2 ms·
You're talking about essentially an HW firewall for USB connections. We can discount VID/PID based black/whitelisting since they're trivial to spoof, but it mi
by shabble 12y ago
You're talking about essentially an HW firewall for USB connections.
We can discount VID/PID based black/whitelisting since they're trivial to spoof, but it might be possible to use them to identify (from an external database) what features that V/P device is supposed to be capable of, and block/alert if it tries to do things it shouldn't.
So if you initially enumerate as 0x0403/0x6001 (FTDI usb-serial) then if you try to start serving up descriptors about how you totally do mass-storage or something, that's probably kinda naughty. You'd potentially need quite a bit of code to parse and decode the various protocols it might be observing, giving a really big code surface for an attacker to identify or compromise your 'condom' itself.
So, with a lot of work, and a really big and annoying to update database, it might be possible to protect against imposter/multi-personality devices.
The bigger overall threat though is probably masquerading as valid mass-storage, but then doing various things to the data you're asked to store/fetch. (See the Active anti-forensics iPod and similar)
As I see it, there's basically nothing you can do here against an actively hostile device that isn't a cat & mouse game of exploit->patch->repeat. Conceivably the OS could sign every file going in, and maintain a local cache of signatures to check when reading, but that falls over in the hugely predominant use-case of using a USB drive to transfer files between things; you have no easy side-channel to also transfer sigs. So then the machines need to trust each other (without the malicious drive compromising one and being able to fake sigs)