Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

PoisonTap did not crack a password. In a 2016 proof of concept, security researcher Samy Kamkar showed how a physically connected device could present itself as an Ethernet adapter and exploit network and browser activity that continued while a computer was locked. The documented chain depended on an exposed port, a running browser making background HTTP requests, and web protections that left some traffic or cookies exposed. It is not evidence that the technique works on every current computer or browser.

What PoisonTap did—and did not—do

Kamkar’s project page, published November 16, 2016, describes PoisonTap as a device that emulates an Ethernet connection over USB or Thunderbolt. Its aim was not to unlock the desktop, read files directly, or guess the user’s password. Instead, it sought to influence network traffic and interact with a browser that was already running. The creator described the device as not requiring the machine to be unlocked.

A lock screen restricts access to the user session, but it does not necessarily stop the computer’s network stack or an active browser from making requests. That distinction is central to the demonstration: PoisonTap targeted background activity available to the locked system, not the password-protected desktop itself. Kamkar’s broad statement that network and USB stacks operate while a machine is locked describes his 2016 demonstration, not a guarantee about every modern system.

How the documented attack chain worked

  1. Connect to an exposed port. The attacker needed physical access to connect the device to a USB or Thunderbolt port. The project says the computer could remain locked.
  2. Present a network interface. PoisonTap emulated Ethernet and answered DHCP with a configuration claiming that the entire IPv4 address space was on its local network. According to the project, this could attract internet-bound traffic even if the emulated interface had low priority.
  3. Wait for browser activity. The demonstration relied on an already-running browser making background requests—for example, for page resources, advertising, analytics, or other content. When such a request was routed through the device, it could return content the browser treated as HTML or JavaScript.
  4. Expose some cookies through HTTP. The project describes hidden iframe requests to many domains. Cookies could accompany requests sent over ordinary, unencrypted HTTP, including cookies that were not marked Secure. Ars Technica’s contemporary explanation likewise emphasizes exposure of unencrypted web traffic and cookies lacking the Secure attribute, not universal access to protected HTTPS sessions.
  5. Seed browser-cache content. PoisonTap could return cacheable HTML or JavaScript that opened an outbound WebSocket. The creator described this as enabling follow-up browser requests after the device was removed. That is a description of the proof of concept; it does not establish that current browsers will behave the same way.

A separate router technique

The project also describes a DNS-rebinding technique aimed at a router. Kamkar notes that the broad IPv4 routing trick does not hijack the actual LAN subnet of the genuine network interface. The router scenario is therefore a separate path, not proof that PoisonTap automatically captures all local-network traffic.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
#1 Best Overall
Yojaro 4Pack Silicone Suction Phone Case Mount, Silicon Adhesive Smartphones Stand Sticky, Hands-Free Phone Accessories Holder for Selfies and Videos (Black & White & Translucent & Light Pink)
  • 【Strong Adsorption】The inspiration of the silicone phone suction case comes from the adhesive force of the octopus. Each suction cup phone mount is 3.15 inches long and 2.17 inches wide, with 24 independent suction cups providing a stronger and more stable suction force, so you don't have to worry about your phone falling during use.
  • 【Back of Phone Suction Grip】Remove the adhesive film on the phone suction cup and stick it on the phone case. You can then fix the phone on any smooth surface, which is very convenient. (The phone suction cup cannot be removed and reused after being attached to the phone case. It is recommended to attach it to a regular phone case, not a valuable one.)
  • 【Widely Used】Our non-slip silicone phone sticky grip mount attaches to almost any flat phone case and make it compatible with common mobile phones such as iPhone and Android.You can shoot, watch videos or video calls in the kitchen, gym, dance studio, bathroom and other places.
  • 【Capture the Wonderful Picture】Whether you are a TikTok creator or just like to share videos and photos, this phone suction cup can help you hands-free capture wonderful videos and photos for sharing with friends.
  • 【Note】You can fix the phone suction cup on a smooth surface such as a mirror or glass. If necessary, wipe the suction cup with a damp cloth to obtain stronger suction. Before releasing your hand, make sure the phone is firmly fixed. (Not applicable to rough walls, wooden surfaces, and other uneven surfaces)

Why HTTPS and cookie settings mattered

PoisonTap should not be described as decrypting HTTPS. The documented cookie exposure involved ordinary HTTP requests and a case where an HTTPS site’s cookie lacked the Secure attribute. HTTPS protects traffic in transit; the Secure cookie attribute tells a browser not to send that cookie over an unencrypted HTTP connection. Ars Technica noted that HTTPS, Secure cookies, and HSTS limit the exposure and downgrade scenario discussed in the demonstration. HSTS tells browsers to use HTTPS for a site, helping resist attempts to fall back to HTTP.

These protections address different parts of the chain. HTTPS and Secure cookies reduce the chance that sensitive content or cookies travel in cleartext. HSTS helps prevent downgrade attempts. None of those facts means a strong computer password is irrelevant: the demonstration targeted network and browser behavior while locked, not the password’s ability to protect the desktop and files.

Rank #2
Apple EarPods Headphones with USB-C Plug, Wired Ear Buds with Built-in Remote to Control Music, Phone Calls, and Volume
  • SUPERIOR COMFORT — Unlike traditional circular ear buds, the design of EarPods is defined by the geometry of the ear. Which makes them more comfortable for more people than any other ear bud–style headphones.
  • HIGH-QUALITY AUDIO — The speakers inside EarPods have been engineered to maximize sound output and minimize sound loss, which means you get high-quality audio.
  • BUILT-IN REMOTE — EarPods with USB-C plug also include a built-in remote that lets you adjust the volume, control the playback of music and video, and answer or end calls with a pinch of the cord.
  • COMPATIBILITY — Works with all devices that have a USB-C port.
  • INTEGRATED MICROPHONE — A built-in microphone precisely captures your voice while you’re on the phone, taking a FaceTime call, or summoning Siri — so you’re always heard loud and clear.

What the project’s scale claims mean

The project page names a $5 Raspberry Pi Zero as the demonstration platform and describes targeting the Alexa top 1,000,000 websites. Those are historical claims made by the creator in 2016, not current hardware pricing, a verified infection count, or evidence that one million sites were successfully compromised. The page also mentions large lists of domains and CDN URLs; those figures describe project scope, not measured victims.

The published project and contemporary coverage date from 2016. They do not establish compatibility with current operating systems, browsers, cookie defaults, network stacks, or endpoint controls, and the available sources provide no independent current prevalence statistic. Avoid treating the proof of concept as a confirmed present-day attack against every locked computer.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Rank #3
PopSockets Adhesive Phone Grip, Holder- Black
  • Secure Hold: Our PopSockets adhesive phone grip gives your cell phone a secure, comfortable hold in hand to help prevent drops while texting, taking photos, or scrolling on the go. Designed to stick firmly to most phone cases and devices.
  • Hands-Free Made Easy: Easily turn your PopSocket into a phone stand to prop up your phone anywhere, perfect for watching videos, video calls, or following recipes. A must-have phone holder that keeps your device secure and ready for anything.
  • Compatibility: Works with all phones, tablets, and Kindles. Sticks best to smooth, hard plastic cases and may not adhere to silicone or textured cases. Easily swap your PopTop to change up your style.
  • Black PopSockets: Simple, refined, and endlessly versatile. A timeless essential for any phone.
  • Travel Must-Have for People On the Go: A must-have travel accessory for flights, flying, airports, air travel, airplanes, planes, international trips, cruises, and long travel days. Key gadget for your airport haul, travel accessories and must-haves.

