ASUS delivers BIOS/UEFI auto-updates over HTTP with no verification
teletext.zaibatsutel.net
ASUS delivers BIOS/UEFI auto-updates over HTTP with no verification
1–10 of 200 posts
Re: ASUS delivers BIOS/UEFI auto-updates over HTTP with no verification
#2I'm not sure whether to laugh or cry.
Re: ASUS delivers BIOS/UEFI auto-updates over HTTP with no verification
#3Wow. I always knew hardware manufacturers half-assed their software, but this is kind of a new low. I'm not sure whether to laugh or cry.
I think someone should write a 'virus' that would remove that vulnerable software from users' computers.
Re: ASUS delivers BIOS/UEFI auto-updates over HTTP with no verification
#4i mean, what else is there?
Re: ASUS delivers BIOS/UEFI auto-updates over HTTP with no verification
#5Re: ASUS delivers BIOS/UEFI auto-updates over HTTP with no verification
#6Wow. I always knew hardware manufacturers half-assed their software, but this is kind of a new low. I'm not sure whether to laugh or cry.
Re: ASUS delivers BIOS/UEFI auto-updates over HTTP with no verification
#7edit: This is not rhetorical. Actually curious if someone on HN familiar with this class of companies (ASUS is not unique among OEMs) can educate.
Re: ASUS delivers BIOS/UEFI auto-updates over HTTP with no verification
#8https://duo.com/assets/pdf/out-of-box-exploitation_oem-updat...
Re: ASUS delivers BIOS/UEFI auto-updates over HTTP with no verification
#9Very nice find. What are the business unit motivations behind critical suppliers like ASUS repeatedly violating customer trust in this manner? At what point in the management chain is the decision reached to sacrifice reputation for - whatever cost savings there are from not implementing TLS/blob signing? edit: This is not rhetorical. Actually curious if someone on HN familiar with this class of companies (ASUS is no…
Re: ASUS delivers BIOS/UEFI auto-updates over HTTP with no verification
#10Very nice find. What are the business unit motivations behind critical suppliers like ASUS repeatedly violating customer trust in this manner? At what point in the management chain is the decision reached to sacrifice reputation for - whatever cost savings there are from not implementing TLS/blob signing? edit: This is not rhetorical. Actually curious if someone on HN familiar with this class of companies (ASUS is no…