Blocking Untrusted USB Devices
roussos.cc
roussos.cc
I've thought about this topic before and arrived at the idea that USB devices ought to be treated kind of like user accounts, where I can control what drivers / data / devices they have access to.
[1]https://hackaday.com/2019/02/12/a-malicious-wifi-backdoor-in...
[2]https://hackaday.com/2014/10/05/badusb-means-were-all-screwe...
Once a USB security key has been authorized and is kept on your person rather than constantly attached to your machine it should be impossible to connect a new device and have it trusted by default - and re-connecting an already connected device would de-authorize it.
The real solution needs to be some sort of standardized auth system, where devices are identified by a public key rather than a static serial number. In the absence of that though, I think whitelisting serial numbers is the next best thing. It'll slow down attacks at least, and open the door for future improvements to the system.
"Type the following words on the newly connected keyboard."
"Move the newly connected mouse in the following directions, in order."
usbguard allow-device -p <id>
[1]: https://github.com/USBGuard/usbguard/blob/master/doc/man/usb...Ok so you might install it then lose HID access?
Sounds like a bad default config.