Follow @Openwall on Twitter for new release announcements and other news
[<prev] [next>] [<thread-prev] [thread-next>] [day] [month] [year] [list]
Date: Fri, 8 Aug 2014 09:21:02 -0700
From: Greg KH <greg@...ah.com>
To: oss-security@...ts.openwall.com
Subject: Re: BadUSB discussion

On Fri, Aug 08, 2014 at 08:09:53PM +0400, gremlin@...mlin.ru wrote:
>  > Oh, and if you want, you can disable all USB devices on your
>  > Linux system by default, and only "authorize" them explicitly
>  > if you programatically think they should be enabled.  We have
>  > had support in the kernel for that for years now, but very few
>  > people actually use it.
> 
> I've faced that only once, and my solution was straightforward:
> those two servers were running a kernel built with only basic
> USB HID support (keyboard+mouse, IIRC) and without module load
> support. That appeared to be quite enough.

That doesn't prevent any other USB HID device from being plugged in and
instantly working.  Which again, you can prevent if you want to, but no
one seems to do that...

>  > So the tools to do this are already there, why aren't you using
>  > them? :)
> 
> You could guess: sometimes I'm developing USB devices and have to
> test them. That formed a good habit of connecting my devices to a
> hub instead of directly to BB :-)

A USB hub doesn't do anything special except slow things down and add
complexity to the overall USB system, and does nothing for "security" at
all.

greg k-h

Powered by blists - more mailing lists

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.