BowTiedIguana Profile picture
May 5 12 tweets 3 min read Twitter logo Read on Twitter
Imagine this: you find a lost USB stick labeled "My Bitcoin Wallet."

Temptation kicks in, and you plug it into your device. Little do you know, you've just become a victim of USB malware or a #BadUSB attack. Let's dive into this frightening world of malicious USB devices! 💀🔌
USB malware isn't new. In the wild, we've seen cases like Stuxnet (2010) & Flame (2012), where USB devices were used to infiltrate & disrupt systems. Such attacks exploit the ubiquitous nature of USBs & users' tendency to trust them. We need to be more vigilant than ever!
BadUSB is an advanced form of USB malware, exploiting the programmable nature of USB devices' firmware. By modifying the firmware, attackers can make a seemingly innocuous USB device into a malicious one that can bypass security measures & execute evil tasks to steal your coins.
One example is the infamous #RubberDucky. Disguised as an ordinary USB flash drive, it's actually a keystroke injection tool that can execute scripted payloads as soon as it's plugged in. It can steal passwords, drop malware, and more—all within seconds!
Consequences of USB malware & BadUSB attacks are dire. They can lead to data theft, unauthorized access, malware installation, and even complete system compromise. In some cases, organizations have experienced long-lasting damage to their reputation & finances.
A famous case of USB malware was the #Stuxnet worm, which targeted Iranian nuclear facilities. It spread via USB sticks, eventually causing severe damage to centrifuges & setting back Iran's nuclear program by years. This demonstrated the power & potential of USB-based attacks.
Another example is #Flame, a sophisticated cyber espionage tool, which spread through USB devices. It targeted Middle Eastern countries, stealing sensitive data & recording conversations. The level of complexity seen in Flame was unprecedented at the time.
Now, let's talk about protection. LizardOS is an operating system that isolates tasks into separate virtual machines (VMs) to minimize damage in case of a breach. It can provide an effective defense against BadUSB attacks!
When you connect a USB device to a LizardOS machine, it's automatically assigned to a dedicated USB VM. This VM isolates USB devices from other VMs, thus preventing the spread of malicious payloads. YOU can decide which VMs can access a USB device & when, reducing attack surface
To maximize protection, it's essential to maintain good security hygiene. Avoid plugging unknown USB devices into your machine, and if you must, use a secure environment like LizardOS to minimize risks.

What if you have to plug your USB device into an untrusted PC? Risky, unless
You use a USB device with secure firmware which can't be modified if you plug it into an infected machine. We use the Kangaru FlashTrust Secure Firmware USB drives kanguru.com/products/kangu…
USB malware and "bad USB" attacks are real threats. Keep this in mind whenever interacting with any USB devices, including public USB charging stations!

Follow me and check out my Twitter bio for more tips on how to protect yourself from cyber attacks.

• • •

Missing some Tweet in this thread? You can try to force a refresh
 

Keep Current with BowTiedIguana

BowTiedIguana Profile picture

Stay in touch and get notified when new unrolls are available from this author!

Read all threads

This Thread may be Removed Anytime!

PDF

Twitter may remove this content at anytime! Save it as PDF for later use!

Try unrolling a thread yourself!

how to unroll video
  1. Follow @ThreadReaderApp to mention us!

  2. From a Twitter thread mention us with a keyword "unroll"
@threadreaderapp unroll

Practice here first or read more on our help page!

More from @BowTiedIguana

May 9
If you're a developer working in crypto, you might be interested in LizardOS - a custom configuration of the security-centric Qubes OS, providing an "out-of-the-box" experience with pre-installed programs and sane default settings.

Find out why and what other devs are saying 🧵
Default apps include web browsers, communication & social apps, media players, document tools, and more. It also comes with a preconfigured VPN

Installation took a few hours, with clear and concise instructions. Expect a learning curve if you're coming from a Windows background
Pros:

* Improved security & anonymity
* Facilitates clean workflows
* Saves time vs. raw Qubes
* Extensive custom documentation
Read 4 tweets
Feb 16
Wondering what happened in the crypto markets over the last few days?

Why are we rallying when there's nothing but bad news?

And how to profit from these conditions?

A quick thread 👇

One of the most consistent ways I've found to make money in crypto is fading bad news during *good* market conditions.

(you don't want to be long in a bear market - this news strategy worked during the last bull market and since the November 2022 bottom)
Why does it work?

Bad news (or the potential for bad news to occur) is often priced in.

Markets are reflexive. If price does down, people assume it's because of the bad news. They sell. Causing price to go down further.

You can be paid to hold risk that other people don't want
Read 10 tweets
Feb 5
Crypto hardware wallets like Ledger and Tezor are great security for *most* people.

But. They are terrible for travelers, even a security risk!

Being found with a wallet marks you as a crypto holder who could be robbed or kidnapped for your digital assets.

What should you do? Image
You could use an airgapped computer and split signing instead

Let's talk about how this would work.

An airgapped computer is often used for sensitive tasks, such as handling private keys for crypto wallets or storing classified information.

It doesn't ever connect to the 'net
You can use a device like a Raspberry Pi for your airgapped computer . Like a hardware wallet, it is cheap, small and easy to set up.

It looks like this (top right) Image
Read 7 tweets
Feb 5
If your bank blocks payments from crypto exchanges, you may want to consider @bisq_network

Bisq is a peer-to-peer exchange that allows you to buy and sell crypto without having to go through a centralized entity like a bank.

Learn more 👇
Peer to peer means that your transactions occur directly between you and the person you're trading with.

This reduces the risk of your bank blocking your transactions, as it doesn't know they're crypto related.
Bisq offers a secure and decentralized platform to trade Bitcoin for a wide range of fiat currencies: USD, EUR, CAD, GBP, AUD, and JPY.

You can choose between wire transfers and Zelle for USD, SEPA payments and Revlout for EUR, etc.
Read 9 tweets
Feb 5
I daren't think of music too much before retirement or I'll never get there (passion is a weird thing), but another few favorites...
Beethoven's Piano Sonata No. 13 in E-flat major, Op. 27, No. 1 2nd mvt "Andante" is a very introspective and expressive piece, you can hear the left hand play legato while the right places stacatto, and the rhythm of the horses, glorious recapitulation
Don't forget he wrote NINE symphonies!

The fifth is probably the best known, but consider the moody second movement of the seventh
Read 4 tweets
Feb 5
1/ If you're need to keep your identity private online
(that's all of us 'toons)

...here are some tips to help you stay anon:
2/ Avoid using a ‘handle’ or pseudonym that you’ve used before, or that people would associate with you.

Becoming a BowTied Animal is a good choice.

Avoid using personal information that can be easily linked to you. This takes some thought.
3/ Use encrypted messaging apps for communication, such as Signal or XMPP with OTR / OMEMO.

You could use Protonmail with PGP for email, but be aware your subject lines will still be plaintext.

Be aware of metadata: who you talk to is just as important as what you talk about.
Read 9 tweets

Did Thread Reader help you today?

Support us! We are indie developers!


This site is made by just two indie developers on a laptop doing marketing, support and development! Read more about the story.

Become a Premium Member ($3/month or $30/year) and get exclusive features!

Become Premium

Don't want to be a Premium member but still want to support us?

Make a small donation by buying us coffee ($5) or help with server cost ($10)

Donate via Paypal

Or Donate anonymously using crypto!

Ethereum

0xfe58350B80634f60Fa6Dc149a72b4DFbc17D341E copy

Bitcoin

3ATGMxNzCUFzxpMCHL5sWSt4DVtS8UqXpi copy

Thank you for your support!

Follow Us on Twitter!

:(