D&C GLug - Home Page

[ Date Index ] [ Thread Index ] [ <= Previous by date / thread ] [ Next by date / thread => ]

Re: [LUG] Completely lock down on virtual consoles on supend

 

On 20 Aug 2013, at 23:01, bad apple <mr.meowski@xxxxxxxx> wrote:

> 
> Now, I happen to be pretty familiar with Inception, and it's not all
> it's cracked up to be... by a long shot. It had a brief moment in the
> sun, but then everything patched it 

I'd be really worried if they hadn't been patched, but it won't be the last.

Before it we had holes in the Windows infrared drivers (okay strictly that didn't 
need physical contact).

X Windows screen saver "debug" left in.

WEP

And many more...

Guess physical access just expands the attack surface. If you can force memory 
exhaustion remotely its a dos, with physical access we'll find out if the screen 
lock is safe from the oom reaper (most should be).

The other thing that has moved is expense of gadgets like key loggers. The great 
thing about USB is it has removed a lot of device connectivity issues, so the key 
loggers now grab data from a variety of USB devices - camera, flash drivers, 
printers. If you are feeling flash<sic> they come looking like USB cables, whose 
going to check their USB cables haven't been switched. 
-- 
The Mailing List for the Devon & Cornwall LUG
http://mailman.dclug.org.uk/listinfo/list
FAQ: http://www.dcglug.org.uk/listfaq