3 ms·
USBGuard
- jvanderbot 3y agoI used this for years and only ever learned to allow devices. I'm sure it has advanced capabilities but it is not user friendly
- zamadatix 3y agoBadUSB works by emulating a keyboard HID device. Would it be possible to improve the BadUSB device to allow plugging the actual keyboard in to the rear, duplicating the identity for the port facing the computer, and passing copies of any keystrokes actually sent as well as then injecting the malicious payload when the time is right? This made me realize for all of the USB security/token devices (I don't think there is) an actual secure/signed transport mode for USB verifying the two aren't being snooped. Or maybe there is and I just don't know about it, this would be a much stronger method of securing devices.
- K0balt 3y agoYes, it would be possible to add data capture and in fact there are many devices that have that as well ass additional capabilities.
- shim__ 3y ago> This made me realize for all of the USB security/token devices (I don't think there is) an actual secure/signed transport mode for USB verifying the two aren't being snooped. Or maybe there is and I just don't know about it, this would be a much stronger method of securing devices. CTAP2(Fido) uses opportunistic encryption without MITM the data will be unreadable to an sniffer.
- yrro 3y agoWasn't this incorporated into GNOME at some point? I remember having to disable it because it didn't work properly. I wonder if it's been improved since then...
- jquast 3y agoIf I were an attacker, could I clone the device id and attributes of the victim's previously approved devices? https://github.com/USBGuard/usbguard#before-the-first-start https://github.com/USBGuard/usbguard#before-the-first-start Anyway I enjoy this HID stuff, I've been playing with using a computer as a keyboard to another computer. With scroll, num, and capslock LED's, bidirectional communication can be achieved and by injecting a small process I think some new kind of universal REPL can be accomplished.
- thefurdrake 3y agoAt this point, I think functionality like this should be expected and standard. Minimal hardware interaction for authentication until the user approves the connection, period.