# Secure USB - Preventing Hacking over USB

**URL:** <https://community.frame.work/t/secure-usb-preventing-hacking-over-usb/30917>\
**Category:** Expansion Card\
**Created:** [May 10, 2023, 5:57am UTC](https://community.frame.work/t/secure-usb-preventing-hacking-over-usb/30917 "2023-05-10T05:57:01Z")\
**Posts on this page:** 15\
**Page:** 1

<div class="post-metadata">

**Author:** ![Zoltan\_Hoppar](https://avatars.discourse-cdn.com/v4/letter/z/ac8455/32.png) [@Zoltan\_Hoppar](https://community.frame.work/u/Zoltan_Hoppar)\
**Post date:** [May 10, 2023, 5:57am UTC](https://community.frame.work/t/secure-usb-preventing-hacking-over-usb/30917/1 "2023-05-10T05:57:01Z")

</div>

Really would like to see real security hw module implemented to prevent malicious USB devices. Ideally really would be interesting to have USB ports with ON/OFF switchable both dataline/power options, or datablockers.

> **[USB Data Blocker Teardown](https://mg.lol/blog/data-blocker-teardown/)**
>
> USB Data Blockers, have been a common peace-of-mind device. But if you ask someone how they work or what they do, the answers tend to differ. And with so many options, how do you choose the right one? This writeup is meant to provide these answers....

Would it be possible to have a such secured USB module shipped by default?

---

<div class="post-metadata">

**Author:** ![Name2](https://avatars.discourse-cdn.com/v4/letter/n/7cd45c/32.png) [@Name2](https://community.frame.work/u/Name2)\
**Post date:** [May 10, 2023, 7:41am UTC](https://community.frame.work/t/secure-usb-preventing-hacking-over-usb/30917/2 "2023-05-10T07:41:12Z")

</div>

+1 great idea to implement a data blocker as an expansion card.

---

<div class="post-metadata">

**Author:** ![MJ1](https://sea1.discourse-cdn.com/flex001/user_avatar/community.frame.work/mj1/32/15519_2.png) [@MJ1](https://community.frame.work/u/MJ1)\
**Post date:** [May 10, 2023, 5:56pm UTC](https://community.frame.work/t/secure-usb-preventing-hacking-over-usb/30917/3 "2023-05-10T17:56:21Z")

</div>

These devices only provide charging. I’m sorry but if you want to charge a device that you _really_ don’t trust maybe don’t use your expensive laptop as a dumb charger? Use an AC adapter or power bank.

---

<div class="post-metadata">

**Author:** ![Shiroudan](https://sea1.discourse-cdn.com/flex001/user_avatar/community.frame.work/shiroudan/32/15620_2.png) [@Shiroudan](https://community.frame.work/u/Shiroudan)\
**Post date:** [May 10, 2023, 5:59pm UTC](https://community.frame.work/t/secure-usb-preventing-hacking-over-usb/30917/4 "2023-05-10T17:59:51Z")

</div>

Does USB-PD not use these lines? At that point just use a barrel jack.

---

<div class="post-metadata">

**Author:** ![Name2](https://avatars.discourse-cdn.com/v4/letter/n/7cd45c/32.png) [@Name2](https://community.frame.work/u/Name2)\
**Post date:** [May 10, 2023, 7:22pm UTC](https://community.frame.work/t/secure-usb-preventing-hacking-over-usb/30917/5 "2023-05-10T19:22:20Z")

</div>

> [@MJ1](#):
>
> These devices only provide charging. I’m sorry but if you want to charge a device that you _really_ don’t trust maybe don’t use your expensive laptop as a dumb charger? Use an AC adapter or power bank.

It is the other way. It is so you can charge the laptop from a source you do not trust.

> [@Shiroudan](#):
>
> Does USB-PD not use these lines? At that point just use a barrel jack.

Yes, they do. You can find devices that block all data except the PD messages.

---

<div class="post-metadata">

**Author:** ![MJ1](https://sea1.discourse-cdn.com/flex001/user_avatar/community.frame.work/mj1/32/15519_2.png) [@MJ1](https://community.frame.work/u/MJ1)\
**Post date:** [May 10, 2023, 8:27pm UTC](https://community.frame.work/t/secure-usb-preventing-hacking-over-usb/30917/6 "2023-05-10T20:27:05Z")

</div>

Really you don’t need to worry about juice jacking if you’re a normal person with a normal threat model / not a target of nation-state & not executive of corporation with seriously valuable trade secrets.

> **[Those scary warnings of juice jacking in airports and hotels? They’re mostly...](https://arstechnica.com/information-technology/2023/05/fearmongering-over-public-charging-stations-needs-to-stop-heres-why/)**
>
> Juice jacking attacks on mobile phones are nonexistent. So why are we so afraid?

