Hacker News new | ask | show | jobs
by iam-TJ 3568 days ago
I think the crux of the issue is that a Windows workstation already authorised on an existing AD domain server will change its default gateway and proxy to the hot-plugged USB Ethernet device but not invalidate the existing credentials so they are captured by the device. Presumably the credentials are transmitted unencrypted.