Gentoo Archives: gentoo-user

From: "J. Roeleveld" <joost@××××××××.org>
To: gentoo-user@l.g.o
Subject: Re: [gentoo-user] Re: Linux USB security holes.
Date: Thu, 09 Nov 2017 06:10:54
Message-Id: 13135444.CUWVRDMnju@andromeda
In Reply to: [gentoo-user] Re: Linux USB security holes. by Ian Zimmerman
1 On Wednesday, November 8, 2017 8:35:37 PM CET Ian Zimmerman wrote:
2 > On 2017-11-08 05:53, J. Roeleveld wrote:
3 > > From what I read, you need physical access.
4 >
5 > According to Solar, for whom I have developed great respect, this is not
6 > necessarily so:
7 >
8 > http://www.openwall.com/lists/oss-security/2017/11/08/5
9
10 I stand corrected. Forgot about this possible avenue. But this will still
11 require the person already has access to the system.
12 I think for most users with just a personal desktop, this is less likely.
13
14 It does bring another possible access, most servers have iKVM/IPMI systems
15 installed for remote management. Those also allow USB devices to be connected
16 over network. I would, however, class access to these parts of the system as
17 "physical" access.
18
19 --
20 Joost