Re: About IR Receivers and security

Alec Leamas <[email protected]>
Newsgroups gmane.comp.hardware.lirc
Message-ID <[email protected]>

On 14/10/17 09:59, Bengt Martensson wrote:

> Just a few comments: A certain degree of "paranoia" is likely a good 
> thing here. Although the danger associated with sniffing IR commands is 
> probably quite low in comparison with other IoT related problems...

Agreed

> I think the completely open socket interface to lircd is a much worse 
> problem, something an attacker can use to cause, at least, a 
> considerable amount of annoyance. (Implementing TV-B-Gone for lircd 
> https://en.wikipedia.org/wiki/TV-B-Gone ?) I wrote this down as a lirc 
> ticket https://sourceforge.net/p/lirc/tickets/312/ .

Agreed.

There are other security issues w lirc. The debian packaging still runs 
this old, big piece of sw as root which is a major risk as well. And 
many (most?) installations runs irexec as root, opening a large security 
hole.

There are probably other issues. Frankly, the basic design just not 
takes security into account. We need to make a security review of lirc, 
and that's no small undertaking.

That said, my gut feeling is that we should be able to make the 
situation much better by addressing the packaging and documentation, 
helping users to set up lirc in general in a more secure way.


Cheers!
--alec



------------------------------------------------------------------------------
Check out the vibrant tech community on one of the world's most
engaging tech sites, Slashdot.org! http://sdm.link/slashdot
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.