How the Top Five PC Makers Open Your Laptop to Hackers: https://www.wired.com/2016/05/2036876/
ASUS delivers BIOS/UEFI auto-updates over HTTP with no verification
41–50 of 200 posts
Re: ASUS delivers BIOS/UEFI auto-updates over HTTP with no verification
#42Re: ASUS delivers BIOS/UEFI auto-updates over HTTP with no verification
#43Damn ASUS that's a real shame, because that Royal Blue Zenbook 3 is god damn sexy https://www.asus.com/Notebooks/ASUS-ZenBook-3-UX390UA/
Doesn't it affect only those who run Windows with this ASUS LiveUpdate thing installed? But perhaps you meant that you must now, as a protest, shun ASUS products. I can sympathise with that.
I usually reformat them on arrival anyway.
Re: ASUS delivers BIOS/UEFI auto-updates over HTTP with no verification
#44IMHO the BIOS is not something that should ever change unless there's a very important reason to, and even then it should be on the explicit action and consent of the user, because of the risks of ending up with a completely non-working machine. UEFI is a whole new mess, but I think the same principle applies.
Re: ASUS delivers BIOS/UEFI auto-updates over HTTP with no verification
#45Wow. I always knew hardware manufacturers half-assed their software, but this is kind of a new low. I'm not sure whether to laugh or cry.
Could be worse, the title made me imagine UEFI firmware itself making HTTP downloads and reflashing itself ;)
Re: ASUS delivers BIOS/UEFI auto-updates over HTTP with no verification
#46Damn ASUS that's a real shame, because that Royal Blue Zenbook 3 is god damn sexy https://www.asus.com/Notebooks/ASUS-ZenBook-3-UX390UA/
I checked the liveupdate01.asus.com and dlcdnet.asus.com domains referenced in the article, and they can certainly serve over HTTPS...
Re: ASUS delivers BIOS/UEFI auto-updates over HTTP with no verification
#47Earlier quoted context omitted.
Could be worse, the title made me imagine UEFI firmware itself making HTTP downloads and reflashing itself ;)
Newer motherboards with ASUS EZ Flash can do that. I don't think it's automatic though.
Convenience and security are often orthogonal.
Re: ASUS delivers BIOS/UEFI auto-updates over HTTP with no verification
#48Re: ASUS delivers BIOS/UEFI auto-updates over HTTP with no verification
#49Poor security hygiene is by no means unique to Asus' motherboards' firmware updates. You can find bad practices in all sorts of embedded systems' firmware updates. Manual downloads of router firmware are an excellent example of this, and that includes third party OSS firmware such as DD-WRT. The Obihai ATAs will auto-update over HTTP although I have not checked if they do any sort of code signing. I have seen OSS liv…
The flip-side is that this isn't the sort of security most of us want, and the fact that router firmware is "insecure" from this perspective is what enables things like DD-WRT to exist in the first place. See also: iOS jailbreaking, Android rooting, console homebrew, etc.
Re: ASUS delivers BIOS/UEFI auto-updates over HTTP with no verification
#50Very nice find. What are the business unit motivations behind critical suppliers like ASUS repeatedly violating customer trust in this manner? At what point in the management chain is the decision reached to sacrifice reputation for - whatever cost savings there are from not implementing TLS/blob signing? edit: This is not rhetorical. Actually curious if someone on HN familiar with this class of companies (ASUS is no…
It's hard to make a case for long term support of commodity hardware sold into the consumer market because the most shiny things at the lowest first tends to drive purchases. It's as true for laptops as it is for Android phones. BestBuy doesn't care if it stocks ASUS or not. It cares about sales and margins. If there's an extra dollar putting Gateway on the shelf instead of ASUS they will. And their customers won't c…
It's a shame because they make really good hardware.