3 ms·
> First, the GRSecurity patchset contains a kernel-level USB whitelist, so you can whitelist only known USB devices. A targeted attacker could attempt to spoof
by stebalien 10y ago
> First, the GRSecurity patchset contains a kernel-level USB whitelist, so you can whitelist only known USB devices. A targeted attacker could attempt to spoof an existing/whitelisted USB device, but it does significantly harden the USB attack surface:
Actually, the GRSecurity patchset includes a toggle to disable all new usb devices after boot. The whitelist mechanism you're referring to relies only on udev (no kernel patching needed). You can even whitelist by driver to, e.g., allow all usb storage devices by default.