July 14, 2022, 11:36 a.m. | /u/chaplin2

cybersecurity www.reddit.com

USB can be used to transfer data from an untrusted system to an offline secure computer. But USB has firmware, usually not signed, and usually without write protection pins. Also, it has various opaque microcontrollers. Vulnerabilities such as BadUSB are used by APT to infect air gapped systems. Formatting a USB doesn’t secure it (sometimes the firmware is stored in a partition that uses a separate data channel that can be accessed only by special devices, not external OS).

What’s …

computers cybersecurity data data transfer medium

SOC 2 Manager, Audit and Certification

@ Deloitte | US and CA Multiple Locations

Security Engineering Professional

@ Nokia | India

Cyber Intelligence Exercise Planner

@ Peraton | Fort Gordon, GA, United States

Technical Lead, HR Systems Security

@ Sun Life | Sun Life Wellesley

SecOps Manager *

@ WTW | Thane, Maharashtra, India

Consultant Appels d'Offres Marketing Digital

@ Numberly | Paris, France