they have the full intention of mounting it to see what is on it
they have the full intention of mounting it to see what is on it
Posted Feb 28, 2013 21:20 UTC (Thu) by Wol (subscriber, #4433)In reply to: A story of three kernel vulnerabilities by drag
Parent article: A story of three kernel vulnerabilities
Not at all.
Assuming the automount works even if the screen is locked (as I get the impression is often the case), this is a perfect way of breaking into someone else's machine. If the exploit opens a root shell on a secret port, that machine is now owned ...
So in that case, the user knows exactly what is on it. They want to see what's on the machine.
So a confirmatory pop-up (as I get on my gentoo system) *is* a very effective security step.
Cheers,
Wol