Hi Marc: This is a security bug, because I cannot examine the state of a potentially malware-laden USB stick without Ubuntu automatically mounting it.
Haven't you ever heard of the "BADUSB" exploit, where a malware-laden USB device first claims to be one type of (innocuous) device, and then later claims to be -- e.g., a mountable volume of some sort. http://thehackernews.com/2014/10/badusb-malware-code-released-turn- usb.html http://www.pcworld.com/article/2840905/badusb-what-you-can-do-about- undetectable-malware-on-a-flash-drive.html http://www.zdnet.com/article/badusb-big-bad-usb-security-problems-ahead/ Henry Baker At 04:23 AM 8/18/2017, Marc Deslauriers wrote: >Thanks for taking the time to report this bug and helping to make Ubuntu >better. We appreciate the difficulties you are facing, but this appears >to be a "regular" (non-security) bug. I have unmarked it as a security >issue since this bug does not show evidence of allowing attackers to >cross privilege boundaries nor directly cause loss of data/privacy. >Please feel free to report any other bugs you may find. > >** Information type changed from Private Security to Public > >-- >You received this bug notification because you are subscribed to the bug >report. >https://bugs.launchpad.net/bugs/1710386 > >Title: > USB drives automount even when automount:false is set > >Status in evince package in Ubuntu: > New > >Bug description: > Turning off automount in dconf worked in 16.04, but no longer works in > 17.04. > > org.gnome.desktop.media-handling current value is false, but USB > insertion still automounts. > > Whose bright idea was it to disable disabling automount? > > ProblemType: Bug > DistroRelease: Ubuntu 17.04 > Package: evince 3.24.0-0ubuntu1.1 > ProcVersionSignature: Ubuntu 4.10.0-32.36-generic 4.10.17 > Uname: Linux 4.10.0-32-generic x86_64 > ApportVersion: 2.20.4-0ubuntu4.5 > Architecture: amd64 > CurrentDesktop: Unity:Unity7 > Date: Sat Aug 12 08:29:09 2017 > InstallationDate: Installed on 2017-08-11 (0 days ago) > InstallationMedia: Ubuntu 17.04 "Zesty Zapus" - Release amd64 (20170412) > SourcePackage: evince > UpgradeStatus: No upgrade log present (probably fresh install) > >To manage notifications about this bug go to: >https://bugs.launchpad.net/ubuntu/+source/evince/+bug/1710386/+subscriptions -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1710386 Title: USB drives automount even when automount:false is set To manage notifications about this bug go to: https://bugs.launchpad.net/ubuntu/+source/evince/+bug/1710386/+subscriptions -- ubuntu-bugs mailing list [email protected] https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs
