As mentioned in #124, our "server room" isn't really locked down, which means that our hardware could be tampered with even just by visitors.
What are the security implications of this?
Is there a way of preventing random ppl from just plugging in usb's or similar?
Is secure boot a thing on nixos?
As mentioned in #124, our "server room" isn't really locked down, which means that our hardware could be tampered with even just by visitors.
What are the security implications of this?
Is there a way of preventing random ppl from just plugging in usb's or similar?
Is secure boot a thing on nixos?
ahtlon
added the Security label 2026-02-25 05:02:29 +01:00
ahtlon
added this to the Security project 2026-02-25 05:02:29 +01:00
ahtlon
moved this to High Severity in Security on 2026-02-25 05:02:39 +01:00
ahtlon
moved this to Medium Severity in Security on 2026-02-25 05:14:39 +01:00
Maybe we could try to physically disable some usb ports.
We could setup [tamper protection](https://mullvad.net/en/help/how-tamper-protect-laptop?page=/en/help/how-tamper-protect-laptop).
This was done already with the malobeo laptop and it makes sense to do something similar on fanny.
There is a wiki entry on secure boot: https://wiki.nixos.org/wiki/Secure_Boot
Maybe we could try to physically disable some usb ports.
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
As mentioned in #124, our "server room" isn't really locked down, which means that our hardware could be tampered with even just by visitors.
What are the security implications of this?
Is there a way of preventing random ppl from just plugging in usb's or similar?
Is secure boot a thing on nixos?
We could setup tamper protection.
This was done already with the malobeo laptop and it makes sense to do something similar on fanny.
There is a wiki entry on secure boot: https://wiki.nixos.org/wiki/Secure_Boot
Maybe we could try to physically disable some usb ports.