Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

How do we know if these are doing something else?


Fun fact. Any USB-C cable that needs to handle higher wattage than 5V@3A has circuitry that talks on the CC line to let the source know it’s not going to melt.


The threshold is higher than that. Passive USB-C cables can do up to 20V @ 3A (60W). Electronically marked cables are only required for higher power profiles.


To be pedantic, the eMarker is required in a USB 2 cable conducting over 3A, and in any USB 3+ cable.


How do you know for the cables without displays?


The USB-IF publishes a list of member companies[1]; purchase products from these qualified manufacturers, and perhaps more importantly, from authorized distributors.

This is a good enough "policy control" for the average consumer.

[1] https://www.usb.org/members


Erm. I fail to see how this moves the needle unless usb-if is doing extreme firmware level source analysis and deterministic compiles and checking them against shipped firmware. Which I doubt is happening, with every atom in my body.


It's a policy control suggestion that's both low effort and immediately actionable by the typical tech-literate types sleuthing these channels.

When baseline consumer behavior is sort-by-price-low-to-high and select the cheapest item from random pop-up white label chinesium third-party vendor on Amazon, exercising an ounce of supply chain due diligence where none previously existed can go a long way.

To be sure, if you think you can economically defend against a coordinated supply chain attack by a speculative adversary willing to pony up real capital operating an otherwise legitimate facade for years building market goodwill only to burn it all down in one shot against a single worthwhile target...well, I've got a bridge to sell you.


Surprised that Anker isn’t obviously on there.


Unsurprising considering Anker doesn’t pay for basic UL listing for many of their AC power taps.


Also at least some of their products are just ODM rebrands. A bit disappointing but probably shouldn't have been surprised.


It appears Anker Innovations Ltd was last listed[1] circa 2020 under VID 10522 (0x291A).

Tread with caution...the prospects of zombie grift tend to be real when brand recognition is established.

[1] https://usb.org/sites/default/files/vendor_ids051920_0.pdf


USB testers are cheaper now, I'd advise anyone to buy one preemptively.

It's nice to one-off check a new cable to know what it can be used for, with the additional benefit of seeing the power curves for the higher models (e.g. see a charger's power output drastically drop down as it overheats)


Do you have any recommendations?


I'm using a super cheap Ali-express one I checked against well know and stable brands of cable/chargers (e.g. Apple and Anker's power bricks and cables).

Otherwise AVHzY is I think the recommended brand, with two levels or pricing depending if you want external output.


The same way you know whether or not anything is doing something else


ie: you probably don’t.


If power is all you are looking for you can always play it safe with a USB Condom.

e.g https://www.amazon.com.au/s?k=PortaPow


Keep in mind that this will limit you to 5V at 0.5A, if I'm not mistaken.


And realize that if you're distrustful of the cable, you should be even more distrustful of that gadget which has even more space to add malicious parts and you're still unable to check it.


https://mg.lol/blog/data-blocker-teardown/

The normal PortaPow tells the device that it's a charger.

The extra paranoid version with no components on the board will often limit charging, it depends on how the device treats a complete lack of data pins.


Yes, but if you use a data blocker with a microcontroller on it, you've just exchanged one company you need to trust for another.


Not exactly. You now have to trust one entity instead of many, and it's an extremely small chip that can't do much, and the hack would have to be built in at purchase time, and the hack would have to take over your phone to exfiltrate.

But if you're worried then get one that has a resistor and only a resistor.


Aren't all these considerations exactly the same as for the cable with the screen?


It depends on what kind of attack you're trying to block.

If you want to block attacks that use the external data pins, then a USB condom will keep you safe. Regardless of whether it has a chip in it.

If you want to block standalone attacks from a malicious cable, then a USB condom wasn't going to help in the first place. For standalone attacks in particular, the risk from a chip-having condom is similar to the risk from a cable, but a cable can use bigger and scarier chips than the one in the PortaPow.


Assuming you trust that device to not be malicious. It's turtles all the way down.


Minimal Portapow for visual verification, https://www.amazon.com/PortaPow-Pure-USB-Data-Blocker/dp/B07...

  Transparent casing, no-chip design and custom made USB connector with data pins visibly removed means you can be sure the blocker is secure.




Consider applying for YC's Fall 2026 batch! Applications are open till July 27.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: