oss-sec mailing list archives
Re: Linux kernel: multiple vulnerabilities in the USB subsystem x2
From: "Perry E. Metzger" <perry () piermont com>
Date: Thu, 22 Aug 2019 21:13:11 -0400
On Thu, 22 Aug 2019 20:33:54 +0100 Eddie Chapman <eddie () ehuk net> wrote:
On 22/08/2019 20:00, Perry E. Metzger wrote:You can argue anything you like. Power charging points have popped up around the world, and you're not in a position to stop them. Furthermore, I'll note that over the air exploitable bugs in things like WiFi stacks and Bluetooth stacks have also appeared over time; perhaps it's foolish to have your phone on at all, and yet people will continue to turn their phones on, and even to use them.Well, I certainly am not deluded enough to think I have the power to stop power charging points popping up everywhere :-) Or to stop people making mistakes. Just because something is possible and everyone else does it doesn't make something less stupid. It's a similar principle with wifi/bluetooth, which is why I avoid connecting even to a family member's wifi access point unless it's absolutely necessary.
I think the fact that you avoid connecting to WiFi access points, even ones owned by family members, unless absolutely necessary, may demonstrate that your model of what does and does not constitute a ordinary user behavior might not be the same as other people's. Most people do use WiFi in a variety of places, and most people do charge off of USB ports they have not personally vetted. Given this, I think fixing bugs that might lead to privilege escalation, even if they require physical connection of USB devices, does indeed seem reasonable. -- Perry E. Metzger perry () piermont com
Current thread:
- Re: Linux kernel: multiple vulnerabilities in the USB subsystem x2, (continued)
- Re: Linux kernel: multiple vulnerabilities in the USB subsystem x2 Greg KH (Aug 22)
- Re: Linux kernel: multiple vulnerabilities in the USB subsystem x2 Perry E. Metzger (Aug 22)
- Re: Linux kernel: multiple vulnerabilities in the USB subsystem x2 Jeremy Stanley (Aug 22)
- Re: Linux kernel: multiple vulnerabilities in the USB subsystem x2 John Haxby (Aug 22)
- Re: Linux kernel: multiple vulnerabilities in the USB subsystem x2 Kurt H Maier (Aug 22)
- Re: Linux kernel: multiple vulnerabilities in the USB subsystem x2 Eddie Chapman (Aug 22)
- Re: Linux kernel: multiple vulnerabilities in the USB subsystem x2 Perry E. Metzger (Aug 22)
- Re: Linux kernel: multiple vulnerabilities in the USB subsystem x2 Eddie Chapman (Aug 22)
- Re: Linux kernel: multiple vulnerabilities in the USB subsystem x2 Mathias Payer (Aug 22)
- Re: Linux kernel: multiple vulnerabilities in the USB subsystem x2 Stuart D. Gathman (Aug 22)
- Re: Linux kernel: multiple vulnerabilities in the USB subsystem x2 Perry E. Metzger (Aug 22)
- Re: Linux kernel: multiple vulnerabilities in the USB subsystem x2 Eddie Chapman (Aug 22)
- Re: Linux kernel: multiple vulnerabilities in the USB subsystem x2 Greg KH (Aug 23)
- Re: Linux kernel: multiple vulnerabilities in the USB subsystem x2 Andrey Konovalov (Sep 27)
- Re: Linux kernel: multiple vulnerabilities in the USB subsystem x2 Tyler Hicks (Sep 27)