Join GitHub today
GitHub is home to over 28 million developers working together to host and review code, manage projects, and build software together.
Sign upallow qubes.InputKeyboard by default in sys-usb salt #3126
Comments
This comment has been minimized.
Show comment
Hide comment
This comment has been minimized.
marmarek
Sep 27, 2017
Member
The main point is you can't unlock the screen with only mouse. So, if user is away, it can do nothing. But if user is there, he/she probably will notice the attack. See explanation here: https://www.qubes-os.org/doc/usb/#security-warning-about-usb-input-devices
This is also one of the reasons why installer refuse to create sys-usb when you use USB keyboard.
|
The main point is you can't unlock the screen with only mouse. So, if user is away, it can do nothing. But if user is there, he/she probably will notice the attack. See explanation here: https://www.qubes-os.org/doc/usb/#security-warning-about-usb-input-devices This is also one of the reasons why installer refuse to create sys-usb when you use USB keyboard. |
adrelanos commentedSep 27, 2017
https://github.com/QubesOS/qubes-mgmt-salt-dom0-virtual-machines/blob/master/qvm/sys-usb.sls does
Wouldn't it make sense to also add...
...?
Why only allow mouse but not keyboard? For security reasons?
A mouse is as good as a keyboard when scripted. Mouse actions reburied for an attack could be recorded and replayed. (There are applications for mouse automation.) Letters can be copied. Well, there is no
enterkey? But then a virtual keyboard should better not be installed? Or I guess there is also another way to use a mouse to get the same action asenter?Unless I am missing something (quite possible), if mouse is allowed, keyboard should as well.