Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]
Groups > linux.debian.user > #242023 > unrolled thread
| Started by | "hdv@gmail" <hdv.jadev@gmail.com> |
|---|---|
| First post | 2021-11-11 18:50 +0100 |
| Last post | 2022-01-11 17:50 +0100 |
| Articles | 12 — 4 participants |
Back to article view | Back to linux.debian.user
How to secure access to SD cards a la USBGuard? "hdv@gmail" <hdv.jadev@gmail.com> - 2021-11-11 18:50 +0100
Re: How to secure access to SD cards a la USBGuard? Stefan Monnier <monnier@iro.umontreal.ca> - 2021-11-12 17:20 +0100
Re: How to secure access to SD cards a la USBGuard? "hdv@gmail" <hdv.jadev@gmail.com> - 2021-11-12 18:10 +0100
Re: How to secure access to SD cards a la USBGuard? Stefan Monnier <monnier@iro.umontreal.ca> - 2021-11-12 18:30 +0100
Re: How to secure access to SD cards a la USBGuard? Andrei POPESCU <andreimpopescu@gmail.com> - 2021-12-05 13:40 +0100
Re: How to secure access to SD cards a la USBGuard? "hdv@gmail" <hdv.jadev@gmail.com> - 2021-12-05 14:20 +0100
Re: How to secure access to SD cards a la USBGuard? David Wright <deblis@lionunicorn.co.uk> - 2021-12-06 17:20 +0100
Re: How to secure access to SD cards a la USBGuard? David Wright <deblis@lionunicorn.co.uk> - 2021-12-06 17:20 +0100
Re: How to secure access to SD cards a la USBGuard? Andrei POPESCU <andreimpopescu@gmail.com> - 2021-12-10 17:30 +0100
Re: How to secure access to SD cards a la USBGuard? David Wright <deblis@lionunicorn.co.uk> - 2022-01-03 04:00 +0100
Re: How to secure access to SD cards a la USBGuard? Andrei POPESCU <andreimpopescu@gmail.com> - 2022-01-11 12:50 +0100
Re: How to secure access to SD cards a la USBGuard? "hdv@gmail" <hdv.jadev@gmail.com> - 2022-01-11 17:50 +0100
| From | "hdv@gmail" <hdv.jadev@gmail.com> |
|---|---|
| Date | 2021-11-11 18:50 +0100 |
| Subject | How to secure access to SD cards a la USBGuard? |
| Message-ID | <DimmZ-2Zd-5@gated-at.bofh.it> |
Hi all, I'd like to limit access to (micro) SD cards on our systems to only those cards that have been vetted up front. At first glance I thought maybe USBGuard would help me do this, but that will only detect built-in or USB-mounted card readers in which the card is plugged, not the storage device itself. Therefore allowing the card reader will automatically allow anyone to access any number of memory cards. That's not what we want for these systems. Using USBGuard I can (and do) limit access to specific USB devices (including thumbdrives), but it seems I cannot use it to limit access to specific memory cards. For built-in readers I figure that is because the communication is not USB-based. But that would not be the case for USB-based card readers. Does anyone have a suggestion on how I can achieve this? Many thanks in advance! Grx HdV
[toc] | [next] | [standalone]
| From | Stefan Monnier <monnier@iro.umontreal.ca> |
|---|---|
| Date | 2021-11-12 17:20 +0100 |
| Message-ID | <DiHrr-7vX-9@gated-at.bofh.it> |
| In reply to | #242023 |
> I'd like to limit access to (micro) SD cards on our systems to only those
> cards that have been vetted up front.
IIUC the way SD card are interfaced with the system, you can't use an
approach like USBGuard for that indeed.
I suspect you'll need to be more specific about what you mean by
"access". E.g. you may need to control this access when `mount`ing,
which will then depend on how you want to allow such mounts.
Then another question will be how you want to "vet" (by partion
UUID, maybe?).
Stefan
[toc] | [prev] | [next] | [standalone]
| From | "hdv@gmail" <hdv.jadev@gmail.com> |
|---|---|
| Date | 2021-11-12 18:10 +0100 |
| Message-ID | <DiIdR-81H-27@gated-at.bofh.it> |
| In reply to | #242072 |
On 2021-11-12 17:13, Stefan Monnier wrote: >> I'd like to limit access to (micro) SD cards on our systems to only those >> cards that have been vetted up front. > > IIUC the way SD card are interfaced with the system, you can't use an > approach like USBGuard for that indeed. I was getting afraid of that. > I suspect you'll need to be more specific about what you mean by > "access". E.g. you may need to control this access when `mount`ing, > which will then depend on how you want to allow such mounts. What I'd like is to be able to let users mount only those memory cards that have been registered up front. I've always thought it strange that people consider thumbdrives to be a risk (and rightly so), but no one is seemingly bothered by almost the equivalent risk posed by memory cards. Those can contain "bad" software as well, and they can to automounted just as easily as USB-drives. So why not make it possible to prevent users from mounting a card they found somewhere or that was given to them by some unknown agent? > Then another question will be how you want to "vet" (by partion > UUID, maybe?). That was indeed my first thought. TBH I don't know of any other trustworthy and unique ID for storage devices (not USB). P.S. Just to be sure: this is not about letting only specific users mount a filesystem. I know how to achieve that goal. This is about preventing social engineering attacks through malicious memory cards, without blocking the card reader altogether. Thanks! Grx HdV
[toc] | [prev] | [next] | [standalone]
| From | Stefan Monnier <monnier@iro.umontreal.ca> |
|---|---|
| Date | 2021-11-12 18:30 +0100 |
| Message-ID | <DiIxb-882-3@gated-at.bofh.it> |
| In reply to | #242080 |
> What I'd like is to be able to let users mount only those memory cards that
> have been registered up front. I've always thought it strange that people
> consider thumbdrives to be a risk (and rightly so), but no one is seemingly
> bothered by almost the equivalent risk posed by memory cards.
There's a difference in the fact that what looks like a USB thumbdrive
may actually expose itself to your machine as something else
(e.g. a combination of a thumbdrive, a keyboard, a mouse, a network
adapter, a serial port, you name it).
Hence USB guard.
IIUC the SD protocol also supports other kinds of devices (SDIO devices)
so it opens up comparable risks, but since it's an extension of the base
SD protocol we can hope that most sdcard readers only support access to
actual mass storage thingies and hence block those threats in
their tracks.
> Those can contain "bad" software as well, and they can to automounted
> just as easily as USB-drives. So why not make it possible to prevent
> users from mounting a card they found somewhere or that was given to
> them by some unknown agent?
I think usually the assumption is that just mounting a card doesn't
introduce serious risk as long as you avoid obvious issues like setuid
bits, and as long as you don't go out of your way to introduce security
holes (such as by auto-executing some files from the just-mounted
partition).
> P.S. Just to be sure: this is not about letting only specific users mount
> a filesystem. I know how to achieve that goal. This is about preventing
> social engineering attacks through malicious memory cards, without blocking
> the card reader altogether.
I see more or less what you're thinking of, but I'm not familiar with
such social engineering attacks to know what to recommend.
As mentioned, the way to control it will depend on the specific tool
used to mount. E.g. if it's mounted by hand via a rule in /etc/fstab,
then you can rules that specify the device via /etc/disk/by-uuid.
Do note that partition UUIDs are not designed to be reliable w.r.t
malicious uses (it's easy to create a partition with the same UUID as
some other).
Another way might to be to force the use of an encrypted filesystem and
see if you can enforce the use of a particular encryption key, so any
memory card not encrypted with the specific key will hopefully fail.
Stefan
[toc] | [prev] | [next] | [standalone]
| From | Andrei POPESCU <andreimpopescu@gmail.com> |
|---|---|
| Date | 2021-12-05 13:40 +0100 |
| Message-ID | <DqYYa-5wP-3@gated-at.bofh.it> |
| In reply to | #242083 |
[Multipart message — attachments visible in raw view] — view raw
On Vi, 12 nov 21, 12:27:59, Stefan Monnier wrote: > > As mentioned, the way to control it will depend on the specific tool > used to mount. E.g. if it's mounted by hand via a rule in /etc/fstab, > then you can rules that specify the device via /etc/disk/by-uuid. > > Do note that partition UUIDs are not designed to be reliable w.r.t > malicious uses (it's easy to create a partition with the same UUID as > some other). /dev/disk/by-id/ should be device specific. Kind regards, Andrei -- http://wiki.debian.org/FAQsFromDebianUser
[toc] | [prev] | [next] | [standalone]
| From | "hdv@gmail" <hdv.jadev@gmail.com> |
|---|---|
| Date | 2021-12-05 14:20 +0100 |
| Message-ID | <DqZAS-5Zu-9@gated-at.bofh.it> |
| In reply to | #242688 |
On 2021-12-05 13:33, Andrei POPESCU wrote: > On Vi, 12 nov 21, 12:27:59, Stefan Monnier wrote: >> >> As mentioned, the way to control it will depend on the specific tool >> used to mount. E.g. if it's mounted by hand via a rule in /etc/fstab, >> then you can rules that specify the device via /etc/disk/by-uuid. >> >> Do note that partition UUIDs are not designed to be reliable w.r.t >> malicious uses (it's easy to create a partition with the same UUID as >> some other). > > /dev/disk/by-id/ should be device specific. Shoot, I had forgotten about WWNs at all! Yep, those should be good enough for my purposes. Thanks for the hint! Grx HdV
[toc] | [prev] | [next] | [standalone]
| From | David Wright <deblis@lionunicorn.co.uk> |
|---|---|
| Date | 2021-12-06 17:20 +0100 |
| Message-ID | <DroSB-4ej-3@gated-at.bofh.it> |
| In reply to | #242689 |
On Sun 05 Dec 2021 at 14:11:25 (+0100), hdv@gmail wrote: > On 2021-12-05 13:33, Andrei POPESCU wrote: > > On Vi, 12 nov 21, 12:27:59, Stefan Monnier wrote: > > > > > > As mentioned, the way to control it will depend on the specific tool > > > used to mount. E.g. if it's mounted by hand via a rule in /etc/fstab, > > > then you can rules that specify the device via /etc/disk/by-uuid. > > > > > > Do note that partition UUIDs are not designed to be reliable w.r.t > > > malicious uses (it's easy to create a partition with the same UUID as > > > some other). > > > > /dev/disk/by-id/ should be device specific. > > Shoot, I had forgotten about WWNs at all! Yep, those should be good > enough for my purposes. I make a habit of archiving the udevadm info, or /run/udev/data/b8:NN files, for all my disks, sticks and cards. I can't find any WWNs that are not on either spinning drives or my (sole) SSD. Even my oldest hard drive (early-2007) lacks one. So I'm interested to know how/where you read them from on SD cards. Is this a new thing with SDXC/SDUC? I use LABELs and "UUIDs" (Serial Numbers) to identify mine. LABELs are most use; for example, I have a Nokia phone that writes a new Serial Number on any µSD card that's inserted. I have no idea why. It's obviously only useful in a cooperative environment. Cheers, David.
[toc] | [prev] | [next] | [standalone]
| From | David Wright <deblis@lionunicorn.co.uk> |
|---|---|
| Date | 2021-12-06 17:20 +0100 |
| Message-ID | <DroSC-4ej-11@gated-at.bofh.it> |
| In reply to | #242688 |
On Sun 05 Dec 2021 at 13:33:41 (+0100), Andrei POPESCU wrote: > On Vi, 12 nov 21, 12:27:59, Stefan Monnier wrote: > > > > As mentioned, the way to control it will depend on the specific tool > > used to mount. E.g. if it's mounted by hand via a rule in /etc/fstab, > > then you can rules that specify the device via /etc/disk/by-uuid. > > > > Do note that partition UUIDs are not designed to be reliable w.r.t > > malicious uses (it's easy to create a partition with the same UUID as > > some other). > > /dev/disk/by-id/ should be device specific. It certainly is, but specific to the card reader reading it, not the card. And that's whether the card is plugged into a slot on the computer, or into a discrete SD/USB adapter. Cheers, David.
[toc] | [prev] | [next] | [standalone]
| From | Andrei POPESCU <andreimpopescu@gmail.com> |
|---|---|
| Date | 2021-12-10 17:30 +0100 |
| Message-ID | <DsQWt-a7-1@gated-at.bofh.it> |
| In reply to | #242726 |
[Multipart message — attachments visible in raw view] — view raw
On Lu, 06 dec 21, 10:18:49, David Wright wrote: > On Sun 05 Dec 2021 at 13:33:41 (+0100), Andrei POPESCU wrote: > > On Vi, 12 nov 21, 12:27:59, Stefan Monnier wrote: > > > > > > As mentioned, the way to control it will depend on the specific tool > > > used to mount. E.g. if it's mounted by hand via a rule in /etc/fstab, > > > then you can rules that specify the device via /etc/disk/by-uuid. > > > > > > Do note that partition UUIDs are not designed to be reliable w.r.t > > > malicious uses (it's easy to create a partition with the same UUID as > > > some other). > > > > /dev/disk/by-id/ should be device specific. > > It certainly is, but specific to the card reader reading it, > not the card. And that's whether the card is plugged into a > slot on the computer, or into a discrete SD/USB adapter. At least with the built-in reader on an Acer Chromebook R13 the ID changes with every card I tested, but you are indeed right about USB adapters (at least for the two I could test). Kind regards, Andrei -- http://wiki.debian.org/FAQsFromDebianUser
[toc] | [prev] | [next] | [standalone]
| From | David Wright <deblis@lionunicorn.co.uk> |
|---|---|
| Date | 2022-01-03 04:00 +0100 |
| Message-ID | <DBlJL-2Fl-3@gated-at.bofh.it> |
| In reply to | #242917 |
On Fri 10 Dec 2021 at 17:20:52 (+0100), Andrei POPESCU wrote: > On Lu, 06 dec 21, 10:18:49, David Wright wrote: > > On Sun 05 Dec 2021 at 13:33:41 (+0100), Andrei POPESCU wrote: > > > On Vi, 12 nov 21, 12:27:59, Stefan Monnier wrote: > > > > > > > > As mentioned, the way to control it will depend on the specific tool > > > > used to mount. E.g. if it's mounted by hand via a rule in /etc/fstab, > > > > then you can rules that specify the device via /etc/disk/by-uuid. > > > > > > > > Do note that partition UUIDs are not designed to be reliable w.r.t > > > > malicious uses (it's easy to create a partition with the same UUID as > > > > some other). > > > > > > /dev/disk/by-id/ should be device specific. > > > > It certainly is, but specific to the card reader reading it, > > not the card. And that's whether the card is plugged into a > > slot on the computer, or into a discrete SD/USB adapter. > > At least with the built-in reader on an Acer Chromebook R13 the ID > changes with every card I tested, but you are indeed right about USB > adapters (at least for the two I could test). I did some comparisons between machines, and it would appear that when the link starts with /dev/disk/by-id/mmc- then the ID is that of the card, whereas when it starts with /dev/disk/by-id/usb- then the ID is that of the card reader. Note that I did all the comparisons using fullsize SD cards pushed into slots in the PCs, so there were no separate adapters involved, neither SD→USB, nor µSD→SD. As one might expect, googling mmc and usb is swamped with stuff about MMC and SD /cards/, so I haven't read anything about the differences between these slots on different computers. But I guess that if you want to distinguish SD cards by their identification/serial number, rather than strings that you write onto them (UUID/LABEL), you need to use a PC with an mmc-style slot. Cheers, David.
[toc] | [prev] | [next] | [standalone]
| From | Andrei POPESCU <andreimpopescu@gmail.com> |
|---|---|
| Date | 2022-01-11 12:50 +0100 |
| Message-ID | <DEnP4-22h-9@gated-at.bofh.it> |
| In reply to | #243604 |
[Multipart message — attachments visible in raw view] — view raw
On Du, 02 ian 22, 20:52:25, David Wright wrote: > On Fri 10 Dec 2021 at 17:20:52 (+0100), Andrei POPESCU wrote: > > On Lu, 06 dec 21, 10:18:49, David Wright wrote: > > > On Sun 05 Dec 2021 at 13:33:41 (+0100), Andrei POPESCU wrote: > > > > On Vi, 12 nov 21, 12:27:59, Stefan Monnier wrote: > > > > > > > > > > As mentioned, the way to control it will depend on the specific tool > > > > > used to mount. E.g. if it's mounted by hand via a rule in /etc/fstab, > > > > > then you can rules that specify the device via /etc/disk/by-uuid. > > > > > > > > > > Do note that partition UUIDs are not designed to be reliable w.r.t > > > > > malicious uses (it's easy to create a partition with the same UUID as > > > > > some other). > > > > > > > > /dev/disk/by-id/ should be device specific. > > > > > > It certainly is, but specific to the card reader reading it, > > > not the card. And that's whether the card is plugged into a > > > slot on the computer, or into a discrete SD/USB adapter. > > > > At least with the built-in reader on an Acer Chromebook R13 the ID > > changes