Risks in using USB flash drives and u3

Authors:

  • Löfvenberg Jacob

Publish date: 2006-01-01

Report number: FOI-R--2078--SE

Pages: 8

Written in: Swedish

Abstract

U3 is a new technology used in combination with USB flash drives. It makes it possible to keep applications, data and configurations on the flash drive. When a u3 stick (USB flash drive with u3) is connected to the host computer, a launch program is automatically run, in which the user can run and administrate the applications on the stick. It is also possible to update the launch program when new versions are made available by the manufacturer. Unfortunately, in practice it is easy for anybody do exchange the launch program for anything. The combination of automatic program run and the possibility to exchange the launch program is problematic from a security point of view. An attack can be aimed at the host computer by exchanging the launch program for a program that installs a surveillance program, forwarding sensitive information over the Internet to a suitable receiver. It is also possible to create viruses which spread using u3 sticks, similar to floppy disk viruses. Thus, the security problems with u3 sticks are evident, especially considering how widely used the technology is.