4 ms·
NO! Summarizing as “when you have physical access, the game is up” is the same as saying that employees who pick up abandoned USB thumbdrives on parking lots a
by pascal_cuoq 12y ago
NO!
Summarizing as “when you have physical access, the game is up” is the same as saying that employees who pick up abandoned USB thumbdrives on parking lots and plug them into work computers are guilty.
Plugging things in are what Thunderbolt/USB ports are FOR. This is how you transmit data and how you extend the computer with new peripherals. It may be impossible to prevent a Thunderbolt or USB peripheral from bricking the computer, but that doing so can end up giving control of it to a third party is an unacceptable security failure, is not the user's fault, and needs to be fixed.
A physical hardware switch located inside the box would be quite appropriate. Everyone knows that you don't need to open the computer to read from an external drive.
- foxhill 12y ago> is the same as saying that employees who pick up abandoned USB thumbdrives on parking lots and plug them into work computers are guilty oh my science they most certainly are. > Plugging things in are what Thunderbolt/USB ports are FOR yes, but the moment you insert them into a machine they are assumed to be trusted. (this is my opinion, it could be incorrect)
- nknighthb 12y ago> the same as saying employees who pick up abandoned USB thumbdrives on parking lots and plug them into work computers are guilty This has been true for as long as USB has existed. The broader version -- "don't attach untrusted hardware" -- has been true for as long as there have been computers. There is a reason secure installations do not allow employees to bring in arbitrary electronics.