From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from list by lists.gnu.org with archive (Exim 4.71) id 1S259c-0006LF-51 for mharc-grub-devel@gnu.org; Mon, 27 Feb 2012 13:18:32 -0500 Received: from eggs.gnu.org ([208.118.235.92]:53399) by lists.gnu.org with esmtp (Exim 4.71) (envelope-from ) id 1S259Z-0006K6-Pz for grub-devel@gnu.org; Mon, 27 Feb 2012 13:18:30 -0500 Received: from Debian-exim by eggs.gnu.org with spam-scanned (Exim 4.71) (envelope-from ) id 1S259V-0006J9-EY for grub-devel@gnu.org; Mon, 27 Feb 2012 13:18:29 -0500 Received: from mail-ey0-f169.google.com ([209.85.215.169]:56052) by eggs.gnu.org with esmtp (Exim 4.71) (envelope-from ) id 1S259V-0006Iw-8j for grub-devel@gnu.org; Mon, 27 Feb 2012 13:18:25 -0500 Received: by eaal1 with SMTP id l1so123547eaa.0 for ; Mon, 27 Feb 2012 10:18:24 -0800 (PST) Received-SPF: pass (google.com: domain of phcoder@gmail.com designates 10.14.183.130 as permitted sender) client-ip=10.14.183.130; Authentication-Results: mr.google.com; spf=pass (google.com: domain of phcoder@gmail.com designates 10.14.183.130 as permitted sender) smtp.mail=phcoder@gmail.com; dkim=pass header.i=phcoder@gmail.com Received: from mr.google.com ([10.14.183.130]) by 10.14.183.130 with SMTP id q2mr8829618eem.101.1330366704332 (num_hops = 1); Mon, 27 Feb 2012 10:18:24 -0800 (PST) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=gamma; h=message-id:date:from:user-agent:mime-version:to:subject:references :in-reply-to:content-type:content-transfer-encoding; bh=FXFXn9LWfLuQA0Wit755NNljjUIaVxsV53Mz1yBCPLc=; b=k5/TyZOy9TDHYTRvud8RXgIpaIuvJ5EATdNiooK8nDXIqE8GPSyuB+iMRxmFKbGHiA OAyf+mA+y0NVzA7+VHXmbBrMcvYIBqRxRyiu2vYUA8gdHtWQShB16eOfQV4s18yuFvPk r5u9iaSI1e2zfyh+LmolNxt0nhZrJgjCy8gKY= Received: by 10.14.183.130 with SMTP id q2mr6625004eem.101.1330366704232; Mon, 27 Feb 2012 10:18:24 -0800 (PST) Received: from debian.x201.phnet (19-234.197-178.cust.bluewin.ch. [178.197.234.19]) by mx.google.com with ESMTPS id y14sm60501408eef.10.2012.02.27.10.18.15 (version=TLSv1/SSLv3 cipher=OTHER); Mon, 27 Feb 2012 10:18:23 -0800 (PST) Message-ID: <4F4BC8E3.7070700@gmail.com> Date: Mon, 27 Feb 2012 19:18:11 +0100 From: =?UTF-8?B?VmxhZGltaXIgJ8+GLWNvZGVyL3BoY29kZXInIFNlcmJpbmVua28=?= User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:8.0) Gecko/20120216 Icedove/8.0 MIME-Version: 1.0 To: Richard Laager , The development of GRUB 2 Subject: Re: Freeze on 27 February References: <4F43C25C.2040106@gmail.com> <1329888906.16648.134.camel@watermelon.coderich.net> <4F45DDF0.2090908@gmail.com> <1330033617.3895.26.camel@watermelon.coderich.net> <4F4AC782.1090402@gmail.com> <1330322499.2901.5.camel@watermelon.coderich.net> <1330322681.2901.8.camel@watermelon.coderich.net> In-Reply-To: <1330322681.2901.8.camel@watermelon.coderich.net> Content-Type: text/plain; charset=UTF-8; format=flowed Content-Transfer-Encoding: 8bit X-detected-operating-system: by eggs.gnu.org: Genre and OS details not recognized. X-Received-From: 209.85.215.169 X-BeenThere: grub-devel@gnu.org X-Mailman-Version: 2.1.14 Precedence: list Reply-To: The development of GNU GRUB List-Id: The development of GNU GRUB List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Mon, 27 Feb 2012 18:18:31 -0000 On 27.02.2012 07:04, Richard Laager wrote: > On Mon, 2012-02-27 at 00:01 -0600, Richard Laager wrote: >> I haven't verified that the kernel itself refuses to create/load >> such a pool. > In any case, what is the threat here? If someone hand-crafts such a > pool, they still have to get the administrator to import it. > > Even if the system is automatically importing pools, they'd still have > to have physical access to, for example, plug in a USB device with the > evil pool. A USB stick "forgotten" in a public place can do wonders. -- Regards Vladimir 'φ-coder/phcoder' Serbinenko