4 ms·
> By default, any users are able to install firmware to removable hardware. The logic here is that if the hardware can be removed, it can easily be moved to a d
by maggit 11y ago
> By default, any users are able to install firmware to removable hardware. The logic here is that if the hardware can be removed, it can easily be moved to a device that the user already has root access on, and asking for authentication would just be security theatre.
- http://www.fwupd.org/users.html http://www.fwupd.org/users.html
But it is not given that a user has physical access to the machine, is it?
Well... I guess that's why it says "By default", and you can configure it? Seems targeted at desktop installations?
- yrro 11y ago> Well... I guess that's why it says "By default", and you can configure it? Seems targeted at desktop installations? Yes, it uses polkit: https://github.com/hughsie/fwupd/tree/master/policy https://github.com/hughsie/fwupd/tree/master/policy
- Menge 11y ago> But it is not given that a user has physical access to the machine, is it? Yes, I think the logic here is flawed. The only way to know someone can do something in the physical security theatre is by their doing it. Needing to cajole any normal user into running a script is a tad more optimal than convincing them to physically move devices from the server room to the new machine that they won in your raffle.