Gentoo Archives: gentoo-user

From: R0b0t1 <r030t1@×××××.com>
To: gentoo-user@l.g.o
Subject: Re: [gentoo-user] Linux USB security holes.
Date: Wed, 08 Nov 2017 06:48:31
Message-Id: CAAD4mYjwv8QgrSwaFoCYRZ2dYQgjSMuKBM0=b0kRUzo4NZ=6mQ@mail.gmail.com
In Reply to: Re: [gentoo-user] Linux USB security holes. by R0b0t1
1 On Wed, Nov 8, 2017 at 12:10 AM, R0b0t1 <r030t1@×××××.com> wrote:
2 > On Wed, Nov 8, 2017 at 12:02 AM, Dale <rdalek1967@×××××.com> wrote:
3 >> Dale wrote:
4 >>> Howdy,
5 >>>
6 >>> I ran up on this link. Is there any truth to it and should any of us
7 >>> Gentooers be worried about it?
8 >>>
9 >>> http://www.theregister.co.uk/2017/11/07/linux_usb_security_bugs/
10 >>>
11 >>> Isn't Linux supposed to be more secure than this??
12 >>>
13 >>> Dale
14 >>>
15 >>> :-) :-)
16 >>>
17 >>
18 >>
19 >> To reply to all that posted so far. I did see that it requires physical
20 >> access, like a lot of other things. Once a person has physical access,
21 >> there are a number of things that can go wrong.
22 >>
23 >> It does seem to be one of those things that while possible, has anyone
24 >> been able to do it in the real world and even without physical access?
25 >> Odds are, no.
26 >>
27 >
28 > The most widely publicized example is STUXNET. There are also reports
29 > that malicious USB keys with driver-level exploits are sometimes used
30 > for industrial espionage.
31 >
32 > The key point being that in either case, someone is spending a lot of
33 > money to research and set up a plausible attack.
34 >
35 >> Still, all things considered, Linux is pretty secure. BSD is more
36 >> secure from what I've read but Linux is better than windoze.
37 >>
38 >> Dale
39 >>
40 >> :-) :-)
41 >>
42
43 I suppose I should add that once the basic work has been done for an
44 exploit like this it will have great reproducibility. But at that
45 level you are (usually) talking about very well funded actors, and one
46 should also be worried about controller-level exploits that would be
47 much harder to discover from an operating system.
48
49 If you can't surround your computer with trustworthy armed guards,
50 assume you suffer from a serious vulnerability based on the
51 preliminary work the article is talking about.
52
53 Rainbows and Sunshine,
54 R0b0t1

Replies

Subject Author
Re: [gentoo-user] Linux USB security holes. Dale <rdalek1967@×××××.com>
Re: [gentoo-user] Linux USB security holes. Martin DiViaio <martindiv@×××××.com>