Controlling device peer-to-peer access from user space
Controlling device peer-to-peer access from user space
Posted Mar 19, 2019 16:11 UTC (Tue) by ScottMinster (subscriber, #67541)Parent article: Controlling device peer-to-peer access from user space
This sounds like it could really enhance those Thunderclap vulnerabilities (https://lwn.net/Articles/782381/). A network adapter that could send read (or write) commands to the storage device without any mediation from the main system seems dangerous. While things would be fine with a well behaving device, could a rogue device read and transmit an entire drive with nothing on the system aware of it? Or some other nefarious behavior writing to the drive.
What sort of security precautions are there to mitigate a rogue device, especially one plugged into an external port?
