Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

You can use an IOMMU to isolate DMA to a separate security domain. This is how Qubes OS works.


No iommu on the imx8mq.


That's unfortunate, since an IOMMU is an excellent solution to this kind of problem, especially when one considers all the potential Linux USB stack vulnerabilities that can be exploited if you assume the modem is untrustworthy.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: