📺 Stream EntrepreneurTV for Free 📺

Why a Dangerous Security Flaw in USB Devices Is Putting Computers Everywhere at Risk Thumb drives and other USB devices are vulnerable to malware that could let an attacker take over a user's computer.

By Benjamin Kabin

entrepreneur daily

Opinions expressed by Entrepreneur contributors are their own.

USB devices and the computers their users connect them to are vulnerable to malicious code that can totally take over a user's computer, manipulate files stored on the drive and redirect Internet traffic.

Security researchers Karsten Nohl and Jakob Lell first demonstrated the attack this summer at the Black Hat security conference in Las Vegas where they showed a large crowd how their malware embeds itself in the firmware that allows USB devices to communicate with computers, Wired reports.

Nohl and Lell did not publish their code, called BadUSB, for fear that it would be used for nefarious purposes; but now two other researchers have opened Pandora's Box.

Related: FBI to Apple, Google: Your New Privacy Policies Are Making People Less Safe

At last week's Derbycon hacker conference two other researchers, Adam Caudill and Brandon Wilson demonstrated that they'd reverse engineered the BadUSB malware and then published it on Github for anyone to see.

"The belief we have is that all of this should be public. It shouldn't be held back. So we're releasing everything we've got," Caudill said at Derbycon. "If you're going to prove that there's a flaw, you need to release the material so people can defend against it."

Caudill's statement highlights a philosophical split among security researchers: those who elect to keep the flaws they find under wraps in order to protect the public directly, and others, who believe publishing their software exploits is the best way to put pressure on the industry to fix security flaws quickly.

In an interview with Wired, Caudill said even if this particular flaw isn't being used by garden variety hackers already, he believes well-funded organizations, like the NSA, may already have the capability and are using it.

Related: "Bash' Bug Could Be Bigger Than Heartbleed

"You have to prove to the world that it's practical, that anyone can do it … That puts pressure on the manufactures to fix the real issue," Caudill said. "If this is going to get fixed, it needs to be more than just a talk at Black Hat."

Because the malware is stored on the device's firmware, which controls the basic functionality of the device, it's very difficult to detect and can't even be deleted by clearing the storage contents. Caudill also demonstrated how the malware can be used to hide files and secretly disable password-protected security features.

Before last week's demonstration Nohl told Wired that he considered this exploit to be basically unpatchable. In order to mitigate against these types of attacks, he said, the entire security architecture would have to be rebuilt from the ground up with code that cannot be changed without the manufacturer's signature. Even then, he said, it could take more than a decade to get rid of vulnerable devices and smooth out all the new bugs.

Both research teams reverse engineered the firmware from USB devices made by Phison, a Taiwanese company and one of the largest USB device makers. Even if you don't use Phison devices yourself, your computer is still vulnerable, especially if you swap files with other users or happen to pick up a new free thumb drive at a business conference.

Related: JPMorgan Hack Exposed Data of 83 Million Homes and Small Businesses

Benjamin Kabin

Journalist

Benjamin Kabin is a Brooklyn-based technology journalist who specializes in security, startups, venture capital and social media.

Want to be an Entrepreneur Leadership Network contributor? Apply now to join.

Editor's Pick

Growing a Business

Future-Proofing Your Business — 5 Strategies for Sustainable Growth in Times of Change

Key strategies for marketing and advertising agency leaders to navigate the rapid pace of technological and market changes, ensuring survival and growth.

Business News

Planet Fitness Is Increasing Membership Prices for the First Time in Nearly 30 Years

The gym chain's classic membership has traditionally been $10 since 1998.

Business News

Apple Issues Apology for iPad Pro 'Crush!' Ad and Pulls It from TV — Here's Why

The ad drew criticism from Hollywood creatives, including actor Hugh Grant.

Side Hustle

Want to Start a Simple Business That Helps the Planet? After 'One Night's Worth of Research,' He Started an Eco-Friendly Gig And Now Makes $200K a Year

Environmentally-conscious laws are picking up steam across the country. When one went into effect in Zach Cavacas's home state, he saw a lucrative business opportunity. Chances are, a similar law is coming to your state, or is already there.

Leadership

Are You a Visionary Leader? Here's How to Tell (and What You Can Do to Become One)

What the world needs now is leaders who think differently. How do you stack up?

Leadership

I've Negotiated High-Pressure, Multi-Million-Dollar Deals for Artists Like Bruno Mars and Enrique Iglesias — Here's the Strategy That Always Helps Me Win

Lylette Pizarro, founder and co-managing partner of Influence Media Partners, reveals what it takes to succeed in the dynamic music industry and beyond.