Anker Charger, 65W 3-Port Fast Compact Foldable USB C Charger Block for MacBook Pro/Air, iPad Pro, Galaxy S20, Dell XPS 13, Note 20/10+, iPhone 17 Series, Steam Deck, and More.
This collaborative space allows users to contribute additional information, tips, and insights to enhance the original deal post. Feel free to share your knowledge and help fellow shoppers make informed decisions.
Anker Charger, 65W 3-Port Fast Compact Foldable USB C Charger Block for MacBook Pro/Air, iPad Pro, Galaxy S20, Dell XPS 13, Note 20/10+, iPhone 17 Series, Steam Deck, and More.
It's actually pretty simple. Older Android and iPhone devices can be compromised directly through USB or other vulnerabilities. On newer devices, if the user accidentally grants the charger/device permissions, the phone can potentially be compromised as well.
The most straightforward approach would be to exfiltrate the device's data to a CCP-controlled server after gaining access. A more sophisticated approach could involve using the granted permissions to emulate an external keyboard or mouse and navigate to a specified URL. The server could then fingerprint the device model and OS version and dynamically determine what to do next.
It's actually pretty simple. Older Android and iPhone devices can be compromised directly through USB or other vulnerabilities. On newer devices, if the user accidentally grants the charger/device permissions, the phone can potentially be compromised as well.The most straightforward approach would be to exfiltrate the device's data to a CCP-controlled server after gaining access. A more sophisticated approach could involve using the granted permissions to emulate an external keyboard or mouse and navigate to a specified URL. The server could then fingerprint the device model and OS version and dynamically determine what to do next.
You are supposed to wear the tinfoil not smoke it.
You are supposed to wear the tinfoil not smoke it.
You don't know about something just because you haven't encountered it. That doesn't mean it doesn't exist.
If you have an iPhone with a USB-C port, there's actually a very simple way to test your charger. Turn on Lockdown Mode in iOS. On most models, under Privacy & Security, the "Wired Accessories" setting will automatically switch to "Always Ask." Then connect your charger.
I've found that some Chinese-made chargers will trigger a prompt asking whether you trust the connected device. That means the charger is doing something beyond simply supplying power. Of course, that doesn't automatically mean the charger is malicious but an ordinary user has no way to detect whether that is benign or malicious.
I've tested this myself: Apple's own chargers don't trigger the prompt, and neither do Meta Oculus chargers. I've also seen reports that Samsung S20 chargers don't trigger it, although I haven't personally tested it.
And remember to turn Lockdown Mode off after testing. It's a very restrictive security mode and can cause many apps and services to behave abnormally.
1
Like
Helpful
Funny
Not helpful
Join The Conversation
Share your experience with the Slickdeals community
Share information with the community. Please follow our Community Guidelines and be kind!
Join The Conversation
Share your experience with the Slickdeals community
Share information with the community. Please follow our Community Guidelines and be kind!
5 Comments
Sign up for a Slickdeals account to remove this ad.
The most straightforward approach would be to exfiltrate the device's data to a CCP-controlled server after gaining access. A more sophisticated approach could involve using the granted permissions to emulate an external keyboard or mouse and navigate to a specified URL. The server could then fingerprint the device model and OS version and dynamically determine what to do next.
If you have an iPhone with a USB-C port, there's actually a very simple way to test your charger. Turn on Lockdown Mode in iOS. On most models, under Privacy & Security, the "Wired Accessories" setting will automatically switch to "Always Ask." Then connect your charger.
I've found that some Chinese-made chargers will trigger a prompt asking whether you trust the connected device. That means the charger is doing something beyond simply supplying power. Of course, that doesn't automatically mean the charger is malicious but an ordinary user has no way to detect whether that is benign or malicious.
I've tested this myself: Apple's own chargers don't trigger the prompt, and neither do Meta Oculus chargers. I've also seen reports that Samsung S20 chargers don't trigger it, although I haven't personally tested it.
And remember to turn Lockdown Mode off after testing. It's a very restrictive security mode and can cause many apps and services to behave abnormally.
Join The Conversation
Share your experience with the Slickdeals community
Share information with the community. Please follow our Community Guidelines and be kind!