如何在公共场所保障Coral Dev Board安全?防止未授权物理访问咨询
Great question—securing a Coral Dev Board that auto-logs in and is accessible via any connected keyboard requires a mix of OS-level hardening and physical safeguards. Let's break down the most effective steps:
1. Disable Auto-Login (The First Line of Defense)
Since the device auto-logs in by default, that's the biggest vulnerability to fix first. Coral Dev Boards run Mendel Linux, which uses LightDM as the display manager. Here's how to turn off auto-login:
- Open the LightDM config file with sudo privileges:
sudo nano /etc/lightdm/lightdm.conf - Find the
[Seat:*]section, then modify or add these lines (clear theautologin-uservalue):autologin-user= autologin-user-timeout=0 - Save and exit (Ctrl+O, Enter, then Ctrl+X), then restart LightDM to apply changes:
sudo systemctl restart lightdm
After this, the board will prompt for a user password on boot instead of logging in automatically.
2. Harden TTY Session Access
Even if you lock the graphical desktop, someone could switch to a TTY terminal (using Ctrl+Alt+F1 to F6) and log in there. Make sure TTY sessions don't auto-login either:
- Check if an auto-login config exists for TTY1:
ls /etc/systemd/system/getty@tty1.service.d/ - If you see an
autologin.conffile, delete it or comment out the auto-login line:
Comment out thesudo nano /etc/systemd/system/getty@tty1.service.d/autologin.confExecStartline that overrides the default getty command, like this:# ExecStart=-/sbin/agetty --autologin your_username --noclear %I $TERM - Reload systemd to apply changes:
sudo systemctl daemon-reload
Also, ensure all user accounts have strong, unique passwords—this is non-negotiable for physical security.
3. Enable Automatic Screen Locking
Even with password-protected login, if you leave the device unlocked, anyone can access it. Set up automatic screen locking in the desktop environment (Mendel uses LXDE by default):
- Open the Screensaver settings: Go to Menu > Preferences > Screensaver
- Check "Lock screen after X minutes of inactivity" (set a short timeout, like 1-2 minutes)
- Make sure "Require password to unlock" is checked
- Optional: Set a custom hotkey (like Ctrl+Alt+L) to lock the screen instantly when you step away.
4. Block Unauthorized USB Input Devices
To prevent random keyboards from being used to access the device, you can use udev rules to whitelist only your authorized keyboard and block all other USB input devices:
- Plug in your authorized keyboard, then run
lsusbto get its vendor ID and product ID. Look for a line like:
Here,Bus 001 Device 003: ID 1234:5678 My Trusted Keyboard1234is the vendor ID and5678is the product ID. - Create a new udev rule file:
sudo nano /etc/udev/rules.d/99-block-unauthorized-keyboards.rules - Add these lines (replace the IDs with your keyboard's values):
# Allow our trusted USB keyboard SUBSYSTEM=="usb", ATTRS{idVendor}=="1234", ATTRS{idProduct}=="5678", MODE="0666" # Block all other USB human interface devices (keyboards/mice) SUBSYSTEM=="usb", ATTRS{bInterfaceClass}=="03", ATTRS{bInterfaceSubClass}=="01", MODE="0000", ENV{UDISKS_IGNORE}="1" - Reload udev rules to activate them:
sudo udevadm control --reload-rules && sudo udevadm trigger
Important: Test this thoroughly before leaving the device unattended—make sure your authorized keyboard works, otherwise you might lock yourself out!
5. Physical Safeguards (Final Layer)
Software fixes are great, but physical security is the last line of defense:
- Place the Coral Dev Board in a locked enclosure (like a small metal lockbox) that only exposes necessary ports (power, network—hide USB ports unless absolutely needed)
- If you need occasional USB access, use a locked USB hub with only your authorized keyboard plugged in, secured inside the enclosure.
内容的提问来源于stack exchange,提问作者Alexandru Cocîndă

