Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

I've had booths on cyber security trade fairs hand out USB flash drives as prizes for spinning a wheel, with no awareness how that might seem odd. I guess people would be reluctant to accept them at BlackHat, but everywhere else people are very trusting towards USB stuff.


I take free USB drives any day. I always test them on the pc that belongs to the coworker that nobody likes first though ;)

In all seriousness though - 128gb usb 3.0 drives can be picked up for $10 on sale all day long. Absolutely no reason to trust some $0.25 random 4gb that a stranger gave you aside from running R-studio on it for fun or something.


I once worked at a place where the security team had a USB stick delivered to all the desktops with some digital brochure about not trusting strangers or some such. Not the cyber security team, but still.


We send staged phishing emails internally to see who takes the bait.

Leaving USB sticks lying around with some sort of callback to see who plugs them in is a really clever idea. We could probably catch the serial number range in Defender ATP.


  [autorun]
  
  open=you_didnt_read_the_brochure_right.exe
  icon=setup.exe,0
  label=My install CD




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: