So if you have 4 or more USB controllers isolating one for its exclusive
use for kb and mouse is safer than PS/2?

If so that eliminates one of the two main reasons I had for buying a new
mobo for Qubes.  The other is that the new one has a hardware TPM and the
one w/o PS/2 only has a firmware TPM, which isn’t recognized by Qubes or
Ubuntu 18.10

On Wed, Apr 10, 2019 at 3:28 AM unman <un...@thirdeyesecurity.org> wrote:

> On Wed, Apr 10, 2019 at 10:09:54AM +1000, haaber wrote:
> > > On 4/10/19 9:50 AM, jrsmi...@gmail.com wrote:
> > > > The PS/2 keyboard leaking to ground risk seems like it would only
> > > > apply if an attacker had physical access. Is that right or is there a
> > > > way it could be exploited remotely?
> > > >
> > > In principle that can be measured far away, with little hw cost Read
> you
> > > here
> > >
> > >
> https://www.blackhat.com/presentations/bh-usa-09/BARISANI/BHUSA09-Barisani-Keystrokes-SLIDES.pdf
> > >
> > >
> > > you also see that they use a 150 ohm resistance between refence ground
> > > and the ground wire that the computer connects to. That may help as a
> > > setup to measure at home. Distance?  Scheier writes (in July 2009):
> "The
> > > attack has been demonstrated to work at a distance of up to 15m, but
> > > refinement may mean it could work over much longer distances."
> > >
> > Sorry, I forgot to add: countermeasures could be: (1) a low-pass filter
> > to remove frequencies > 200Hz and (2)  white noise injection in the
> > "cleaned" (by step 1) ground wire PS/2 frequency range 10-20 kHz. If you
> > like to solder a bit ... maybe look at "Avalanche Breakdown Diodes" ?
> >
>
> Or use a ground lifter or work off disconnected UPS as needed.
>
> --
> You received this message because you are subscribed to a topic in the
> Google Groups "qubes-users" group.
> To unsubscribe from this topic, visit
> https://groups.google.com/d/topic/qubes-users/uNmSPbt-9L0/unsubscribe.
> To unsubscribe from this group and all its topics, send an email to
> qubes-users+unsubscr...@googlegroups.com.
> To post to this group, send email to qubes-users@googlegroups.com.
> To view this discussion on the web visit
> https://groups.google.com/d/msgid/qubes-users/20190410102757.dbkavoizsjjt4mm5%40thirdeyesecurity.org
> .
> For more options, visit https://groups.google.com/d/optout.
>

-- 
You received this message because you are subscribed to the Google Groups 
"qubes-users" group.
To unsubscribe from this group and stop receiving emails from it, send an email 
to qubes-users+unsubscr...@googlegroups.com.
To post to this group, send email to qubes-users@googlegroups.com.
To view this discussion on the web visit 
https://groups.google.com/d/msgid/qubes-users/CAMCsksHJbOP88CWb9F3%3DjSsOG19rZ_CTDjtak9VGGCwSMZ%3DwNA%40mail.gmail.com.
For more options, visit https://groups.google.com/d/optout.

Reply via email to