Slashdot Mirror


USB Type-C Authentication Program Launched (newatlas.com)

With the arrival of USB-C a few years back, plugging into laptops, tablets and smartphones became even easier than before. But there are potential security risks. The USB Type-C Authentication Program launched today aims to address such issues. From a report: The new protocol from the USB Implementers Forum (USB-IF) can be used to validate the authenticity of a cable, charger or hardware at the moment of connection, and stop attacks in their tracks. The USB-IF has chosen DigiCert to operate registrations and certificate authority services for the new specification, which makes use of 128-bit cryptographic-based authentication for certificate format, digital signing, hash and random number generation.

"USB Type-C Authentication gives OEMs the opportunity to use certificates that enable host systems to confirm the authenticity of a USB device or USB charger, including such product aspects as the descriptors, capabilities and certification status," said DigiCert in a press release. "This protects against potential damage from non-compliant USB chargers and the risks from maliciously embedded hardware or software in devices attempting to exploit a USB connection."

7 of 133 comments (clear)

  1. Lovely. by Anonymous Coward · · Score: 5, Insightful

    So this is going to enable Apple and their ilk to even more aggressively force people to buy their own craptastic cables.
    Good intentions, but I know exactly how this will be used.

    Mark my words, it will be used to oppress the user, not protect them.

  2. Authorized Devices Indeed by Mia+Yuuki · · Score: 5, Insightful

    I can see it now. I am sorry, the certificate on your charging cables does not match the approved list on the phone and thus you need to order a new charging cable from the vendor. Oh, and if you persist in trying to use the non-approved cable from Amazon, we will be forced to void your warranty. Remember kids, only use Vendor OEM USB Devices. Everyone else is just a crook.

    1. Re:Authorized Devices Indeed by Anonymous Coward · · Score: 5, Insightful

      Worse: "The certificate for your otherwise authorized power supply has now expired."

    2. Re:Authorized Devices Indeed by mysidia · · Score: 4, Insightful

      On the other hand it can be used to prevent that rogue USB flash drive you found on the parking lot from installing a key logger in your computer.

      Not at all. That Rogue USB flash drive will still be able to contain installable malware. Nothing about the authentication standard changes that.

    3. Re:Authorized Devices Indeed by sexconker · · Score: 4, Insightful

      Devices were putting themselves in danger by not having basic electrical protection on the ports. In 90s, this was such a common (and commonly solved) problem that the Tawainese motherboard manufacturers listed all sorts of per-USB-port short, over voltage, over current, etc. protections on the box.

      It became a problem again with USB 3 because the first players to the market with USB controllers didn't learn their lesson from the USB 1.0/1.1 days. There's absolutely no reason a bad USB cable should be able to kill an entire device. At worst, it should kill a single port. Ideally, it would have a replaceable/resettable fuse so you don't even lose the port.

  3. This is all Apple was waiting for... by FrankSchwab · · Score: 4, Interesting

    ...to transition from Lightning to USB-C. They had to have a way to maintain their revenue from selling $20 cables, and licensing the ability to sell authorized cables. I don't know how many lightning cables I've thrown away because they worked for three months, then Apple updated IOS and blocked them.

    Now I'll have to buy Apple USB-C cable, and HP USB-C cables, and Lenovo USB-C cables, and Nikon USB cables, and Microsoft USB cables. And, with OEMs promiscuously relabeling each others products, I'll never know which cable to use with which devices.

    They've re-invented the RS-232 connection nightmares, but without the ability to carry a bag of dongles that might straighten things out. And so dies USB as the most successful cabling and protocol standard in technology history.

    --
    And the worms ate into his brain.
    1. Re:This is all Apple was waiting for... by DontBeAMoran · · Score: 4, Interesting

      Do you really think Apple will be the only one to abuse this DRM-inside-the-cable bullshit?

      --
      #DeleteFacebook