Exactly as a water leak from pipes occurs, so do the electrical signals from USB ports, indirectly exposing sensitive data to a seasoned intruder, according to new research by scientists at the University of Adelaide in Australia.

The phenomenon is known as «channel-to-channel conversation leakage» (channel-to-channel crosstalk leakage) and affects USΒ devices that are connected to adjacent ports.
"Electricity flows like water in pipes and can leak," said project leader Dr. Yuval Yarom. "In our work, we showed that voltage fluctuations on the USB port data lines can be controlled by neighboring ports on the USB."
This scenario assumes the existence of a malicious USB device that has been connected to a nearby port. The attacker can use this device to monitor the data flow of neighboring ports.
Researchers say an attacker could collect this data and use an Internet to send it to the attacker's server. Anything that passes in an unencrypted form through nearby USB ports can be collected.
For the practical side of their research, the scientists used a modified USB light bulb to record every keystroke on a nearby USB keyboard, then sent the data to another computer via Bluetooth.
Furthermore, conducting a USB attack via channel-to-channel crosstalk leakage is not as complicated as many of our readers would think. It has been proven in many studies that users in general have the habit of accepting random USB drives and installing them on personal or corporate computers without considering the security implications.
«The main message of our study is that users should not connect anything to USB if they cannot fully trust it,» is the researchers' conclusion, and we fully embrace it at secnews.
The full research is not yet publicly announced, but it will be presented under the title «USB Snooping Made Easy: Crosstalk Leakage Attacks on USB Hubs» next week at the USENIX Security Symposium in Canada.
