Fun fact. Any USB-C cable that needs to handle higher wattage than 5V@3A has circuitry that talks on the CC line to let the source know it’s not going to melt.
The threshold is higher than that. Passive USB-C cables can do up to 20V @ 3A (60W). Electronically marked cables are only required for higher power profiles.
The USB-IF publishes a list of member companies[1]; purchase products from these qualified manufacturers, and perhaps more importantly, from authorized distributors.
This is a good enough "policy control" for the average consumer.
Erm. I fail to see how this moves the needle unless usb-if is doing extreme firmware level source analysis and deterministic compiles and checking them against shipped firmware. Which I doubt is happening, with every atom in my body.
It's a policy control suggestion that's both low effort and immediately actionable by the typical tech-literate types sleuthing these channels.
When baseline consumer behavior is sort-by-price-low-to-high and select the cheapest item from random pop-up white label chinesium third-party vendor on Amazon, exercising an ounce of supply chain due diligence where none previously existed can go a long way.
To be sure, if you think you can economically defend against a coordinated supply chain attack by a speculative adversary willing to pony up real capital operating an otherwise legitimate facade for years building market goodwill only to burn it all down in one shot against a single worthwhile target...well, I've got a bridge to sell you.
USB testers are cheaper now, I'd advise anyone to buy one preemptively.
It's nice to one-off check a new cable to know what it can be used for, with the additional benefit of seeing the power curves for the higher models (e.g. see a charger's power output drastically drop down as it overheats)
I'm using a super cheap Ali-express one I checked against well know and stable brands of cable/chargers (e.g. Apple and Anker's power bricks and cables).
Otherwise AVHzY is I think the recommended brand, with two levels or pricing depending if you want external output.
And realize that if you're distrustful of the cable, you should be even more distrustful of that gadget which has even more space to add malicious parts and you're still unable to check it.
The normal PortaPow tells the device that it's a charger.
The extra paranoid version with no components on the board will often limit charging, it depends on how the device treats a complete lack of data pins.
Not exactly. You now have to trust one entity instead of many, and it's an extremely small chip that can't do much, and the hack would have to be built in at purchase time, and the hack would have to take over your phone to exfiltrate.
But if you're worried then get one that has a resistor and only a resistor.
It depends on what kind of attack you're trying to block.
If you want to block attacks that use the external data pins, then a USB condom will keep you safe. Regardless of whether it has a chip in it.
If you want to block standalone attacks from a malicious cable, then a USB condom wasn't going to help in the first place. For standalone attacks in particular, the risk from a chip-having condom is similar to the risk from a cable, but a cable can use bigger and scarier chips than the one in the PortaPow.