Re: About IR Receivers and security

Egoitz Aurrekoetxea <egoitz-Q/[email protected]>
Newsgroups gmane.comp.hardware.lirc
Message-ID <[email protected]>

On 13/10/17 13:26, Alec Leamas wrote:
> Hi.
>
> First of all: please don't top-post. The archives becomes a mess.
>
> On 13/10/17 13:03, Egoitz Aurrekoetxea wrote:
>> Hi Alec!
>>
>>
>> The question wasn't that... I now know how to do it through sysfs......
>> the question is :
>>
>>
>> "Can you suffer a security issue having the IR Receiver operative
>> although without configuring any kind of user space daemon? At least...
>> not conscientiously....
>
> Well, if you consider an arbitrary input device a problem, yes. The
> kernel provides decoding of many ir remotes out of the box and without
> any userspace code.
>
>
> --alec
>
> ------------------------------------------------------------------------------
>
> Check out the vibrant tech community on one of the world's most
> engaging tech sites, Slashdot.org! http://sdm.link/slashdot

Hi Alec!

Sorry for top posting. I consider a problem, when an arbitrary device
could perform some kind of request to your system.... not just the fact
of writing to a /dev file.... if later that content becomes inoffensive
if something else does not 
interpret it and then does something consequently.....  that's what I
was wondering, if you an experts of this kind of communication device or
the own protocol, could know if by the fact of being listening (because
the module load) in irda
without later having configured nothing conscientiously (at least) to
act with that input, could cause any kind of problem to a computer....

Just that... not just the fact of receiving input... a wifi device
receives input constantly.... but later it connects where you say to
wpa_supplicant for instance.... so I have just had loaded the
hid-generic kernel module... but nothing else... just
if that could become dangerous if someone could... you know... or if you
recommend reinstalling the os...

Best regards,

------------------------------------------------------------------------------
Check out the vibrant tech community on one of the world's most
engaging tech sites, Slashdot.org! http://sdm.link/slashdot
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.