Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Adding info about thunderbolt 3 security and security levels #31

Open
wants to merge 1 commit into
base: master
Choose a base branch
from
Open
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
6 changes: 5 additions & 1 deletion linux-workstation-security.md
Original file line number Diff line number Diff line change
@@ -1,6 +1,6 @@
# Linux workstation security checklist

Updated: 2017-12-15
Updated: 2019-08-22

*Status: CURRENT*

Expand Down Expand Up @@ -98,6 +98,10 @@ ExpressCard are guilty of the same, though some later implementations of
Thunderbolt attempt to limit the scope of memory access. It is best if the
system you are getting has none of these ports, but it is not critical, as
they usually can be turned off via UEFI or disabled in the kernel itself.
If you are getting a system that has Thunderbolt 3, it is best if you plan on
leaving it enabled to ensure that Thunderbolt security is enabled and if security
levels are supported it is set to User Authorzation. This will prevent Thunderbolt
devices from attaching to the system without the user's knowledge.

#### TPM Chip

Expand Down