Software Safeguards Coming to Protect Against Potentially Dangerous USB-C Cables - MacRumors
Skip to Content

Software Safeguards Coming to Protect Against Potentially Dangerous USB-C Cables

by

The USB Implementers Forum (USB-IF) today announced the launch of the USB Type-C Authentication specification, a software protocol that will serve as a line of defense protecting USB-C products from non-compliant USB-C cables that are potentially able to damage a device.

With the USB Type-C Authentication specification, computers and other devices with USB-C ports will be able to confirm the authenticity of a USB device or USB charger, verifying elements like certification status and power flow, along with ensuring no malware is present.

Retina-MacBook-USB-C

Using this protocol, host systems can confirm the authenticity of a USB device or USB charger, including such product aspects as the descriptors/capabilities and certification status. All of this happens right at the moment a wired connection is made - before inappropriate power or data can be transferred.

USB Type-C Authentication empowers host systems to protect against non-compliant USB Chargers and to mitigate risks from maliciously embedded hardware or software in USB devices attempting to exploit a USB connection

The USB Type-C Authentication specification comes after some non-compliant USB-C cables were able to damage electronic devices. Google engineer Benson Leung spent weeks testing USB-C cables sold by Amazon after a third-party cable he bought destroyed his Chromebook Pixel, making it his mission to highlight the risks of non-compliant cables.

Leung's work led Amazon to ban third-party retailers from offering USB-C cables that do not adhere to the standard specifications issued by the USB-IF, and it's also led to the creation of the protections announced today.

Key characteristics of the USB Type-CTM Authentication solution include:

- A standard protocol for authenticating certified USB Type-CTM Chargers, devices, cables and power sources
- Support for authenticating over either USB data bus or USB Power Delivery communications channels
- Products that use the authentication protocol retain control over the security policies to be implemented and enforced
- Relies on 128-bit security for all cryptographic methods
- Specification references existing internationally-accepted cryptographic methods for certificate format, digital signing, hash and random number generation

Apple began using USB-C with the Retina MacBook, choosing the standard because it allows both data and power transfer through a single connector. USB-C is appealing for its universality, but because USB-C cables can transfer more power than traditional USB connectors, non-compliant or faulty equipment can damage electronic devices by providing too much power.

The Retina MacBook already has safeguards built in to protect it from non-compliant cables, but the new USB Type-C Authentication feature will offer another layer of protection should Apple choose to implement it. Current machines will only charge from third-party USB-C power adapters if they comply with the USB Power Delivery specification, and if too much power is detected, the USB-C ports on the MacBook will shut down.

While the Retina MacBook is the only product that currently offers USB-C functionality, Apple may choose to offer USB-C ports in additional machines in upcoming updates scheduled to take place across 2016.

Top Rated Comments

133 months ago
A problem that only exists because companies insist on combining charging cables and data cables into one.

Reminds me the story of the space pen. NASA realized that regular ballpoint pens don't work in zero gravity, so they spent some enormous amount of resources on R&D to design a pressurized ink cartridge that can write upside down and in zero gravity, what we call the space pen. The Russians just used a pencil.

Sometimes the simplest solution is the best one. Dedicated power port. Done.
http://www.snopes.com/business/genius/spacepen.asp
Score: 11 Votes (Like | Disagree)
CarlJ Avatar
133 months ago
Reminds me the story of the space pen. NASA realized that regular ballpoint pens don't work in zero gravity, so they spent some enormous amount of resources on R&D to design a pressurized ink cartridge that can write upside down and in zero gravity, what we call the space pen. The Russians just used a pencil.
Aside from this story being known to be false (someone already provided the snopes link, Fisher paid for the development themselves, so no tax dollars were harmed), a pencil is a terrible idea in space - you'll invariably end up with random bits of graphite (if not also sharpener shavings and eraser dross) floating around the capsule, getting into places where they ought not to be - especially troubling given that graphite is electrically conductive and could damage, you know, those electronic circuits you're depending on for life support, navigation, landing, and other such mundane activities.

This suggests a quote that isn't fake:

"For every complex problem there is an answer that is clear, simple, and wrong." -- H. L. Mencken
Score: 7 Votes (Like | Disagree)
133 months ago
Yes I know the story is not literally true. That doesn't mean it's not a nice and colorful anecdote to go along with the idea that the simplest solution is sometimes the best one.
It would be if it weren't the case that, in the story you shared, the simplest solution was not the best one.
Score: 6 Votes (Like | Disagree)
133 months ago
A problem that only exists because companies insist on combining charging cables and data cables into one.

Sometimes the simplest solution is the best one. Dedicated power port. Done.
Would you advocate that solution for smartphones as well?

Before non-Apple (smart)phones switched to some version of USB (and even then it took a while until micro USB emerged as a standard), the plethora of different charging plugs and parameters for phones were a royal pain, in regard to not being able to use other people's chargers and in perfectly good chargers ending up in landfills when one bought a new phone which came with a different type of charger. Standardisation of chargers then coincided with the need to transfer large-ish amounts of data to phones and that locked in the combination of data and charging in one port.
Score: 3 Votes (Like | Disagree)
You are the One Avatar
133 months ago
Do you take the RED cable or the BLUE cable?

Score: 3 Votes (Like | Disagree)
stiligFox Avatar
133 months ago
...the USB-C ports on the MacBook will shut down.
I wish...
Score: 2 Votes (Like | Disagree)

Popular Stories

Apple Logo Spotlight

Apple Just Increased Prices on MacBooks, iPads, and More

Thursday June 25, 2026 5:44 am PDT by
Apple today dramatically increased device prices across multiple product lines. Subscribe to the MacRumors YouTube channel for more videos. After temporarily taking it down earlier today, Apple's online store is back up with a series of product price increases. The changes are as follows: HomePod mini: $129, up from $99 (+$30) HomePod: $349, up from $299 (+$50) Apple TV: $199, up from...
Apple Up Arrow Fearture

Apple Explains Why It Raised Prices on 14 Products Today

Thursday June 25, 2026 10:42 am PDT by
Apple today raised prices on many of its products, including all Macs and iPads, as well as the Apple TV, HomePod, HomePod mini, and Vision Pro. We shared a list of the price increases, which range from $30 for the HomePod mini to up to $1,300 for the Mac Studio. iPhone, Apple Watch, and AirPods prices have not changed, at least for now. In a statement shared with MacRumors, Apple said it...
Apple Event Logo

Apple to Release These 20 New Products Across Rest of 2026 and 2027

Sunday June 21, 2026 7:42 am PDT by
Apple's annual WWDC developers conference is in the rearview mirror, but there is still a lot to look forward to over the next year and beyond. In his Power On newsletter today, Bloomberg's Mark Gurman listed around 20 products that he expects Apple to release across the remainder of 2026 and 2027. Now that the more intelligent and personal version of Siri has finally arrived in beta, a...