|
|
Log in / Subscribe / Register

Practical security for 2014

Practical security for 2014

Posted Jan 11, 2014 4:53 UTC (Sat) by drag (guest, #31333)
In reply to: Practical security for 2014 by Cyberax
Parent article: Practical security for 2014

Just as long as it can't be done via software is really the most important part.

But nothing beats physically disabling the ability of the computer to write to flash when it comes to making sure that nothing writes to flash without your permission. :)


to post comments

Practical security for 2014

Posted Jan 11, 2014 5:17 UTC (Sat) by tnoo (subscriber, #20427) [Link] (1 responses)

Sure, as long as the flash drive or the system's software really honors this jumper setting. Like, for example, CHDK on Canon cameras uses the storage card lock slider to indicate whether the firmware should be loaded from the card on bootup. If so, the camera writes the images to the locked storage card.

The situation might be still worse with flash drives which contain full microcontrollers doing all kinds of elaborate calculations, and thus are likely to be hackable as well.

Practical security for 2014

Posted Jan 17, 2014 10:05 UTC (Fri) by robbe (guest, #16131) [Link]

> The situation might be still worse with flash drives which contain full
> microcontrollers [...]

Every storage device since at least 2000 (including "simple" cards) includes controllers sufficiently complex to host malware.

See for example http://www.bunniestudios.com/blog/?p=3554


Copyright © 2026, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds