Elektrine lite

← Feed

@alexhaydock@infosec.exchange

Post #1630648

2026-04-23 12:13 UTC

The UK NCSC are releasing some kind of inline display connection widget thing to “secure” HDMI and DisplayPort connections. Really struggling to understand the threat model on this one… it seems so badly explained in the post. Are they trying to suggest channels like EDID or HDMI CEC are actual threat vectors? Or maybe it’s an attempt to defend against people plugging in inline capture cards or something? (Can’t really see how that’d work anyway) :neocat_googly: https://www.ncsc.gov.uk/news/world-first-ncsc-engineered-device-secures-vulnerable-display-links

Replies (4)

  • I crave details, NCSC! Give me your threat model! :neocat_glare:

    Open ##1913745

  • @mal3aby@mastodon.smears.org 2026-04-23 12:55

    @alexhaydock I mean, Ethernet-over-HDMI (HEC) is a thing - maybe it's that? Though I'm not sure I've ever actually seen one in the wild... I too would love to know what this is about :)

    Open ##1913751

  • @phlash@mastodon.me.uk 2026-04-23 13:11

    @alexhaydock Possibly this threat: https://arxiv.org/abs/2407.09717 ..but more likely attacks against the EDID and HEC support in display drivers, especially as HEC is largely abandoned and probably the driver code has had little attention for years.

    Open ##1913752

  • @gilester45@twit.social 2026-04-23 15:19

    @alexhaydock Oh great, because HDMI, HDCP, CEC and EDID all work so seamlessly already, let's add more complexity.

    Open ##1913753