The Security Vulnerability
Desktop versions of Ubuntu Linux are designed to be user-friendly. Because of this, they utilize a background service called udisks2. This daemon constantly monitors your hardware ports. If you plug a USB flash drive into the computer, udisks2 automatically mounts the filesystem and frequently opens a file manager window displaying its contents. In a secure server environment, or on a public-facing kiosk machine, this behavior is a massive security risk. An attacker could plug in a maliciously crafted USB drive that exploits the auto-mounting process to execute code before you even touch the keyboard. To harden your system, you must disable the auto-mount daemon.
How to Disable USB Auto-Mount via GSettings
You can instruct the GNOME desktop environment to completely ignore new storage volumes using the terminal.
- Open your Terminal application (Ctrl + Alt + T) or log into your machine via SSH.
- Type the following command exactly as written:
gsettings set org.gnome.desktop.media-handling automount false- Press Enter.
- To also prevent the system from automatically opening the folder if you mount it manually, type:
gsettings set org.gnome.desktop.media-handling automount-open false- Press Enter.
Manual Intervention Required
The change takes effect immediately for your specific user account. The next time you plug a USB drive into the computer, absolutely nothing will happen on the screen. The operating system will recognize that hardware is attached, but it will stubbornly refuse to interact with the filesystem. To access the data, you must now open the file manager, locate the greyed-out drive in the left-hand sidebar, and explicitly click on it to mount it manually, ensuring you have total control over when external code is processed.