Electronic cancer: E-cigarettes can be used to spread malware and hijack PCs
The use of the increasingly popular smoking alternative e-cigarettes may be 95 percent safer than smoking a traditional cigarette, but they may not be so safe for your computers, according to two new demonstrated proofs-of-concept.
The first comes from security researcher Ross Bevington, who demonstrated at a recent convention how an e-cigarette could be easily used to attack a computer by either interfering with its network traffic or fooling the machine into thinking the vape is a keyboard or mouse. The demonstration required a victim’s machine to be unlocked, but Bevington told Sky News that was not the case for all attacks. He noted that PoisonTap, a form of malware that is freely available, could be used in an e-cigarette and would work with locked personal computers.
The second e-cig hacking possibility comes from a security engineer and malware researcher by the name of FourOctets, who recently posted a 22-second proof-of-concept video. It showed a modified vape pen hijacking and running code on a Windows laptop it had been plugged into. FourOctets’ method was more complicated. as he told Sky that he had modified the vape pen by adding a hardware chip which allowed the device to communicate with the laptop.
Sorry if I get vape pens banned at your work place…… pic.twitter.com/VYhIIvyDEx
— ㅤ (@fouroctets) May 25, 2017
For those not familiar with e-cigarettes, they are charged via a standard USB cable, meaning that they can be plugged into a power socket or a USB slot on any computer. Although e-cigarettes don’t always come with complicated electronics, some do include built-in chips and basic storage, meaning that, like a USB stick, they can be used as an attack vector.
The good news is that both FourOctets and Bevington only showed proofs-of-concept. That means there are no examples of e-cigarettes being used to hack computers yet in the wild. But now that it’s possible, it’s only a matter of time until malicious hackers start using them to give smokers an electronic form of cancer.
Photo: Vaping360.com
Since you’re here …
… We’d like to tell you about our mission and how you can help us fulfill it. SiliconANGLE Media Inc.’s business model is based on the intrinsic value of the content, not advertising. Unlike many online publications, we don’t have a paywall or run banner advertising, because we want to keep our journalism open, without influence or the need to chase traffic.The journalism, reporting and commentary on SiliconANGLE — along with live, unscripted video from our Silicon Valley studio and globe-trotting video teams at theCUBE — take a lot of hard work, time and money. Keeping the quality high requires the support of sponsors who are aligned with our vision of ad-free journalism content.
If you like the reporting, video interviews and other ad-free content here, please take a moment to check out a sample of the video content supported by our sponsors, tweet your support, and keep coming back to SiliconANGLE.