Re: RFC/patch: authorizing (or not) devices to connect to the system

David Brownell <[email protected]>
Newsgroups gmane.linux.usb.devel
Message-ID <[email protected]>
On Tuesday 24 April 2007, Robert Marquardt wrote:
> Inaky Perez-Gonzalez schrieb:
> > ...
> > I've been toying with some patches to implement this concept also in a 
> > generic way so that it could be used to implement a control mechanism
> > for locking down systems (like for example, don't connect this kind of 
> > hw, because policy won't allow it being configured).
> 
> Definitely something useful. I have seen several attempts to limit access to
> only specific USB sticks on Windows. It is a hot topic in our security 
> concious times.

If this is a "security" issue, what's the threat being defended against?
Just for USB sticks?

If certain sticks are allowed, what's keeping those on-site so they can't
be used to export data or import viruses?  And what's keeping someone from
creating a stick that identifies itself as one of those "specific" sticks?

Most of the foofraw about being "security conscious" is most accurately
termed "security theatre" or "fear-mongering".  It's not a new problem.

- Dave


-------------------------------------------------------------------------
This SF.net email is sponsored by DB2 Express
Download DB2 Express C - the FREE version of DB2 express and take
control of your XML. No limits. Just data. Click to get it now.
http://sourceforge.net/powerbar/db2/
_______________________________________________
[email protected]
To unsubscribe, use the last form field at:
https://lists.sourceforge.net/lists/listinfo/linux-usb-devel
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.