TechBooky AI Assistant
TechBooky AI Assistant
👋 Welcome to TechBooky AI Assistant

I can help with:
🔎 Tech News
🤖 AI Topics
💻 Gadgets
☁️ Cloud
✍️ Guest Posts
📢 Advertising
🔗 Backlinks
📩 Newsletter
  • AI Search
  • Cryptocurrency
  • Earnings
  • Enterprise
  • About TechBooky
  • Submit Article
  • Advertise With TechBooky
  • Contact Us
TechBooky
  • African
  • AI
  • Metaverse
  • Gadgets
Generic selectors
Exact matches only
Search in title
Search in content
Post Type Selectors
Search in posts
Search in pages
  • African
  • AI
  • Metaverse
  • Gadgets
Generic selectors
Exact matches only
Search in title
Search in content
Post Type Selectors
Search in posts
Search in pages
TechBooky
Generic selectors
Exact matches only
Search in title
Search in content
Post Type Selectors
Search in posts
Search in pages
Home Research/How to do it

Why the Security of USB Is Fundamentally Broken

Paul Balo by Paul Balo
July 31, 2014
in Research/How to do it, Security
Share on FacebookShare on Twitter
Share this story

Send it to someone who should read it.

f Facebook X X in LinkedIn wa WhatsApp tg Telegram @ Email
In Brief
  • Sharing USB drives pose a notable risk for malware infection that persists despite antivirus scans and occasional reformatting.
  • This is attributed not just to the files a device might carry, but the very design and operational architecture of USB technology.
  • Security researchers Karsten Nohl and Jakob Lell provided alarming evidence to this effect, revealing the inherent flaws in USB security through their study.

Sharing USB drives pose a notable risk for malware infection that persists despite antivirus scans and occasional reformatting. This is attributed not just to the files a device might carry, but the very design and operational architecture of USB technology.

Security researchers Karsten Nohl and Jakob Lell provided alarming evidence to this effect, revealing the inherent flaws in USB security through their study. They introduced a proof-of-concept malware, BadUSB, that once housed in a USB device, could compromise PCs, subtly alter files, or tamper with internet traffic. Uniquely, this malware resides not in the device’s storage, but in the firmware that governs essential functions and can endure even when it appears that all data has been removed. Nohl and Lell warn that prevention of such a breach is almost impossible without strictly avoiding USB sharing or physically barricading the ports.

The implications of this problem are profound as they cannot be patched. USB design is being exploited in this process, making it necessary to consider USBs as compromised and disposable on interfacing with an unsecure computer.

Nohl and Lell’s research highlights the core issue: the firmware found in all USBs can harbour malicious code. This vulnerability is not restricted just to thumb drives but spans all devices using USB technology, from keyboards to smartphones.

Maintaining the integrity of USB firmware is a tough task due to the lack of ‘code-signing’ measures which validate incoming code as original from the device’s manufacturer. Without such measures and without true firmware for comparison, USB security becomes a challenge.

Also worth reading
Cyera Buys Oasis Security For $1B As AI Agents Create New Identity Risks Microsoft Launches MAI-Cyber-1-Flash As AI Security Becomes A Model Race Mirage Kitten Malware Shows Cyber-Espionage Pressure Across Africa And MEA Anthropic Says Claude Models Breached Real Systems During Cyber Tests Lesotho Launches National CSIRT As Cybersecurity Becomes Core Digital Infrastructure OpenAI Says Rogue Agent Also Breached Other Services After Hugging Face Incident

Nohl and Lell’s studies made it clear that secure usage of USB devices is a far-stretched ideal. To Nohl’s mind, the only practical solution is a paradigm shift in USB usage – avoiding connecting USBs to unknown or insecure computers and not introducing unfamiliar USB devices into your own system – thus undermining the essential utility of these versatile, omnipresent devices.

Recognizing this threat is the first step. The next step is to actualize this new security model, which would necessitate convincing device manufacturers of its urgency. If not, Nohl suggests treating USB devices with extreme caution – rendering them unshareable and reversing their innate convenience.

