Hi Marc:

This is a security bug, because I cannot examine the state of a
potentially malware-laden USB stick without Ubuntu automatically
mounting it.

Haven't you ever heard of the "BADUSB" exploit, where a malware-laden
USB device first claims to be one type of (innocuous) device, and then
later claims to be -- e.g., a mountable volume of some sort.

http://thehackernews.com/2014/10/badusb-malware-code-released-turn-
usb.html

http://www.pcworld.com/article/2840905/badusb-what-you-can-do-about-
undetectable-malware-on-a-flash-drive.html

http://www.zdnet.com/article/badusb-big-bad-usb-security-problems-ahead/

Henry Baker

At 04:23 AM 8/18/2017, Marc Deslauriers wrote:
>Thanks for taking the time to report this bug and helping to make Ubuntu
>better. We appreciate the difficulties you are facing, but this appears
>to be a "regular" (non-security) bug.  I have unmarked it as a security
>issue since this bug does not show evidence of allowing attackers to
>cross privilege boundaries nor directly cause loss of data/privacy.
>Please feel free to report any other bugs you may find.
>
>** Information type changed from Private Security to Public
>
>-- 
>You received this bug notification because you are subscribed to the bug
>report.
>https://bugs.launchpad.net/bugs/1710386
>
>Title:
>  USB drives automount even when automount:false is set
>
>Status in evince package in Ubuntu:
>  New
>
>Bug description:
>  Turning off automount in dconf worked in 16.04, but no longer works in
>  17.04.
>
>  org.gnome.desktop.media-handling current value is false, but USB
>  insertion still automounts.
>
>  Whose bright idea was it to disable disabling automount?
>
>  ProblemType: Bug
>  DistroRelease: Ubuntu 17.04
>  Package: evince 3.24.0-0ubuntu1.1
>  ProcVersionSignature: Ubuntu 4.10.0-32.36-generic 4.10.17
>  Uname: Linux 4.10.0-32-generic x86_64
>  ApportVersion: 2.20.4-0ubuntu4.5
>  Architecture: amd64
>  CurrentDesktop: Unity:Unity7
>  Date: Sat Aug 12 08:29:09 2017
>  InstallationDate: Installed on 2017-08-11 (0 days ago)
>  InstallationMedia: Ubuntu 17.04 "Zesty Zapus" - Release amd64 (20170412)
>  SourcePackage: evince
>  UpgradeStatus: No upgrade log present (probably fresh install)
>
>To manage notifications about this bug go to:
>https://bugs.launchpad.net/ubuntu/+source/evince/+bug/1710386/+subscriptions

-- 
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.
https://bugs.launchpad.net/bugs/1710386

Title:
  USB drives automount even when automount:false is set

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/evince/+bug/1710386/+subscriptions

-- 
ubuntu-bugs mailing list
[email protected]
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs

Reply via email to