Re: About IR Receivers and security

Egoitz Aurrekoetxea <egoitz-Q/[email protected]>
Newsgroups gmane.comp.hardware.lirc
Message-ID <[email protected]>
Hi!!! 



> El 14 oct 2017, a las 9:59, Bengt Martensson <[email protected]> escribió:
> 
> On 10/13/17 14:56, Egoitz Aurrekoetxea wrote:
>>>> "Can you suffer a security issue having the IR Receiver operative
>>>> although without configuring any kind of user space daemon? At least...
>>>> not conscientiously....
>>> 
>>> Well, if you consider an arbitrary input device a problem, yes. The
>>> kernel provides decoding of many ir remotes out of the box and without
>>> any userspace code.
> 
> Just a few comments: A certain degree of "paranoia" is likely a good thing here. Although the danger associated with sniffing IR commands is probably quite low in comparison with other IoT related problems...

I’m not worried about snniffing because have not used it.... I mean have not need IR device... it’s just in the laptop...


> 
> I think the completely open socket interface to lircd is a much worse problem, something an attacker can use to cause, at least, a considerable amount of annoyance. (Implementing TV-B-Gone for lircd https://en.wikipedia.org/wiki/TV-B-Gone ?) I wrote this down as a lirc ticket https://sourceforge.net/p/lirc/tickets/312/ .


Lirc has not been running... I have been compiling all my system through the package Manager... Later using it... I have let’s say, know about lirc and lircd reading about this subject... so nope lircd.. should not have been running....

So as far as the kernel loaded modules... by their own, should not perform nothing in the full laptop (let’s say) than, at most, write to an unattended /dev file (socket)... I suppose all will be fine....

> 
> 
> > Put a piece of tape over the IR receiver - problem solved (just as
> > some Facebook inventor uses tape over his laptop camera).
> 
> What is transparent for visual light is not necessary transparent for IR, and vice versa. I would not trust "a piece of tape"; better to use something thicker...



I agree with that 🙂🙂 I prefer unbinding it through sysfs....


> 
> Greetz,
> 
> Bengt





Many many many thanks Bengt 😀😀,

Cheers!




> 
> ------------------------------------------------------------------------------
> Check out the vibrant tech community on one of the world's most
> engaging tech sites, Slashdot.org! http://sdm.link/slashdot


------------------------------------------------------------------------------
Check out the vibrant tech community on one of the world's most
engaging tech sites, Slashdot.org! http://sdm.link/slashdot
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.