84
you are viewing a single comment's thread
view the rest of the comments
view the rest of the comments
this post was submitted on 29 Dec 2023
84 points (98.8% liked)
Asklemmy
43982 readers
652 users here now
A loosely moderated place to ask open-ended questions
Search asklemmy ๐
If your post meets the following criteria, it's welcome here!
- Open-ended question
- Not offensive: at this point, we do not have the bandwidth to moderate overtly political discussions. Assume best intent and be excellent to each other.
- Not regarding using or support for Lemmy: context, see the list of support communities and tools for finding communities below
- Not ad nauseam inducing: please make sure it is a question that would be new to most members
- An actual topic of discussion
Looking for support?
Looking for a community?
- Lemmyverse: community search
- sub.rehab: maps old subreddits to fediverse options, marks official as such
- !lemmy411@lemmy.ca: a community for finding communities
~Icon~ ~by~ ~@Double_A@discuss.tchncs.de~
founded 5 years ago
MODERATORS
Firstly, never stick a storage drive into your personal machine that was previously owned by an individual. If you need to use the drive always open it on a machine disconnected from the Internet that contains no personal files. Better would be to boot up a live Linux machine and read the drive and format if needed.
Autorun doesn't exist anymore.
As long as you don't open any executables, you'll be fine.
What's the chance that the seller has a 0day (which would be veeery valuable) and is using it to steal data from someone random? Not worth it for sure on their side.
While autorun doesn't exist anymore, there's many many other methods of attack via usb.
Here's a list with 10 seconds of searching:
https://www.bleepingcomputer.com/news/security/heres-a-list-of-29-different-types-of-usb-attacks/
It's entirely possible this drive was made maliciously to pass on data from whatever unsuspecting soul uses it. The seller op bought from could even be a victim themselves. You just never know.
We're talking about an sd card here. The absolute majority of these attacks only work with USB drives.
And the rest either don't make sense or make use of a 0day, which, as I've already said, is inconceivable
How do you read a SD card? I usually put it in my SD card reader which is USB.
The SD card is still speaking SD protocol, the card reader bridges between USB and SD.
This only works with USB sticks because they're plugged on directly over USB and you don't know whether it'll present itself as a storage device or as a keyboard that immediately starts typing stuff and running a bunch of commands.
The risk is not the flash storage part, it's the USB interface.
But I don't think OP is saying the package came with an sd card reader as well that they used