Thursday, April 3, 2025
HomeComputer SecurityUSB-IF Launches USB Type-C Authentication Program To Protect Against From Malicious Devices

USB-IF Launches USB Type-C Authentication Program To Protect Against From Malicious Devices

Published on

SIEM as a Service

Follow Us on Google News

USB-IF announced USB Type-C Authentication Program to confirm the authencity of the USB device USB device, USB cable or USB charger.

The Authentication program is the milestone for USB security protocol. The authentication program protect against non-compliant USB chargers and to mitigate risks from malicious firmware/hardware in USB devices attempting to exploit a USB connection.

The program aimed in protecting the USB users from security threats. USB devices remains as a top attack vector, around 9% malwares are designed to directly exploit USB protocol or interface weaknesses.

“USB-IF is excited to launch the USB Type-C Authentication Program, providing OEMs with the flexibility to implement a security framework that best fits their specific product requirements,” said USB-IF President and COO Jeff Ravencraft.

The USB-C cables first published in 2014 and it is the replacement of older USB cables. USB Type-C ports supports for a number of protocols and you can use number of adapters such as VGA, DisplayPort, HDMI and other ports.

Important Characteristics of the USB Type-C Authentication

  • A standard protocol for authenticating certified USB Type-C chargers, devices, cables, and power sources.
  • Support for authenticating over either USB data bus or USB Power Delivery communications channels.
  • Products that use the authentication protocol retain control over the security policies to be implemented and enforced.
  • Relies on 128-bit security for all cryptographic methods.
  • Specification references existing internationally-accepted cryptographic methods for certificate format, digital signing, hash, and random number generation.

USB-IF has selected DigiCert Inc to manage the PKI and certificate authority services for the USB Type-C Authentication Program.

The external data storage device, they are prone to certain cyber attacks and corruption. However, they are convenient and, when combined with other safety measures, can be used safely within a business.

You can follow us on LinkedinTwitterFacebook for daily Cybersecurity updates also you can take the Best Cybersecurity courses online to keep your self-updated

Gurubaran
Gurubaran
Gurubaran is a co-founder of Cyber Security News and GBHackers On Security. He has 10+ years of experience as a Security Consultant, Editor, and Analyst in cybersecurity, technology, and communications.

Latest articles

Secure Ideas Achieves CREST Accreditation and CMMC Level 1 Compliance

Secure Ideas, a premier provider of penetration testing and security consulting services, proudly announces...

New Phishing Campaign Targets Investors to Steal Login Credentials

Symantec has recently identified a sophisticated phishing campaign targeting users of Monex Securities (マネックス証券),...

UAC-0219 Hackers Leverage WRECKSTEEL PowerShell Stealer to Extract Data from Computers

In a concerning development, CERT-UA, Ukraine's Computer Emergency Response Team, has reported a series...

Hunters International Linked to Hive Ransomware in Attacks on Windows, Linux, and ESXi Systems

Hunters International, a ransomware group suspected to be a rebrand of the infamous Hive...

Supply Chain Attack Prevention

Free Webinar - Supply Chain Attack Prevention

Recent attacks like Polyfill[.]io show how compromised third-party components become backdoors for hackers. PCI DSS 4.0’s Requirement 6.4.3 mandates stricter browser script controls, while Requirement 12.8 focuses on securing third-party providers.

Join Vivekanand Gopalan (VP of Products – Indusface) and Phani Deepak Akella (VP of Marketing – Indusface) as they break down these compliance requirements and share strategies to protect your applications from supply chain attacks.

Discussion points

Meeting PCI DSS 4.0 mandates.
Blocking malicious components and unauthorized JavaScript execution.
PIdentifying attack surfaces from third-party dependencies.
Preventing man-in-the-browser attacks with proactive monitoring.

More like this

Operation HollowQuill Uses Malicious PDFs to Target Academic and Government Networks

A newly uncovered cyber-espionage campaign, dubbed Operation HollowQuill, has been identified as targeting academic,...

New Trinda Malware Targets Android Devices by Replacing Phone Numbers During Calls

Kaspersky Lab has uncovered a new version of the Triada Trojan, a sophisticated malware...

DarkCloud Stealer Uses Weaponized .TAR Archives to Target Organizations and Steal Passwords

A recent cyberattack campaign leveraging the DarkCloud stealer has been identified, targeting Spanish companies...