From: "Karl O. Pinc" <kop@meme.com>
To: linux-hotplug@vger.kernel.org
Subject: Re: [PATCH] add ACLs to /dev/sgX nodes for CD-ROM
Date: Mon, 14 Mar 2011 23:20:43 +0000 [thread overview]
Message-ID: <1300144843.15120.3@mofo> (raw)
In-Reply-To: <1299402082-4796-1-git-send-email-arvidjaar@mail.ru>
On 03/14/2011 11:41:09 AM, Kay Sievers wrote:
> On Mon, Mar 14, 2011 at 17:33, Harald Hoyer <harald@redhat.com>
> > Oh! You don't want to do this... Won't this allow ordinary users to
> flash a new
> > firmware, opening some security issues here?
> Do we really don't want that? Locally logged-in users could put glue
> in the tray too. :)
Has this been thought through?
Glue in the tray is a simple denial of service attack,
and one that affects but a single system component.
Flashing firmware, in theory at least, opens the door to
installing malware right into the firmware and enables
all sorts of ugly possibilities starting with malware that
runs before the boot process even gets going,
can't be detected by scanning the drive, and can't be removed by
wiping the hard drive and power cycling. It sounds scary if
an ordinary user, especially one not sitting next to
the box, can install such malware without any other
sort of privilege escalation.
Karl <kop@meme.com>
Free Software: "You don't pay back, you pay forward."
-- Robert A. Heinlein
prev parent reply other threads:[~2011-03-14 23:20 UTC|newest]
Thread overview: 7+ messages / expand[flat|nested] mbox.gz Atom feed top
2011-03-06 9:01 [PATCH] add ACLs to /dev/sgX nodes for CD-ROM Andrey Borzenkov
2011-03-06 15:33 ` Kay Sievers
2011-03-06 17:21 ` Nicolas Pomarède
2011-03-07 15:23 ` Kay Sievers
2011-03-14 16:33 ` Harald Hoyer
2011-03-14 16:41 ` Kay Sievers
2011-03-14 23:20 ` Karl O. Pinc [this message]
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=1300144843.15120.3@mofo \
--to=kop@meme.com \
--cc=linux-hotplug@vger.kernel.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for NNTP newsgroup(s).