Protect your USB ports against exploits like #BadUSB and #PoisonTap by putting rules in place with something like #USBGuard.
https://github.com/dkopecek/usbguard
#infosec #linux #usb
https://github.com/dkopecek/usbguard
#infosec #linux #usb
IOW: it's basically impossible compared to shoving #PoisonTap into a [locked!] machine!
- And by the time one has physical access they could just get any #malware going instead which would be more convenient to do attacks and espionage with.
Cuz it's not like one can just "do a LAN TAP, but for RAM" and get access...
- Not to mention that there are already mitigations on the way, like encrypting RAM contents at a higher level, Address Randomization, etc.
