Hughes: Updating Logitech Hardware on Linux
Richard Hughes describeshis work to address the MouseJackvulnerability in Logitech (and other) receivers. This vulnerability allows anattacker to pair new devices with the receiver with no user interaction orawareness, and, thus, take over the machine. "This makessitting in a cafi(C) quite a dangerous thing to do when any affected hardwareis inserted, which for the unifying dongle is quite likely as it'sexplicitly designed to remain in an empty USB socket."
Logitech has provided firmware updates, but not for "unsupported" platformslike Linux. Hughes has filled that gap by getting documentation and afixed firmware image from Logitech and adding support for these devices tofwupd. He is now looking for testers to ensure that the whole thing worksacross all devices. This is important work that is well worth supporting.