Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.debian.user > #240238

Re: write only storage.

From Michael Stone <mstone@debian.org>
Newsgroups linux.debian.user
Subject Re: write only storage.
Date 2021-09-21 22:10 +0200
Message-ID <CZUfv-5nu-1@gated-at.bofh.it> (permalink)
References <CZQvg-386-5@gated-at.bofh.it> <CZQOB-3eW-1@gated-at.bofh.it> <CZRhE-3oA-1@gated-at.bofh.it> <CZRrk-3Hf-9@gated-at.bofh.it> <CZRUm-3QH-9@gated-at.bofh.it>
Organization linux.* mail to news gateway

Show all headers | View raw


On Tue, Sep 21, 2021 at 06:37:41PM +0100, Tim Woodall wrote:
>A ransomware attack that exploits a zero day ssh vulnerability for
>example wouldn't be a complete disaster - this is only home usage - but
>it seems fairly trivial to create a 'worm' usb device using a pi. I
>haven't tested yet but with a blu-ray burner attached too the pi could
>write to disc once there's 25G written and then delete it.
>
>I'm slightly surprised someone hasn't done something like this already.

Because it's not actually easy to use such a thing. What would the pi 
present itself as? A block device? Filesystems generally need to rewrite 
specific blocks in order to work. You need to be able to access specific 
objects. So maybe you expose the pi via CIFS or NFS or somesuch. Ok, but 
files are often not written as one atomic operation, especially on 
network filesystems. So you can't make the files completely immutable, 
you need to be able to append to them while they're being written. So 
what's your trigger condition to change from "appendable" to 
"immutable"? 

There are solutions for this, mostly in the compliance space, but
they're generally pretty niche.

Back to linux.debian.user | Previous | Next — Previous in thread | Next in thread | Find similar | Unroll thread


Thread

write only storage. Tim Woodall <debianuser@woodall.me.uk> - 2021-09-21 18:10 +0200
  Re: write only storage. Toni Mas Soler <antomassol@protonmail.com> - 2021-09-21 18:30 +0200
    Re: write only storage. "Andrew M.A. Cater" <amacater@einval.com> - 2021-09-21 19:10 +0200
      Re: write only storage. Tim Woodall <debianuser@woodall.me.uk> - 2021-09-21 19:40 +0200
        Re: write only storage. "Thomas Schmitt" <scdbackup@gmx.net> - 2021-09-21 20:50 +0200
        Re: write only storage. Michael Stone <mstone@debian.org> - 2021-09-21 22:10 +0200
        Re: write only storage. Stefan Monnier <monnier@iro.umontreal.ca> - 2021-10-01 17:10 +0200
      Unclosed DVD-R or BD-R sessions ? was: Re: write only storage. "Thomas Schmitt" <scdbackup@gmx.net> - 2021-09-21 20:50 +0200
    Re: write only storage. Michael Stone <mstone@debian.org> - 2021-09-21 19:10 +0200
  Write *once* storage (was Re: write only storage) Steve McIntyre <steve@einval.com> - 2021-09-21 19:30 +0200
    Re: Write *once* storage (was Re: write only storage) "James H. H. Lampert" <jamesl@touchtonecorp.com> - 2021-09-21 19:40 +0200
    Re: Write *once* storage (was Re: write only storage) Joe Pfeiffer <pfeiffer@cs.nmsu.edu> - 2021-09-22 01:30 +0200
  Re: write only storage. Marco Möller <talby@debianlists.mobilxpress.net> - 2021-09-21 19:30 +0200
    Re: write only storage. Tim Woodall <debianuser@woodall.me.uk> - 2021-09-21 19:50 +0200
    Re: write only storage. Linux-Fan <Ma_Sys.ma@web.de> - 2021-09-21 21:50 +0200
    Re: write only storage. Marco Möller <talby@debianlists.mobilxpress.net> - 2021-09-22 18:20 +0200
  Re: write only storage. David Christensen <dpchrist@holgerdanske.com> - 2021-09-22 06:20 +0200
    Re: write only storage. Tim Woodall <debianuser@woodall.me.uk> - 2021-09-22 10:10 +0200
      Re: write only storage. "Thomas Schmitt" <scdbackup@gmx.net> - 2021-09-22 12:30 +0200
        Re: write only storage. Tim Woodall <debianuser@woodall.me.uk> - 2021-09-22 16:40 +0200
      Re: write only storage. David Christensen <dpchrist@holgerdanske.com> - 2021-09-23 01:00 +0200

csiph-web