BadUSB is a theoretical exploit that was presented by SR Labs at the Black Hat conference in August 2014. SR Labs demonstrated a vulnerability in one USB device that allowed malicious code to be programmed into the USB controller through a firmware update process.
The attack described is very sophisticated and, in the case of iStorage products, would require advanced knowledge of our USB controller, a leaked version of our firmware, the programming tool to update our controller, the password used for our programming tool and an in-depth understanding of the device’s functionality.
According to SR Labs, the failsafe method to eliminate this threat is to simply disable the ability to update the controller’s firmware. Many of iStorage devices shipping today, including all our USB 3.0 security products, already have the firmware locked which prevents field updates to the USB controller.
As a continuous improvement, iStorage is locking down the firmware on all USB controllers used in iStorage devices to safeguard against this vulnerability. We recommend checking our website periodically for notices regarding BadUSB and Security Updates.