The solution
In November 2016 security researcher Samy Kamkar released PoisonTap: free software on a $5 Raspberry Pi Zero that, plugged into a locked Mac or PC for about 30 seconds, intercepts the machine's web traffic and authentication cookies, then installs a backdoor that keeps the browser and local network remotely controllable after the device is gone. 'The primary motivation is to demonstrate that even on a password-protected computer running off of a WPA2 Wi-Fi, your system and network can still be attacked quickly and easily,' he told Ars.
The chain uses only standard conveniences. The Pi poses as an Ethernet card and, handing out addresses via DHCP, becomes the gateway; by defining the local network as the entire IPv4 space it becomes the gateway for all internet traffic too. It finds a background browser and injects hidden iframes pointing at Alexa's top one million sites, and — masquerading as each site's HTTP server — collects the cookies that come back. Cache-planted code keeps a persistent WebSocket alive after the stick is pulled; a DNS rebinding attack gives administrative reach into the connected router.
The defenses the piece lists are structural, not behavioral. HSTS and properly secured cookies defeat the cookie harvest — which is why Google and Facebook pages could not be triggered — while multi-factor authentication barely helps, because it is not re-triggered by cookie-based logins. End users can close browsers before locking up, enable FileVault2 and sleep on a Mac, or flush caches; the safest habit is simply to carry the machine along.
PoisonTap continued Kamkar's line of cheap, published hacks: a $10 USB charger that harvests keyboard strokes, a $30 device that opens electronically locked cars and garages, a DIY stalker app built on Google Street View. He released the source code and a demonstration video, and Ars Technica framed the pattern as a standing warning about the security tradeoffs of an increasingly computerized world.
Why it worked
It needs no zero-days: USB networking, DHCP, permissive 'local' ranges and cache persistence are all ordinary conveniences, simply chained in the right order.
It relocated the trust boundary: the login prompt was never the real attack surface — the network stack and the background browser were.
At $5 it democratized an attack that had read as a state-actor fantasy, moving the defense argument from user habits to protocol-level guarantees.
What can be applied
Once hardware is touched, password strength is irrelevant. Put the guarantee at the protocol layer — HSTS, Secure cookies — because behavioral rules like 'lock your screen' fail against a $5 device.
Aftermath
Kamkar published the full source code and a demo video, making the chain reproducible by anyone with a $5 board. The article noted the exploit already failed against sites properly running HSTS and Secure cookies — Google and Facebook among them — a snapshot of the industry mid-shift toward HTTPS-everywhere defaults. Its practical advice ended with the truly paranoid option: bring the laptop with you, or turn the machine off altogether.
FOLLOW THE EVIDENCE