3 ms·
Isn't this a security risk?
by mikotodomo 4y ago
Isn't this a security risk?
- tenebrisalietum 4y ago- `/dev/mem` should only be accessible by root or whoever you set the permissions to (don't `chmod 777 /dev/mem`). - root can install device drivers which have full executable run of the system anyway and do anything you can do with this device; this is also true on Windows. - read about CONFIG_STRICT_DEVMEM - https://man7.org/linux/man-pages/man4/mem.4.html#:~:text=Since%20Linux%202.6.26%2C%20and%20depending%20on%20the%20architecture%2C,not%20allowed%20but%20accessing%20memory-mapped%20PCI%20regions%20is https://man7.org/linux/man-pages/man4/mem.4.html#:~:text=Sin.... - wait until you hear about `/dev/kmem`. - it's possible to build a Linux kernel without `/dev/mem` support and also without loadable module support (I think), so if your threat model indicates this needs to be addressed it is possible.
- colechristensen 4y agoIt would be a fun exercise/YouTube video/class… you are an unprivileged user, /dev/mem is 777, go forth and prosper.
- deleted 4y ago[deleted]
- amarshall 4y ago`CONFIG_LOCK_DOWN_KERNEL_FORCE_CONFIDENTIALITY=y` or similar may also be of interest, see `man kernel_lockdown`.
- no_time 4y ago>root can install device drivers which have full executable run of the system anyway and do anything you can do with this device; this is also true on Windows. Oddly enough, no. Or atleast last time I tried on Ubuntu I had to disable secure boot. Seemed like an easier way than to sign the build files
- pritambaral 4y agoSecure Boot can be configured to also trust user keys. Ubuntu's installer does it automatically if you choose to install it with third-party drivers (like Nvidia). Those user keys are then available to root to sign any DKMS kernel modules.