The "Giveaway" that gives your data away..
We've all been there, you walk the floor on a certain expo – and then it catches your eyes! A bowl full of Cellular-power banks chargers, you could almost sense those milliamps running through your veins – you promised yourself that you would be stronger this time, but yet again you cannot resist and take one – convincing yourself that it's for the kids…
After the "Golden era" of USB mass storage keys as a giveaways, it's now the time for Cellular-power banks, as people got the understanding that plugging a USB mass storage device that you just got from an unknown source is not what a professional CISO would do.
In most cases people WILL take a Cellular power bank and use if freely, of course you, that is now reading this – don’t, but there are many who will – and it's up to us to spread the word – they can just as malicious. By simply reducing the battery size, you can make room for a nice rubber ducky device impersonating as a keyboard, working under the radar – with wealth of various payloads with courtesy of the legitimate developers community or the dark web.
Now you see me -
Now you don’t –
BTW – In the last RSA we gave out rubber duckies (the real ones), and after hearing our pitch, people were afraid to take them, although we promised them, it only quacks…