Live data from Hacker News

The Google plasma globe affair of 2012

lcamtuf.coredump.cx

101–103 of 103 posts

Re: The Google plasma globe affair of 2012

#101
post #96

Earlier quoted context omitted.

> I was imagining this being in some advanced setting ... most users don't touch these settings That just leaves most users unprotected. > I was suggesting that they come pre-installed GNOME's support for USBGuard is installed by default, but USBGuard itself may not be depending on the distro. Agreed that it and other security/safety/robustness (for eg SMART disk warnings need to be supported) stuff (should be enable…

> That just leaves most users unprotected. Aren't these users already unprotected? I don't think this is a security concern for most people and turning on by default would frustrate them more. It'd be like shipping Firefox or Chrome with NoScript on my default. Sure, more protection, but it would turn away more people than it would pull in. Better as optional.

Firefox is ratcheting up the tracking protection for normal users and GNOME enabled Thunderbolt protection by default, so there is definitely precedent for protecting regular users too. Also with the rise of stalkerware, normal users are definitely targets too. I think the interface I proposed would be reasonable enough for most people and you could make it easy to turn off with the right UX.

Re: The Google plasma globe affair of 2012

#102
post #56

Earlier quoted context omitted.

For those wondering, there is an easy defense against this on Linux, USBGuard ( https://usbguard.github.io/ ) RHEL7+ include USBGuard as part of the standard repo [0] [0] https://access.redhat.com/documentation/en-us/red_hat_enterp...

This isn't very practical as a defense. You can't configure it to ban keyboards, because you still need a keyboard, and you might need to swap keyboards if your original one breaks.

That's not correct, it can block and does block USB keyboards. If your main keyboard was totally dead and you needed to whilelist a replacement keyboard you'd do so by booting into single-user mode.
Post reply on HN