Updated in 2025 to align with recent developments.

Related Reading

More contextual TechBooky stories selected from tags, categories and article context.

  • blog-a-lurking-npm-package
    Malicious npm Package Compromises WhatsApp Accounts
  • claude code1
    Leaked & Exploited Claude Code Distributes…
  • ORJAL4DYNFOR3K2HJT2YITAO6Q
    Meta Warns of WhatsApp Security Threat
  • handala hackers
    FBI Warns of Handala Hackers Using Telegram for Malware
  • Microsoft Teams
    Microsoft Teams Vulnerability Exposes User Systems
  • Chinaflag_computercode_MykhailoPolenok-AlamyStockPhoto
    New Malware Deployed By Chinese APT To Retain Access…
  • android
    Google Patches 107 Flaws Including 2 Android Zero-Days
  • OpenClaw moltbot AI assistant
    OpenClaw’s Viral Rise Exposes Security Risks in Agentic AI
Keep Reading Smarter

Search TechBooky with AI

Use TechBooky's AI Search to explore the context behind this story and related coverage across the site.

Try AI Search
More On This Topic
Research/How to do it Security
Follow TechBooky

Follow TechBooky for more technology stories and newsroom updates.

f Facebook X X in LinkedIn ig Instagram wa WhatsApp

Paul Balo

Paul Balo

Paul Balo is the founder of TechBooky and a highly skilled wireless communications professional with a strong background in cloud computing, offering extensive experience in designing, implementing, and managing wireless communication systems.

Search TechBooky
Open TechBooky AI Search Try the AI Assistant

BROWSE BY CATEGORIES

Receive top tech news directly in your inbox

subscription from
Loading

Freshly Squeezed

  • Samsung Memory Warning Shows AI Chip Shortage May Last Into 2028 August 1, 2026
  • Siri AI Paywall Would Make Apple Intelligence A Services Business July 31, 2026
  • Mirage Kitten Malware Shows Cyber-Espionage Pressure Across Africa And MEA July 31, 2026
  • Snapchat Stops Paying Fully AI-Generated Spotlight Videos As AI Slop Spreads July 31, 2026
  • Anthropic Says Claude Models Breached Real Systems During Cyber Tests July 31, 2026
  • DeepSeek V4 Flash API Raises The Pressure In The AI Agent Price War July 31, 2026
  • MTN Nigeria Fintech Revenue Slump Shows Airtime Lending Risk July 31, 2026
  • Google Earth AI Image Tool Shows How Fake Satellite Proof Could Spread July 31, 2026
  • Lesotho Launches National CSIRT As Cybersecurity Becomes Core Digital Infrastructure July 31, 2026
  • Gabon Data Centre Push Shows Africa Digital Sovereignty Is Becoming Infrastructure July 31, 2026
  • Inforcer Raises $50M As AI Turns Microsoft 365 Security Into An MSP Problem July 31, 2026
  • Rwanda 3G Shutdown Shows Africa Mobile Money Needs A Careful 4G Migration July 31, 2026

Browse Archives

August 2026
M T W T F S S
 12
3456789
10111213141516
17181920212223
24252627282930
31  
« Jul    

Quick Links

  • About TechBooky
  • Advertise With TechBooky
  • Contact us
  • Submit Article
  • Privacy Policy
Generic selectors
Exact matches only
Search in title
Search in content
Post Type Selectors
Search in posts
Search in pages
  • African
  • Artificial Intelligence
  • Gadgets
  • Metaverse
  • Tips
  • AI Search
  • About TechBooky
  • Advertise With TechBooky
  • Submit Article
  • Contact us

© 2025 Designed By TechBooky Elite

Discover more from TechBooky

Subscribe now to keep reading and get access to the full archive.

Continue reading

We use cookies to ensure that we give you the best experience on our website. If you continue to use this site we will assume that you are happy with it.