Firewalls Don't Stop Dragons Podcast

Firewalls Don't Stop Dragons Podcast


How to Avoid Juice Jacking

April 24, 2023

Our smartphones have become indispensable tools for our daily lives – so seeing that dreaded red battery indicator can induce some serious anxiety. But before you jack your phone into some public USB charging port, think twice. Those USB connections can pass data as well as power, and it’s actually possible to hack your phone using those ubiquitous and innocent-looking ports. Is this common? Probably not. But it’s also very easy to avoid. I’ll give you several tips for staying safe, particularly while traveling.


In other news: Mullvad VPN was subjected to a search warrant (but had no data to give up); Proton has announced that it has created a password manager; YubiCo is merging with another company and going public; Facebook probably owes you some money; Apple HomePods can tell you if your house is on fire; one of several Israeli spyware makers is shutting down; the US and several partner countries are urging device makers to adopt Security by Design principles; hackers use fake Chrome updates to install malware; the much-hyped Florida water treatment plant hack wasn’t really a hack; clever thieves are stealing modern cars through headlamp connectors; and health care portal check-in vendors are tricking patients into allowing them to monetize very sensitive health data.


Article Links
  1. [mullvad.net] Mullvad VPN was subject to a search warrant. Customer data not compromised https://mullvad.net/en/blog/2023/4/20/mullvad-vpn-was-subject-to-a-search-warrant-customer-data-not-compromised/
  2. [proton.me] Proton Pass is now in beta https://proton.me/blog/proton-pass-beta
  3. [yubico.com] Yubico is merging with ACQ Bure: merged company intends to go public on Nasdaq First North Growth Market in Stockholm https://www.yubico.com/blog/yubico-is-merging-with-acq-bure/
  4. [Lifehacker] Facebook Probably Owes You Money https://lifehacker.com/facebook-probably-owes-you-money-1850350640
  5. [MacRumors] HomePod Can Now Alert You If Your Smoke Alarm Goes Off https://www.macrumors.com/2023/04/18/homepod-alert-smoke-alarm/
  6. [The Hacker News] Israeli Spyware Vendor QuaDream to Shut Down Following Citizen Lab and Microsoft Expose https://thehackernews.com/2023/04/israeli-spyware-vendor-quadream-to-shut.html
  7. [cisa.gov] U.S. and International Partners Publish Secure-by-Design and -Default Principles and Approaches    https://www.cisa.gov/news-events/news/us-and-international-partners-publish-secure-design-and-default-principles-and-approaches
  8. [Tom’s Guide] Hackers are using fake Chrome updates to spread malware — don’t fall for this https://www.tomsguide.com/news/hackers-are-using-fake-chrome-updates-to-spread-malware-dont-fall-for-this
  9.  [VICE] Much-Hyped Water Plant Hack Wasn’t a Hack, Was Actually User Error, Official Says https://www.vice.com/en/article/y3wddv/much-hyped-water-plant-hack-wasnt-a-hack-was-actually-user-error-official-says
  10. [theregister.com] CAN do attitude: How thieves steal cars using network bus https://www.theregister.com/2023/04/06/can_injection_attack_car_theft/
  11. [statnews.com] I declined to share my medical data with advertisers at my doctor’s office. One company claimed otherwise https://www.statnews.com/2023/04/07/medical-data-privacy-phreesia/
  12. Tip of the Week: How to Avoid Juice Jacking https://firewallsdontstopdragons.com/how-to-avoid-juice-jacking/

Further Info

Table of Contents

Use these timestamps to jump to a particular section of the show.


  • 0:01:02: News preview
  • 0:03:03: Mullvad VPN search warrant reveals zero customer data
  • 0:04:57: Proton launching a new password manager
  • 0:06:46: YubiCo merging with ACQ Bure
  • 0:07:41: Facebook may owe you some money
  • 0:12:10: Apple HomePod can now detect smoke alarm alerts
  • 0:15:16: Israeli Spyware Vendor QuaDream to Shut Down
  • 0:20:38: U.S. (et al) Publish Secure-by-Design Principles
  • 0:24:33: Hackers use fake Chrome updates to spread malware
  • 0:31:13: Much-Hyped Water Plant “Hack” Was Actually User Error
  • 0:36:45: Clever thieves steal cars by hacking CAN bus
  • 0:45:24: Unwanted sharing of medical data with advertisers
  • 0:57:48: Tip of the Week: Juice Jacking
  • 1:03:39: Preview of upcoming stuff

loaded