Bug#928032: Default configuration for USBGuard

2019-07-25 Thread Thiébaud Weksteen
On Sun, Jul 21, 2019 at 10:20 AM Birger Schacht wrote: > > Hi, > > On 7/16/19 7:01 PM, Thiébaud Weksteen wrote: > > It might be worth talking about what threat we want to address in the > > default config. In both cases (keep or generate-policy), the kernel > > will be exposed until usbguard is

Bug#928032: Default configuration for USBGuard

2019-07-21 Thread Birger Schacht
Hi, On 7/16/19 7:01 PM, Thiébaud Weksteen wrote: > It might be worth talking about what threat we want to address in the > default config. In both cases (keep or generate-policy), the kernel > will be exposed until usbguard is started. If we are considering an > attacker using a malicious device

Bug#928032: Default configuration for USBGuard

2019-07-16 Thread Birger Schacht
Hi, On 7/16/19 12:47 PM, Antoine Beaupré wrote: > On 2019-07-15 11:09:55, Thiébaud Weksteen wrote: >> On generate-policy vs PresentDevicePolicy, I would argue that the >> simplest option is the best. By running generate-policy, you are >> parsing all current devices, generating rules and then

Bug#928032: Default configuration for USBGuard

2019-07-16 Thread Antoine Beaupré
On 2019-07-15 11:09:55, Thiébaud Weksteen wrote: > Hi Birger, Antoine, > > Thanks for getting 0.7.5 ready. For the difference between "allow" and > "keep" on PresentDevicePolicy, the standard use case is handled > similarly (i.e., user installing USBGuard for the 1st time, no > customisation). The

Bug#928032: Default configuration for USBGuard

2019-07-15 Thread Thiébaud Weksteen
Hi Birger, Antoine, Thanks for getting 0.7.5 ready. For the difference between "allow" and "keep" on PresentDevicePolicy, the standard use case is handled similarly (i.e., user installing USBGuard for the 1st time, no customisation). The difference is slightly more subtle for hosts that have

Bug#928032: Default configuration for USBGuard

2019-07-12 Thread Birger Schacht
Hi, I'm currently working on packaging the 0.7.5 release of usbguard, which was released a little more than a week ago. I have looked at the various options we have to tackle the default configuration. I agree that the prompts at installation time should be minimized, so I'm not convinced of my

Bug#928032: Default configuration for USBGuard

2019-06-19 Thread Antoine Beaupre
On Fri, Apr 26, 2019 at 03:10:19PM +0200, Thiébaud Weksteen wrote: > Does anyone have any preference? I think minimizing the number of prompts to the user would be preferable, honestly. I would do the following changes in the Debian package: 1. PresentDevicePolicy=keep - just to avoid breaking