How to reduce the risk

If you leave a computer unattended

  • Control physical access to ports. The documented chain began with a device being connected to an exposed USB or Thunderbolt port.
  • Do not rely on locking alone to stop background activity. Kamkar recommended an encrypted sleep mode that requires a key to decrypt memory; Ars Technica suggested closing the browser or putting the computer to sleep. These are source-attributed recommendations, not verified instructions for a particular current device. Choose a sleep or shutdown state that prevents the browser from continuing to make requests while unattended.
  • Do not treat clearing the browser cache as a guaranteed cleanup. Ars Technica cautioned that cache clearing may be imperfect; it should not be presented as a reliable way to undo every possible consequence.

If you operate a website

  • Serve the site over HTTPS throughout.
  • Set the Secure attribute on cookies that should never be sent over HTTP.
  • Use HSTS to help browsers resist HTTPS downgrade attempts.
  • Apply Subresource Integrity to remotely hosted JavaScript resources where appropriate.

These are mitigations recommended by Kamkar and discussed by Ars Technica for the attack path they described. They reduce specific exposures; they do not turn the 2016 demonstration into a claim about all current systems.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Where the demonstration came from

Samy Kamkar’s PoisonTap project page contains the primary description of the attack chain, historical hardware, and suggested mitigations. The project source repository provides the associated code and materials. Ars Technica’s 2016 explanation of PoisonTap offers contemporary independent context on the HTTP and cookie limitations and defensive steps.

Best Value
Anteel 2 Pack Silicone Suction Cup Phone Case Mount Double Sided, Hands-Free Silicon Phone Grip with Higher Suction Power for Selfies and Videos, Non Slip Phone Accessories (LightPink&White)
  • 【PKYAA Double Sided Silicone Suction Phone Case Mount】PKYAA With Double Sided 40 Strong and Reliable individual suction cups, PKYAA provides a thicken and upgraded universal silicon suction mount for your phone.
  • 【Friendly to Content Creators】If you are a content creator or an online influencer, you can create videos anywhere with this suction mount completely hands free with this silicone cell phone mount for cases.
  • 【HANDS-FREE & Adhere to Mirrors】This Double Sided silicone suction phone case mount allows you to stick your phone to the mirror easily. No longer holding your phone in one hand to watch video tutorials while making up.
  • 【Strong Grip on the Smooth Surface】You can easily hang your phone anywhere with a smooth surface. All you do is you clean off your phone and smooth surface. It is STURDY and it not only sticks to mirrors, it also sticks to windows, it sticks to refrigerators, tiles and other clean, flat surfaces.
  • 【Press Down Firmly Every 30 Minutes】Use your palm or fingers to press the phone down firmly and check it's secure before letting go. Apply even pressure for a few seconds to allow the suction cup to adhere properly. To maintain the grip and prevent accidental falls, it's a good practice to periodically reapply pressure to the suction cup.
Rank #4
360° Rotating Stainless Steel Phone Tether Tab (Silvery 3-Pack) - Universal for iPhone & Other Phones (Fits Wristbands/Necklaces/Crossbody Straps)
  • [360 ° Flexible Rotation Design] Comes with a rotatable lanyard ring that supports 360 ° free rotation, effectively solving the problem of twisted and tangled lanyards
  • [Wide compatibility] The ultra-thin 0.02-inch design does not block the charging port at all, and both wired and wireless charging can be used directly without removing the pad. Compatible with most smartphones such as iPhone, compatible with various wristbands, lanyards, crossbody straps, and keychains
  • [Durable and Portable Material] Premium rust-resistant stainless steel material with good flexibility, which not only avoids scratching the phone case, but also has excellent anti rust and anti fading performance
  • [Multi scenario Practical] Paired with a lanyard or wristband, hands-free use can be achieved. The phone is within reach and not easily dropped, ideal for daily commuting and outdoor activities. Suitable for full coverage phone cases, does not support half coverage phone cases
  • [Quality Service] If you find any damage or other issues with the product upon receipt, please contact us immediately. We will handle it quickly

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.