[apparmor] Accessing DMI data!?

mailinglisten at posteo.de mailinglisten at posteo.de
Mon Feb 10 15:23:42 UTC 2020


hello,

i just discovered, some apps desire access to DMI data, precisely to
/sys/devices/virtual/dmi/id/

In the case of audio software i can understand it may need to know on
what hardware it runs.

but a web browser? why would a webbrowser need to know the bios version
or computer model name?

the one who really benefits from such information is a possble attacker,
thus for a web browser i would deny access to this data.

what do you think?


-------------- next part --------------
A non-text attachment was scrubbed...
Name: signature.asc
Type: application/pgp-signature
Size: 488 bytes
Desc: OpenPGP digital signature
URL: <https://lists.ubuntu.com/archives/apparmor/attachments/20200210/f337fd08/attachment.sig>


More information about the AppArmor mailing list