1 |
On Wed, Nov 8, 2017 at 12:10 AM, R0b0t1 <r030t1@×××××.com> wrote: |
2 |
> On Wed, Nov 8, 2017 at 12:02 AM, Dale <rdalek1967@×××××.com> wrote: |
3 |
>> Dale wrote: |
4 |
>>> Howdy, |
5 |
>>> |
6 |
>>> I ran up on this link. Is there any truth to it and should any of us |
7 |
>>> Gentooers be worried about it? |
8 |
>>> |
9 |
>>> http://www.theregister.co.uk/2017/11/07/linux_usb_security_bugs/ |
10 |
>>> |
11 |
>>> Isn't Linux supposed to be more secure than this?? |
12 |
>>> |
13 |
>>> Dale |
14 |
>>> |
15 |
>>> :-) :-) |
16 |
>>> |
17 |
>> |
18 |
>> |
19 |
>> To reply to all that posted so far. I did see that it requires physical |
20 |
>> access, like a lot of other things. Once a person has physical access, |
21 |
>> there are a number of things that can go wrong. |
22 |
>> |
23 |
>> It does seem to be one of those things that while possible, has anyone |
24 |
>> been able to do it in the real world and even without physical access? |
25 |
>> Odds are, no. |
26 |
>> |
27 |
> |
28 |
> The most widely publicized example is STUXNET. There are also reports |
29 |
> that malicious USB keys with driver-level exploits are sometimes used |
30 |
> for industrial espionage. |
31 |
> |
32 |
> The key point being that in either case, someone is spending a lot of |
33 |
> money to research and set up a plausible attack. |
34 |
> |
35 |
>> Still, all things considered, Linux is pretty secure. BSD is more |
36 |
>> secure from what I've read but Linux is better than windoze. |
37 |
>> |
38 |
>> Dale |
39 |
>> |
40 |
>> :-) :-) |
41 |
>> |
42 |
|
43 |
I suppose I should add that once the basic work has been done for an |
44 |
exploit like this it will have great reproducibility. But at that |
45 |
level you are (usually) talking about very well funded actors, and one |
46 |
should also be worried about controller-level exploits that would be |
47 |
much harder to discover from an operating system. |
48 |
|
49 |
If you can't surround your computer with trustworthy armed guards, |
50 |
assume you suffer from a serious vulnerability based on the |
51 |
preliminary work the article is talking about. |
52 |
|
53 |
Rainbows and Sunshine, |
54 |
R0b0t1 |