UPDATED 22:39 EDT / JUNE 18 2017

INFRA

Electronic cancer: E-cigarettes can be used to spread malware and hijack PCs

The use of the increasingly popular smoking alternative e-cigarettes may be 95 percent safer than smoking a traditional cigarette, but they may not be so safe for your computers, according to two new demonstrated proofs-of-concept.

The first comes from security researcher Ross Bevington, who demonstrated at a recent convention how an e-cigarette could be easily used to attack a computer by either interfering with its network traffic or fooling the machine into thinking the vape is a keyboard or mouse. The demonstration required a victim’s machine to be unlocked, but Bevington told Sky News that was not the case for all attacks. He noted that PoisonTap, a form of malware that is freely available, could be used in an e-cigarette and would work with locked personal computers.

The second e-cig hacking possibility comes from a security engineer and malware researcher by the name of FourOctets, who recently posted a 22-second proof-of-concept video. It showed a modified vape pen hijacking and running code on a Windows laptop it had been plugged into. FourOctets’ method was more complicated. as he told Sky that he had modified the vape pen by adding a hardware chip which allowed the device to communicate with the laptop.

For those not familiar with e-cigarettes, they are charged via a standard USB cable, meaning that they can be plugged into a power socket or a USB slot on any computer. Although e-cigarettes don’t always come with complicated electronics, some do include built-in chips and basic storage, meaning that, like a USB stick, they can be used as an attack vector.

The good news is that both FourOctets and Bevington only showed proofs-of-concept. That means there are no examples of e-cigarettes being used to hack computers yet in the wild. But now that it’s possible, it’s only a matter of time until malicious hackers start using them to give smokers an electronic form of cancer.

Photo: Vaping360.com

A message from John Furrier, co-founder of SiliconANGLE:

Support our mission to keep content open and free by engaging with theCUBE community. Join theCUBE’s Alumni Trust Network, where technology leaders connect, share intelligence and create opportunities.

  • 15M+ viewers of theCUBE videos, powering conversations across AI, cloud, cybersecurity and more
  • 11.4k+ theCUBE alumni — Connect with more than 11,400 tech and business leaders shaping the future through a unique trusted-based network.
About SiliconANGLE Media
SiliconANGLE Media is a recognized leader in digital media innovation, uniting breakthrough technology, strategic insights and real-time audience engagement. As the parent company of SiliconANGLE, theCUBE Network, theCUBE Research, CUBE365, theCUBE AI and theCUBE SuperStudios — with flagship locations in Silicon Valley and the New York Stock Exchange — SiliconANGLE Media operates at the intersection of media, technology and AI.

Founded by tech visionaries John Furrier and Dave Vellante, SiliconANGLE Media has built a dynamic ecosystem of industry-leading digital media brands that reach 15+ million elite tech professionals. Our new proprietary theCUBE AI Video Cloud is breaking ground in audience interaction, leveraging theCUBEai.com neural network to help technology companies make data-driven decisions and stay at the forefront of industry conversations.