@Me
I would be less worried about a USB killer and more about a rubber ducky.
I wouldn't. Faking an input device relies too much on knowing the setup of the computer it gets plugged into. It's no doubt a handy little tool if you can seek out a specific target machine so that you can quickly set it up and walk away, but other USB exploits that have been discussed already make more sense if you're baiting someone. I suppose it all comes down to what the aim of the attack is/was.
Keyboards are users, so the computer is usually set to trust them, you would need a computer set to not mount any new devices to prevent them from running rampant.
And, honestly, that's exactly what a secure OS should be doing. Convenience often wins out, though, and there's always the issue of how secure any system can be once you, even by proxy, have physical access. @Frequent Fly On The Wall
Could you imagine being in a similar position?
Only to the extent that it makes a semi-plausible cover story. There are so many things that were done that I can't imagine doing if I were just going for a swim at the vacation property of a leader of a foreign country. But, then, the story from the US side of things smells a bit funny, too. It's particularly newsworthy because it's all so puzzling. @Vesselin Bontchev
Do you guys seriously think that a professionally made Chinese malware would visibly install something on the machine?
Depends. If it was designed for a particular target system and was instead plugged into a different (possibly hardened) setup, it's quite possible that the host OS would start kicking out notifications. But I would agree that, if it were a spying operation of some kind, the operational security was just awful. At first blush, nobody appears to have behaved very professionally. 3ce49f96ab12fc5c4fc1ed91ff01ae70ba3d908bed41fc276c626ef86a8ad287