Ars also goes into why this fear mongering is suddenly in the news again. Also " There are _no_ documented cases of juice jacking _ever_ taking place in the wild."  
If you’re still worried, there are plenty of sellers of USB condoms that are happy to take your money. Just buy one of them? There isn’t really a need for Framework to make a limited charge-only expansion card for a threat that never been documented as actually taking place in the real world.

> [@Name2](#):
>
> It is the other way. It is so you can charge the laptop from a source you do not trust.

The OP has a link to USB-A devices.

For charging the Framework laptop itself you would be using USB-C with a PD charger capable of higher wattage. USB-C PD is negotiated over the CC line, I haven’t tied it but you might not even need the data lines at all. Easy to test if you wish using a spare USB-C cable. Just slit the side of the cable’s jacket and cut the USB2 data lines, they are normally green and white twisted together. The high speed data lines are unlikely to be involved, you can leave them. If a USB-C PD device charges from the cable then the CC line is the only thing you need. You could then create a “secure” USB-C PD expansion card by a opening one up & cutting all the data line traces with an exacto knife. Just leave power and CC.

Btw, don’t google “USB killer”. Another threat you’ll never run into that even a standard USB condom won’t protect you from.

---

<div class="post-metadata">

**Author:** ![Clover3077](https://sea1.discourse-cdn.com/flex001/user_avatar/community.frame.work/clover3077/32/15373_2.png) [@Clover3077](https://community.frame.work/u/Clover3077)\
**Post date:** [May 10, 2023, 11:28pm UTC](https://community.frame.work/t/secure-usb-preventing-hacking-over-usb/30917/7 "2023-05-10T23:28:47Z")

</div>

To be completely honest, the best way against those stuff is just don’t plugin things you don’t trust.

Next best would be require authentication for attaching usb devices which is what I plan to do. It seems to be quite easy on linux but I haven’t get around to try that yet [Authorizing (or not) your USB devices to connect to the system — The Linux Kernel documentation](https://docs.kernel.org/usb/authorization.html)

threat model-wise. It is mostly 1. you found something random and you plug it in, or 2. someone pluged something in your computer.  
In case 1, don’t be stupid and, if you have to, use some device you don’t care about.  
In case 2, you really have more serious problem than what you are trying to prevent, and it does not stop the attacker to just use the inner usbc port. don’t forget framework input cover can be swapped and nobody is stopping someone from putting something malicious in place of a expansion card that look the same as the original. tbh that is more concerning since I am working on rp2040 expansion card which can be easily programmed to do HID injection, it will cost \<$20 ea if I make 10 of them.

---

<div class="post-metadata">

**Author:** ![MJ1](https://sea1.discourse-cdn.com/flex001/user_avatar/community.frame.work/mj1/32/15519_2.png) [@MJ1](https://community.frame.work/u/MJ1)\
**Post date:** [May 10, 2023, 11:45pm UTC](https://community.frame.work/t/secure-usb-preventing-hacking-over-usb/30917/8 "2023-05-10T23:45:09Z")

</div>

> [@Clover3077](#):
>
> don’t forget framework input cover can be swapped and nobody is stopping someone from putting something malicious in place of a expansion card that look the same as the original.

Oh boy, somehow I forgot about that. A malicious expansion card would be interesting to see. But, as fans of Framework also not something you want to see. Could use a USB-C or USB-A expansion card, which is something most people are likely to have in their frame work. Keep the original shell so it looks 100% legit. Pass though the USB-C or USB-A so it still works as a real one would. But again you have to consider that the average user just isn’t a valuable enough target to warrant the skill & effort needed to make a malicious module that has the ability to act silently and do something truly worthwhile.

---

<div class="post-metadata">

**Author:** ![Clover3077](https://sea1.discourse-cdn.com/flex001/user_avatar/community.frame.work/clover3077/32/15373_2.png) [@Clover3077](https://community.frame.work/u/Clover3077)\
**Post date:** [May 11, 2023, 12:54am UTC](https://community.frame.work/t/secure-usb-preventing-hacking-over-usb/30917/9 "2023-05-11T00:54:26Z")

</div>

> [@MJ1](#):
>
> A malicious expansion card would be interesting to see. But, as fans of Framework also not something you want to see.

I know right.  
In my opinion framework is the best platform to make a super secure laptop but definite isn’t that out of the box.

