD can be a goal. No, this device does not do that.

"I wouldn't be so sure." is not the right test to pick. Yes it might destroy the SSD, but more likely just burns out something on the motherboard.

When you are picking an emergency destruction method your test should be: "I'm reasonably certain that this irreparably destroys the data"


But this is USB.


True. But options are limited. Something is better than nothing in a scenario where secret police are at your door.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: