Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.kernel > #1228074

Re: Failover root devices

From Austin S Hemmelgarn <ahferroin7@gmail.com>
Newsgroups linux.kernel
Subject Re: Failover root devices
Date 2015-09-18 17:40 +0200
Message-ID <qa5Vx-6Jf-37@gated-at.bofh.it> (permalink)
References (10 earlier) <q9M6u-3l9-39@gated-at.bofh.it> <q9M6u-3l9-37@gated-at.bofh.it> <qa5iP-5JO-23@gated-at.bofh.it> <qa5st-6aQ-17@gated-at.bofh.it> <qa5su-6aQ-37@gated-at.bofh.it>
Organization linux.* mail to news gateway

Show all headers | View raw


[Multipart message — attachments visible in raw view] - view raw

On 2015-09-18 11:04, Ortwin Glück wrote:
>> If you have physical access then the machine is yours to do with as
>> you please.
>
> Thinking of ATMs or voting machines that is a bold statement :-)
Many voting machines already have known ACE exploits already (I 
distinctly remember a while back some CS students demonstrated a 
'modern' voting machine playing PAC-Man without modifying any of the 
hardware at all), and those that have network access or other accessible 
peripheral connections are inherently insecure, period.

And most ATM's (at least in the US) run Windows (_shivers_) XP or 
eCommStation (the current commercial version of OS/2 (yes it still lives 
on), neither of which is particularly secure even when it comes to 
remote access to the system, and even then, the kind of access you need 
would involve3 directly tampering with the system.

Irrespective of that, neither one should be configured to work like 
that.  The intent is for custom setups primarily, if some company 
decides to use this in an insecure way, that's their problem, not ours 
(it's really easy to use a wide number of kernel features in ways that 
compromise security, that doesn't mean we should just rip those out).
>
> Thinking of mobile phones it depends on your jurisdiction.
This isn't a legal ruling, it's a simple statement of fact, if someone 
has physical access to a system, they effectively have root access, 
period.  While this is not probably what the above comment was directly 
referring to, it is an established fact.


Back to linux.kernel | Previous | NextPrevious in thread | Next in thread | Find similar | Unroll thread


Thread

Re: Failover root devices Ortwin Glück <odi@odi.ch> - 2015-09-17 13:50 +0200
  Re: Failover root devices Drew DeVault <sir@cmpwn.com> - 2015-09-17 14:00 +0200
    Re: Failover root devices Richard Weinberger <richard.weinberger@gmail.com> - 2015-09-17 19:50 +0200
      Re: Failover root devices Drew DeVault <sir@cmpwn.com> - 2015-09-17 19:50 +0200
        Re: Failover root devices Richard Weinberger <richard@nod.at> - 2015-09-17 20:00 +0200
          Re: Failover root devices Drew DeVault <sir@cmpwn.com> - 2015-09-17 20:10 +0200
            Re: Failover root devices Richard Weinberger <richard@nod.at> - 2015-09-17 20:20 +0200
              Re: Failover root devices Drew DeVault <sir@cmpwn.com> - 2015-09-17 20:20 +0200
                Re: Failover root devices Richard Weinberger <richard@nod.at> - 2015-09-17 20:20 +0200
                Re: Failover root devices Drew DeVault <sir@cmpwn.com> - 2015-09-17 20:30 +0200
                Re: Failover root devices Drew DeVault <sir@cmpwn.com> - 2015-09-17 20:30 +0200
                Re: Failover root devices Ortwin Glück <odi@odi.ch> - 2015-09-18 17:00 +0200
                Re: Failover root devices Drew DeVault <sir@cmpwn.com> - 2015-09-18 17:10 +0200
                Re: Failover root devices Ortwin Glück <odi@odi.ch> - 2015-09-18 17:10 +0200
                Re: Failover root devices Austin S Hemmelgarn <ahferroin7@gmail.com> - 2015-09-18 17:40 +0200
                Re: Failover root devices Richard Weinberger <richard@nod.at> - 2015-09-17 20:30 +0200
              Re: Failover root devices Harald Hoyer <harald.hoyer@gmail.com> - 2015-09-17 20:30 +0200
                Re: Failover root devices Drew DeVault <sir@cmpwn.com> - 2015-09-17 20:30 +0200
                Re: Failover root devices Richard Weinberger <richard@nod.at> - 2015-09-17 20:40 +0200
                Re: Failover root devices Drew DeVault <sir@cmpwn.com> - 2015-09-17 20:40 +0200
                Re: Failover root devices Richard Weinberger <richard@nod.at> - 2015-09-17 20:50 +0200
                Re: Failover root devices Richard Weinberger <richard@nod.at> - 2015-09-17 20:30 +0200
      Re: Failover root devices Austin S Hemmelgarn <ahferroin7@gmail.com> - 2015-09-17 20:40 +0200
        Re: Failover root devices Richard Weinberger <richard@nod.at> - 2015-09-17 20:50 +0200
          Re: Failover root devices Austin S Hemmelgarn <ahferroin7@gmail.com> - 2015-09-18 16:50 +0200

csiph-web