with every card I tested, but you are indeed right about USB > > adapters (at least for the two I could test). > > I did some comparisons between machines, and it would appear that > when the link starts with /dev/disk/by-id/mmc- then the ID is > that of the card, whereas when it starts with /dev/disk/by-id/usb- > then the ID is that of the card reader. Note that I did all the > comparisons using fullsize SD cards pushed into slots in the PCs, > so there were no separate adapters involved, neither SD→USB, nor µSD→SD. My guess is micro-SD to SD adapters are passive only (i.e. just connecting pin-to-pin as needed), so it shouldn't matter. For the OP's issue, it seems a possible solution would be to disallow any USB-to-SD adapters, and for the (hopefully few) users that really need to use SD cards to use MMC-style slots only. A less secure option would be to allow USB adapters only for a few select *trusted* users, with the understanding that they use "safe" SD cards only. Kind regards, Andrei -- http://wiki.debian.org/FAQsFromDebianUser
[toc] | [prev] | [next] | [standalone]
| From | "hdv@gmail" <hdv.jadev@gmail.com> |
|---|---|
| Date | 2022-01-11 17:50 +0100 |
| Message-ID | <DEsvn-5dJ-1@gated-at.bofh.it> |
| In reply to | #243854 |
On 2022-01-11 12:41, Andrei POPESCU wrote: > On Du, 02 ian 22, 20:52:25, David Wright wrote: >> On Fri 10 Dec 2021 at 17:20:52 (+0100), Andrei POPESCU wrote: >>> On Lu, 06 dec 21, 10:18:49, David Wright wrote: >>>> On Sun 05 Dec 2021 at 13:33:41 (+0100), Andrei POPESCU wrote: >>>>> On Vi, 12 nov 21, 12:27:59, Stefan Monnier wrote: >>>>>> >>>>>> As mentioned, the way to control it will depend on the specific tool >>>>>> used to mount. E.g. if it's mounted by hand via a rule in /etc/fstab, >>>>>> then you can rules that specify the device via /etc/disk/by-uuid. >>>>>> >>>>>> Do note that partition UUIDs are not designed to be reliable w.r.t >>>>>> malicious uses (it's easy to create a partition with the same UUID as >>>>>> some other). >>>>> >>>>> /dev/disk/by-id/ should be device specific. >>>> >>>> It certainly is, but specific to the card reader reading it, >>>> not the card. And that's whether the card is plugged into a >>>> slot on the computer, or into a discrete SD/USB adapter. >>> >>> At least with the built-in reader on an Acer Chromebook R13 the ID >>> changes with every card I tested, but you are indeed right about USB >>> adapters (at least for the two I could test). >> >> I did some comparisons between machines, and it would appear that >> when the link starts with /dev/disk/by-id/mmc- then the ID is >> that of the card, whereas when it starts with /dev/disk/by-id/usb- >> then the ID is that of the card reader. Note that I did all the >> comparisons using fullsize SD cards pushed into slots in the PCs, >> so there were no separate adapters involved, neither SD→USB, nor µSD→SD. > > My guess is micro-SD to SD adapters are passive only (i.e. just > connecting pin-to-pin as needed), so it shouldn't matter. > > For the OP's issue, it seems a possible solution would be to disallow > any USB-to-SD adapters, and for the (hopefully few) users that really > need to use SD cards to use MMC-style slots only. I am afraid that I won't be able to exclude SD cards from use. They are in use right now and changing that policy would create too much negative sentiment among the users of these systems/laptops. We have a hard enough time to get them to comply as it is. Plus, I try to accommodate our users where I can, so that they know I am doing my best to not get in their way unless it can't be done in another way. This has paid many dividends in the past, where others were not able to get our users to cooperate and they would when I asked them. Just because they trust I am doing my best to think of them. I am very careful not to waste that goodwill. > A less secure option would be to allow USB adapters only for a few > select *trusted* users, with the understanding that they use "safe" SD > cards only. The problem is that a significant number of those users is not very much security aware. In the past I have been able to demonstrate many many social engineering and technical attacks to them, and still they fall for it. It is not that they are unwilling or dumb. They just don't get how computers (or indeed they themselves) can be manipulated so easily. They expect us admins to make that impossible, but they also don't want to be bothered by any measures we take... I am still trying to find a manageable and dependable way to limit the mounting of storage devices to devices (not filesystems) that have been vetted up front. Thanks for taking the time to help me with this! Grx HdV
[toc] | [prev] | [standalone]
Back to top | Article view | linux.debian.user
csiph-web