Access Card Reader from Amazon with Malware

Fully Compatible with DOD Military USB Common Access Card (CAC)! Download Windows, Mac & Linux drivers from company website!

Still available on Amazon.

3 Likes

I believe some military online services (personnel records, portals, etc.) use CACs for authentication/access purposes from home computers. And they’re used inside military/government facilities for secure access and signing into computers, of course, by military and contractor personnel.

https://nitter.net/briankrebs/status/1526374598236856323

(The referenced tweets, via privacy-friendly Nitter.)

1 Like

I wonder whether it works plug-and-play with any version of any operating system.

If it were me, a device that says that it does not require drivers but doesn’t work plug-and-play would get returned to Amazon. (However at that price, Amazon may well refund you without requiring the device to be returned.)

Here’s your actual product link: https://www.amazon.com/saicoo-Military-Compatible-Horizontal-Version/dp/B0177O5XNA (but DON’T BUY unless you are prepared to contend with malware)

I wonder how many US government employees and contractors are currently compromised by this. I would think that the US government needs to start auditing that urgently.

1 Like

One would be too many.

…and potentially infect any military/government systems you’re authorized to connect to with data-exfiltrating malware.

You’d think we would have learned from the massive OPM data breach, among many, many others.

P.S. Someone posted the Ramnit html bits in this tweet: https://nitter.net/pic/media%2FFS7otQAUsAITKkW.png%3Fname%3Dorig

Back in the day, I was issued a CAC card reader for home use.

When I retired, I had to turn it in. Just like a weapon. (About 17 years ago.)

2 Likes