How to use Linux's built-in USB attack protection

Discussion in 'all things UNIX' started by summerheat, Jun 16, 2017.

  1. summerheat

    summerheat Registered Member

    Joined:
    May 16, 2015
    Posts:
    2,199
    http://www.zdnet.com/article/how-to-use-linuxs-built-in-usb-attack-protection/

    Interesting. I had not been aware of this tool. Although I don't think that I need it ...
     
  2. mirimir

    mirimir Registered Member

    Joined:
    Oct 1, 2011
    Posts:
    9,252
    I don't see how this can protect against LiveCDs. Because USBGuard is an app in the installed Linux. And so it's just dead bits on a disk while the LiveCD is booting. You can disable USB ports in the BIOS, however. Or disconnect them from the motherboard. Or fill them with epoxy.
     
  3. oliverjia

    oliverjia Registered Member

    Joined:
    Jul 21, 2005
    Posts:
    1,926
    Exactly
     
  4. summerheat

    summerheat Registered Member

    Joined:
    May 16, 2015
    Posts:
    2,199
    Yes, I agree. I think this tool is useful in enterprises where sysadmins can stop employees playing with USB sticks.

    :argh: A fool-proof solution, indeed.
     
  5. Mrkvonic

    Mrkvonic Linux Systems Expert

    Joined:
    May 9, 2005
    Posts:
    10,226
    If someone has physical access to your hardware, you have a much bigger problem than wannabe Jason Bourne games.
    Mrk
     
  6. RockLobster

    RockLobster Registered Member

    Joined:
    Nov 8, 2007
    Posts:
    1,812
    encrypt it with luks, install the luks header and /boot on a seperate media.
     
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.