Filesystem mounts in user namespaces
Filesystem mounts in user namespaces
Posted Aug 6, 2015 18:35 UTC (Thu) by raven667 (subscriber, #5198)In reply to: Filesystem mounts in user namespaces by nybble41
Parent article: Filesystem mounts in user namespaces
That may not be practically achievable because it requires a large body of code to be perfect, which will never happen, given that you can't make a large body of code perfect, what's your next plan for containing the risk? How about a small system which handles the USB and filesystem that passes just the file data over an internal network to the main system, so the actual attack vector against the main system is that file passing network interface which can be made much simpler than all of USB and filesystem drivers.
In most cases people will just eat the risk and deal with the fact that kiosks can be broken into if you try, putting a keylogger on the kiosk might not even reduce its usability such that the owner even cares, certainly not enough to pay more money to increase security.