[News] public charging station may put your phone at risk of hacking

2017-04-16 06:37:34
3450 36
Plugging your smartphone to public charging stations or computers using USB cables can make your device vulnerable to hackers, warn scientists including one of Indian origin.
Experts have long known the risks of charging a smartphone using a USB cord that can also transfer data.
The new research at New York Institute of Technology (NYIT) shows that even without data wires, hackers using a "side channel" can quickly find out what websites a user has visited while charging a device.
Researchers, including NYIT Kiran Balagani, warn that "a malicious charging station" can use seemingly unrelated data - such as a device's power consumption - to extract sensitive information.
As a walk through any airport will show, most people are happy to plug their phones into public charging stations, putting their phones at risk of "juice-jacking," when a compromised outlet steals data through a USB data cable, researchers said.
The study is the first to show that even without a data cable, hackers can analyse a device's power needs to get at users' private information, with speed and accuracy depending on a number of factors.
The side-channel attacks were successful as "webpages have a signature that reflects the way they load and consume energy," said Paolo Gasti, assistant professor at NYIT.
The remaining power traces act as "signatures" and help hackers discover which sites have been visited.
The researchers conducted the study using power use signatures they had previously identified and tested the attack under various conditions.
After collecting power traces via a range of smartphones browsing popular websites, researchers launched attacks and checked the accuracy with which their algorithms could determine which websites were visited while the phones were plugged in.
Various factors such as battery charging level, browser cache enabled/disabled, taps on the screen, and Wi-Fi/LTE influenced the accuracy rate in tracing websites visited.
Some conditions, such as a fully charged battery, facilitate a fast and accurate penetration, while others, such as tapping the screen while a page is loading, lessen hackers' ability to determine what website is being viewed.
The important finding from the study is that such an attack can be carried out successfully, researchers said.
In the study, the slower, less accurate attempts at penetration were still accurate within six seconds about half the time.
"Although this was an early study of power use signatures, it's very likely that information besides browsing activity can also be stolen via this side channel," said Gasti."Since public USB charging stations are so widely used, people need to be aware that there might be security issues with them. For example, informed users might choose not to browse the web while charging," he said.
2017-04-16 06:37:34
Favorites9 RateRate
it's danger u can use instead of it
2017-04-16 07:04:03

Кролик Майстер

aayush yogesh Mhetar Author | from Redmi Note 4


Yes sir....
2017-04-16 07:05:45
Useful information.
2017-04-16 07:14:29
Shree Sharma.

Кролик Майстер

Saajan Palta | from Redmi Note 3


Nice Info..
2017-04-16 07:19:58
using power bank is the safest way
2017-04-16 07:56:49


Rashid kamaal | from Redmi Note 4


Nice information and the details
2017-04-16 08:01:35

Кролик Майстер

aayush yogesh Mhetar Author | from Redmi Note 4


Girish km
using power bank is the safest way

Ur right.
2017-04-16 08:08:52

Кролик Майстер

aayush yogesh Mhetar Author | from Redmi Note 4


Rashid kamaal
Nice information and the details

Thank you.....
2017-04-16 08:09:30

Кролик Сансей

SAIRITWIK | from Redmi Note 3


It's better for us to carry a power bank...
2017-04-16 08:56:33

Кролик новачок

1674210683 | from Redmi Note 4


good information
2017-04-16 09:28:33
please sign in to reply.
Sign In Sign Up
  • Followers


  • Threads


  • Replies


  • Points


100 threads in a Month
3 Days in a row
7 Days in a row
21 Days in a row
40 Days in a row
70 Days in a row
100 Days in a row
App Review
1 million members
Xiaomi 7th Birthday
New Home
June-100 replies in a month
more power more life
July-100 replies in a month
Aug-100 replies in a month
Sep-100 replies in a month
1st Anniversary
71st Independence Day
My Poster My Life
MIUI 7th Anniversary
2 million registered members
Newbie Member
Twitter Medal
2017 Xiaomi Annual Bill

Mi Comm APP

Stay updated on Mi Products and MIUI

Content Policty
Quick Reply To Top Return to the list