iSECPartners / yontma

You'll never take me alive.
Other
86 stars 18 forks source link

Add Support for USB / Firewire devices #25

Closed kill-9-me closed 11 years ago

kill-9-me commented 11 years ago

Checking for new USB / Firewire devices during a locked session could prevent firewire DMA attacks or attacks from USB keychains.

If a laptop is high profile enough Power or Ethernet can be maintained while transporting.

andreasjunestam commented 11 years ago

Duplicate of issue #4

mlynch-isec commented 11 years ago

I think this is actually different than #4.

539F4uL7 - you're saying YoNTMA should hibernate if a USB/Firewire device is inserted while the screen is locked?

catskillmarina commented 11 years ago

Not exactly. I would like it to hibernate if an UNKNOWN devices is inserted while the screen is locked. Hibernating if any device is inserted while screen is locked would be even better. I would like to see it watching for any suspicious device changes.

catskillmarina commented 11 years ago

Maybe even blacklist some devices - though this could be easilly subverted, a shutdown if a known mouse wiggler or keylogger was added might give some extra protection. If a known bad device is added i would like to see a hibernate or shutdown whether the screen was locked or not.