[mdlug] MDLUG meeting 10/11/2014 - Good Meeting

Drew drew4096 at gmail.com
Sun Oct 12 15:53:23 EDT 2014


We didn't get around to discussing BadUSB.

The story is that there are a lot of usb devices out there that are
actually *two* devices: the device that it's supposed to be (usually a
flash drive), and malware that identifies itself as  a keyboard and
then begins sending nefarious keyboard signals which are able to do
things as if they were the person using the machine, or possibly even
as root, without the user knowing about it until it's too late.

At the very least, USB devices will need to be vetted on a system
connected only to a LiveCD that can run lsusb tocount how many
additional devices show up. Probably the USB drivers will need to be
rewritten to notify the user of each device activation and issue a
captcha challenge.


On 10/12/14, gib at juno.com <gib at juno.com> wrote:
> We had our mdlug.org meeting yesterday.  Several interesting ideas came up.
> A few: 1. Current events (we have new ones of course). We talked about the
> HP break up, BAD USB exploit. 2. Beacons (Paypal). 3. Vitalization. 4.
> Blender (Okay I intended to talk about this but didn't get a chance). 5.
> Helicopters drones and quad-copters oh my. 6. Wearables 7. Raspberry PI
> (Drew had his set up and running and we used SSH to connect to it). 8.
> VMware has a new product EVO Rail (didn't get a chance to talk about this
> too much).  9. Elections 10. Penguicon. Other topics: Tony did  a demo of a
> product, OwnCloud, which he will demo at Tuesday's MUG.ORG meeting. TOR was
> mentioned along with NSA  and security topics. One new member said she works
> on security devices (nuspire.com). Another new member told us about the
> security book (ThatCyberSecurityGuy.com) he just wrote. The Keypass password
> tool was discussed. Setting Keypass up with OwnCloud sounded like a good
> discussion. Search engines
>   DuckDuckGo, SmartPage were mentioned. The domain name registrar
> NameCheap.com was a solution that Tony uses because it also provides useful
> services like dynamic DNS. So, just another MDLUG meeting with nothing
> special going on.  :)  Just kidding, we had a great meeting.
>
> ____________________________________________________________
> Fast, Secure, NetZero 4G Mobile Broadband. Try it.
> http://www.netzero.net/?refcd=NZINTISP0512T4GOUT2
> _______________________________________________
> mdlug mailing list
> mdlug at mdlug.org
> http://mdlug.org/mailman/listinfo/mdlug
>


More information about the mdlug mailing list