clarify USB security changes

This commit is contained in:
Daniel Micay 2024-06-19 18:58:13 -04:00
parent 0e28e2b725
commit 441c18784b

View File

@ -782,10 +782,10 @@
<p>Changes since the 2024061400 release:</p> <p>Changes since the 2024061400 release:</p>
<ul> <ul>
<li>hide USB peripheral security setting when USB-C port setting is available</li> <li>remove our USB peripheral security setting on devices supporting our much better USB-C port mode (Pixel 6 and later)</li>
<li>extend USB-C port setting to pogo pins (for Pixel Tablet)</li> <li>extend USB-C port setting to also handle pogo pins on the Pixel Tablet</li>
<li>kernel (5.10, 5.15, 6.1, 6.6): replace our deny_new_usb feature with a new deny_new_usb2 feature also disabling USB gadgets</li> <li>kernel (5.10, 5.15, 6.1, 6.6): replace our deny_new_usb feature with a new deny_new_usb2 feature also disabling USB gadgets</li>
<li>extend USB-C port setting to enable deny_new_usb2 as a second layer of defense beyond low-level hardware disabling of new USB connections and then USB data</li> <li>extend USB-C port setting to enable deny_new_usb2 as a second layer of defense disablingf new USB connections and then USB data at a hardware level, in case the USB controller is compromised or doesn't work correctly</li>
<li>require user authentication for changing auto-reboot, USB peripheral and USB-C port security settings</li> <li>require user authentication for changing auto-reboot, USB peripheral and USB-C port security settings</li>
<li>temporarily add back memory tagging exception for Pixel wifi_ext service</li> <li>temporarily add back memory tagging exception for Pixel wifi_ext service</li>
<li>add GrapheneOS Linux kernel port to the 6.6 GKI LTS branch</li> <li>add GrapheneOS Linux kernel port to the 6.6 GKI LTS branch</li>