Live data from Hacker News

ASUS delivers BIOS/UEFI auto-updates over HTTP with no verification

teletext.zaibatsutel.net

1–10 of 200 posts

Re: ASUS delivers BIOS/UEFI auto-updates over HTTP with no verification

#3

Wow. I always knew hardware manufacturers half-assed their software, but this is kind of a new low. I'm not sure whether to laugh or cry.

Worst part is that they didn't even respond to responsible disclosure.

I think someone should write a 'virus' that would remove that vulnerable software from users' computers.

Re: ASUS delivers BIOS/UEFI auto-updates over HTTP with no verification

#6

Wow. I always knew hardware manufacturers half-assed their software, but this is kind of a new low. I'm not sure whether to laugh or cry.

Could be worse, the title made me imagine UEFI firmware itself making HTTP downloads and reflashing itself ;)

Re: ASUS delivers BIOS/UEFI auto-updates over HTTP with no verification

#7
Very nice find. What are the business unit motivations behind critical suppliers like ASUS repeatedly violating customer trust in this manner? At what point in the management chain is the decision reached to sacrifice reputation for - whatever cost savings there are from not implementing TLS/blob signing?

edit: This is not rhetorical. Actually curious if someone on HN familiar with this class of companies (ASUS is not unique among OEMs) can educate.

Re: ASUS delivers BIOS/UEFI auto-updates over HTTP with no verification

#9
post #7

Very nice find. What are the business unit motivations behind critical suppliers like ASUS repeatedly violating customer trust in this manner? At what point in the management chain is the decision reached to sacrifice reputation for - whatever cost savings there are from not implementing TLS/blob signing? edit: This is not rhetorical. Actually curious if someone on HN familiar with this class of companies (ASUS is no…

Don't assume that there is any decision process. Those hardware makers are famous for not getting software. Probably the intern who wrote the downloader did not know who to talk to to get the certificate purchased.

Re: ASUS delivers BIOS/UEFI auto-updates over HTTP with no verification

#10
post #7

Very nice find. What are the business unit motivations behind critical suppliers like ASUS repeatedly violating customer trust in this manner? At what point in the management chain is the decision reached to sacrifice reputation for - whatever cost savings there are from not implementing TLS/blob signing? edit: This is not rhetorical. Actually curious if someone on HN familiar with this class of companies (ASUS is no…

I think in many cases there's no conscious decision not to implement TLS or code signing. It could just be that no one who cares enough about security is in a position to drive that change. There are many organizations that quite simply lack any kind of security culture.
Post reply on HN