'BadUSB' Security Threat Affects Billions of Devices and is Fundamentally Unfixable

Advertisement
By NDTV Correspondent | Updated: 3 October 2014 15:52 IST

We all use USB storage devices and accessories - in fact there are billions of them in the world right now, according to the USB Implementers Forum - and we take for granted that they'll just work when plugged in. Before the standard existed, plugging anything in to a PC usually involved shutting it down, restarting, and installing drivers.

This simplicity is achieved using microcontrollers in each USB device which negotiate connections with host PCs and tell both parties how to recognise each other. Now, nearly 20 years after the first USB devices became widespread, a lack of forethought about security in the original implementations of those controllers is being exploited.

Security researchers Adam Caudill and Brandon Wilson announced that they had reverse-engineered one widely used USB controller chip and demonstrated how they had been successful in reprogramming commonly available USB pen drives to behave in unexpected ways. Their methods can be expected to be replicated for malicious purposes since the two have released all their findings, including source code, to the public.

Advertisement

A previous report on the potential vulnerability, which has come to be known as BadUSB, was published earlier this year although no information was released that could have been used by attackers. Caudill and Wilson believe that the scale of the problem is so immense that the entire industry needs to be jolted into action, or nothing will be done about it. It is also possible that the flaw has been known to attackers (including government agencies) for a long time and has been exploited without anyone knowing. Forcing knowledge of BadUSB into the public domain will make potential victims aware of that possibility.

Advertisement

Terrifyingly, fixing the problem will require a completely new set of USB protocols and the scrapping of all devices that are currently in existence. People are so used to USB that they will not hesitate to plug in a storage device, keyboard, or any other product - even a smartphone. This complacence can be exploited by attackers, for example, by leaving a doctored pen drive lying around in public or giving thousands of them away for free in a promotion - no one would hesitate to plug it in.

Because the drive's firmware has been modified, formatting it won't do any good. Malware detection tools can only scan storage locations, not firmware. Experts citied by Wired estimate that it could take over a decade for a new, secure version of USB to become dominant, and even then there would be no way to ensure that every single previously sold USB device had been destroyed.

Advertisement

Even commonly available password-protected pen drives can be compromised - the duo demonstrated a technique by which any password set by a user could be invalidated. The user might continue thinking his device is secure, but unbeknownst to him, any combination of characters will be able to unlock it.

Another demonstration involved modifying a commodity pen drive so that it contains a completely hidden partition which is only mounted by plugging a pen drive into a PC and then ejecting it. When unmounted, the secret partition's contents are not detectable even to forensic examination tools. The final demo was of a virtual keyboard which was capable of taking over input and entering commands on a PC - just plugging in any USB device could trigger a flood of keyboard inputs that could potentially be used to install malware, steal passwords, or anything else.

Advertisement

In effect, USB itself should now be considered fundamentally insecure. Users concerned about device and data security should not use any new USB device that comes into their possession. Affected devices cannot be detected and there is no patch. At most, according to the two demos, PCs might be able to detect fishy behaviour but would not be able to prevent it before it happened. The USB-IF has not responded, although at least one secure device vendor, Ironkey, has publicly announced that its products are not vulnerable because they use signed firmware code, and signatures are verified on each use to make sure the code has not been tampered with.

USB as a standard is already set to become a lot more confusing with the impending debut of the new, backwards-incompatible Type-C connector which will work with existing USB 3.0 and older devices as well as upcoming USB 3.1 standard.

Get your daily dose of tech news, reviews, and insights, in under 80 characters on Gadgets 360 Turbo. Connect with fellow tech lovers on our Forum. Follow us on X, Facebook, WhatsApp, Threads and Google News for instant updates. Catch all the action on our YouTube channel.

Advertisement

Related Stories

Popular Mobile Brands
  1. Google's Pixel Upgrade Program Lets You Get the Latest Model Every Year
  2. Sony's Year-End Holiday Sale on PS5 Accessories, Games Kicks Off Next Week
  3. OTT Releases This Week: Thamma, Mrs Deshpande, Raat Akeli Hai The Bansal Murders, and More
  4. Oppo Reno 15 Pro, Reno 15 Pro Max Global Variants Surface on Geekbench
  5. YouTube Bans Popular Channels for Making Misleading AI-Generated Movie Trailers
  6. Dominic and The Ladies' Purse Streaming Now: Know Where to Watch It Online
  7. Here's When the Realme 16 Pro Series Will Launch in India
  8. Xiaomi 17 Ultra Battery Details and Colourways Surface Ahead of Launch
  9. Starlink satellite tumbles toward Earth after orbital failure
  10. Four More Shots Please Final Season Streaming Now: Know Where to Watch it Online
  1. Astronomers Observe Black Hole Twisting Spacetime for the First Time, Confirming Einstein’s Theory
  2. Hubble Captures Rare Collision in Nearby Planetary System, Revealing Violent Planet Formation
  3. Scientists Rule Out Elusive Sterile Neutrino After 10-Year Hunt, Shaking Particle Physics
  4. NASA’s PUNCH Mission Provides First Continuous Views of Solar Eruptions Across Space
  5. Starlink Satellite Breaks Apart in Orbit, Begins Uncontrolled Fall Toward Earth After SpaceX Anomaly
  6. Four More Shots Please Final Season Out on Prime Video: Know Everything About This Show For One Last Time
  7. Godday Godday Chaa 2 Now Streaming Online: A Powerful Punjabi Comedy with Social Satire
  8. Pharma Streaming Now on JioHotstar: Everything You Need to Know About This Thought-Provoking Drama Online
  9. Mrs. Deshpande Now Streaming Online: A Powerful Drama Exploring Identity, Marriage and Strength
  10. Adobe Partners With Runway to Offer Firefly Users Early Access to Video Generation Models
Gadgets 360 is available in
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2025. All rights reserved.