The Security Liability
Ubuntu is designed for a user-friendly desktop experience, which means its default file manager (Nautilus) behaves much like Windows or macOS. Whenever you plug in an external USB flash drive or a portable hard drive, Ubuntu automatically detects the hardware, mounts the filesystem, and often opens a new window displaying the drive’s contents. While convenient for personal laptops, this automatic mounting is a severe security risk on public-facing workstations, kiosks, or servers. Automatically mounting an unknown USB drive can expose the system to malicious scripts, corrupted filesystems, or unauthorized data extraction.
Disabling the Automount Daemon
To secure your machine and ensure that external drives are only mounted when explicitly commanded by an administrator, you must disable the desktop automount feature via the GNOME settings database.
Because this is a core desktop behavior, you must modify it using the terminal. Open your terminal application (Ctrl+Alt+T). You will use the gsettings command to alter the media-handling schemas. Type the following command exactly as written: gsettings set org.gnome.desktop.media-handling automount false and press Enter. Next, to prevent Ubuntu from even attempting to open a folder window if a drive *is* manually mounted, type: gsettings set org.gnome.desktop.media-handling automount-open false and press Enter. The changes take effect immediately. From now on, when you insert a USB drive, the system will recognize the hardware, but it will remain unmounted and inaccessible until you manually click on it in the file manager sidebar and provide your user password.