"[device name] is requesting [scary sounding permission] Allow?"
It won't protect users from themselves, but it will protect "bad-usb" style attacks.
"[device name] is requesting [scary sounding permission] Allow?"
It won't protect users from themselves, but it will protect "bad-usb" style attacks.
A conference coordinator hands me a T3-HDMI adapter (as in the above scenario), I plug it in to my laptop, and it says "This device is requesting direct memory access. Allow Y/N?" My talk starts in an hour. Should I ask for the source code to the adapter firmware so I can do a quick audit?
Unless maybe you meant just the same scary message for every thunderbolt device, in which case people become acclimated to ignoring the message. And that may be after they've wasted support time asking why some device wants this scary access.
But are thunderbolt devices really expected to be that common that a message like this would be treated like the windows UAC dialog?
A security prompt seems very reasonable to me here, however I'm not sure Intel or Apple are very interested in that becasue they would be admitting a weakness and hinder the adoption of their own technology in some ways.
However for user trust this would be a very big win in my eyes.
If Thunderbolt gives even a slight advantage over USB-C, vendors will want to use it over USB-C. And the layperson will want it as well, which leads to "creep" making the most insecure but fastest method the "main".
There would need to be a way to dissuade vendors from using Thunderbolt for everything... And sadly a warning message isn't enough.
There is Thunderbolt 2, but it never saw any adoption outside Apple, and it's basically dead.
But in all seriousness, I agree that it's far from perfect, however I still think there is a way to allow the possibility without almost completely giving up on security.