For instance, if I were to make framework physically secure, I would add cryptographic chips to the modules and require authentication to enable the usbc port underneath when a module is detached. possibly adding intrution detection to modules themselves through metalic layers.

the chassie intrution detection switch that is used to alert people the laptop is on when opening it can definitely be configured to wipe all data in RAM and TPM which framework have, effectively erase all meaningful data if disk encryption is used with TPM. and more sensors such as light and temperature can be added to protect against other attacks

All these can make repairing the laptop a nightmare which is why framework won’t do it. but the beauty about framework is that it is so well documented that you can do most if not everything yourself

---

<div class="post-metadata">

**Author:** ![Name2](https://avatars.discourse-cdn.com/v4/letter/n/7cd45c/32.png) [@Name2](https://community.frame.work/u/Name2)\
**Post date:** [May 11, 2023, 4:35am UTC](https://community.frame.work/t/secure-usb-preventing-hacking-over-usb/30917/10 "2023-05-11T04:35:36Z")

</div>

> [@MJ1](#):
>
> If you’re still worried, there are plenty of sellers of USB condoms that are happy to take your money. Just buy one of them? There isn’t really a need for Framework to make a limited charge-only expansion card

There is also hdmi, displayport, ethernet… adaptors, and yet the modules were done. Not sure why you guys are so up in arms about it. It does not even have to be Framework, it could be done by a third party, for people interested in it. It is a good idea.

---

<div class="post-metadata">

**Author:** ![skylar](https://avatars.discourse-cdn.com/v4/letter/s/b487fb/32.png) [@skylar](https://community.frame.work/u/skylar)\
**Post date:** [September 23, 2023, 3:55am UTC](https://community.frame.work/t/secure-usb-preventing-hacking-over-usb/30917/11 "2023-09-23T03:55:25Z")

</div>

PortaPow makes a [dongle](https://www.amazon.com/PortaPow-USB-C-Data-Blocker-Protect/dp/B082WDHS22) that does this for $6, however according the reviews it doesn’t support PD, which is odd.  
Even if you need a microcontroller to forward the PD messages this would be a pretty easy thing to make.  
At some point the paranoia might escalate to distrust of Intel Management Engine and the purchase of an MNT Reform though.  
Side note: I myself have the USB-A blocker, but every time I’ve needed to charge any kind of USB device since purchase I’ve had a trustworthy charger and cable with me too.

---

<div class="post-metadata">

**Author:** ![Jason\_Dagless](https://avatars.discourse-cdn.com/v4/letter/j/48db29/32.png) [@Jason\_Dagless](https://community.frame.work/u/Jason_Dagless)\
**Post date:** [September 23, 2023, 10:15am UTC](https://community.frame.work/t/secure-usb-preventing-hacking-over-usb/30917/12 "2023-09-23T10:15:42Z")

</div>

I have a couple of USB data blocker plugs but I only use them for ports that are powering a DAC.

---

<div class="post-metadata">

**Author:** ![qemu-system-x86\_64](https://sea1.discourse-cdn.com/flex001/user_avatar/community.frame.work/qemu-system-x86_64/32/19267_2.png) [@qemu-system-x86\_64](https://community.frame.work/u/qemu-system-x86_64)\
**Post date:** [September 24, 2023, 7:47pm UTC](https://community.frame.work/t/secure-usb-preventing-hacking-over-usb/30917/13 "2023-09-24T19:47:05Z")

</div>

Don’t leave your computer in a place you don’t trust.

---

<div class="post-metadata">

**Author:** ![CGE](https://avatars.discourse-cdn.com/v4/letter/c/ebca7d/32.png) [@CGE](https://community.frame.work/u/CGE)\
**Post date:** [October 2, 2023, 10:21am UTC](https://community.frame.work/t/secure-usb-preventing-hacking-over-usb/30917/14 "2023-10-02T10:21:33Z")

</div>

> [@skylar](#):
>
> PortaPow makes a [dongle](https://www.amazon.com/PortaPow-USB-C-Data-Blocker-Protect/dp/B082WDHS22) that does this for $6, however according the reviews it doesn’t support PD, which is odd.  
> Even if you need a microcontroller to forward the PD messages this would be a pretty easy thing to make.

I suppose that depends on what you are defending against. As PD negotiation involves bidirectional communication, if the intention is to defend against an attacker able to exploit flaws/backdoors in PD implementations themselves, then it would be _very_ difficult to make a secure device, and arguably impossible to do so perfectly. And, of course none of these devices secure against the much more common risk, especially with PD, of the wrong voltage being provided.

However, I think there could be a place for a device like this that would make PD reasonably secure against typical (show up as keyboard / mass storage) USB attacks, and poor power implementations. It could reasonably interpret and translate PD negotiation with a well written, tested, and verified firmware, so that it would appear consistent to the end device, and could implement strong protection, even if sacrificial, against wrong voltages.

---

<div class="post-metadata">

**Author:** ![LukDeHuk](https://avatars.discourse-cdn.com/v4/letter/l/96bed5/32.png) [@LukDeHuk](https://community.frame.work/u/LukDeHuk)\
**Post date:** [October 2, 2023, 11:15am UTC](https://community.frame.work/t/secure-usb-preventing-hacking-over-usb/30917/15 "2023-10-02T11:15:21Z")

</div>

If you’re using Linux, this is a good solution [https://usbguard.github.io/](https://usbguard.github.io/) , it blocks unknown usb devices on the kernel level.
