Hacker News new | ask | show | jobs
by moosingin3space 2419 days ago
You can use an IOMMU to isolate DMA to a separate security domain. This is how Qubes OS works.
1 comments

No iommu on the imx8mq.
That's unfortunate, since an IOMMU is an excellent solution to this kind of problem, especially when one considers all the potential Linux USB stack vulnerabilities that can be exploited if you assume the modem is untrustworthy.