oss-sec mailing list archives
Re: BadUSB discussion
From: lazytyped <lazytyped () gmail com>
Date: Fri, 08 Aug 2014 09:21:19 -0700
On 08/08/2014 09:17, Greg KH wrote:
There is a USB firmware download spec, which is quite easy to use, if manufacturers actually followed it (side note, I was one of the authors of that spec...) And if USB device manufacturers actually required signed firmware to run in their devices, that would solve this issue instantly as long as the signing keys don't leak.
Or, for cheap devices like USB dongles, just keep the firmware read-only. Who's going to update it anyway. But yes, either the update should be signed and verified, or hardware-switch controlled or impossible to begin with (read-only). Not only for USB devices. - twiz
Current thread:
- Re: BadUSB discussion, (continued)
- Re: BadUSB discussion Greg KH (Aug 08)
- Re: BadUSB discussion Daniel Kahn Gillmor (Aug 08)
- Re: BadUSB discussion Greg KH (Aug 08)
- Re: BadUSB discussion Eddie Chapman (Aug 08)
- Re: BadUSB discussion Greg KH (Aug 08)
- Re: BadUSB discussion Eddie Chapman (Aug 08)
- Re: BadUSB discussion Greg KH (Aug 08)
- Re: BadUSB discussion Eddie Chapman (Aug 08)
- Re: BadUSB discussion Greg KH (Aug 08)
- Re: BadUSB discussion Eddie Chapman (Aug 08)
- Re: BadUSB discussion lazytyped (Aug 09)
- Re: BadUSB discussion Dean Pierce (Aug 08)
- Re: BadUSB discussion Greg KH (Aug 08)
- Re: BadUSB discussion (GalaxyMaster) (Aug 08)
- Re: BadUSB discussion Yves-Alexis Perez (Aug 08)
- Re: BadUSB discussion Yves-Alexis Perez (Aug 08)
- Re: BadUSB discussion Greg KH (Aug 08)
- Re: BadUSB discussion Yves-Alexis Perez (Aug 08)
- Re: BadUSB discussion Greg KH (Aug 08)
- Re: BadUSB discussion Yves-Alexis Perez (Aug 09)
- Re: BadUSB discussion Vincent Lefevre (Aug 14)