Re: RFC/patch: authorizing (or not) devices to connect to the system
Robert Marquardt <[email protected]>
| Newsgroups | gmane.linux.usb.devel |
|---|---|
| Message-ID | <[email protected]> |
Inaky Perez-Gonzalez schrieb: > Hi All > > As part of the work for Wireless USB, I need to introduce in the USB stack > the concept of unauthorized vs authorized device. The first one is one that > cannot be really used until we move it to authorized, but at least we have > some knowledge of it. > > I've been toying with some patches to implement this concept also in a > generic way so that it could be used to implement a control mechanism > for locking down systems (like for example, don't connect this kind of > hw, because policy won't allow it being configured). Definitely something useful. I have seen several attempts to limit access to only specific USB sticks on Windows. It is a hot topic in our security concious times. The device has to be admitted as far as allowing enough communication to get its credentials. For USB sticks this is VID, PID and serial number string. An API to userland is needed to allow user interaction (at least a daemon) to decide policy dynamically. ------------------------------------------------------------------------- This SF.net email is sponsored by DB2 Express Download DB2 Express C - the FREE version of DB2 express and take control of your XML. No limits. Just data. Click to get it now. http://sourceforge.net/powerbar/db2/ _______________________________________________ [email protected] To unsubscribe, use the last form field at: https://lists.sourceforge.net/lists/listinfo/linux-usb-devel