Live data from Hacker News

ThinkPwn: System Management Mode arbitrary code execution

github.com

111–120 of 154 posts

Re: ThinkPwn: System Management Mode arbitrary code execution

#111
post #62

Don't just plaster Lenovo with this - they're getting the splatter because Cr4sh has been researching their firmware, but this is a multi-vendor issue. A few important notes from the article and the releaser's blog post: * This is not a Lenovo problem so much as a problem for multiple vendors who used BIOS based on Intel's reference information. The original problem was with source code provided by Intel. The same pr…

Perhaps financial compensation was indeed not Cr4sh's motivation for this zero day, but I felt it's a stretch to call this disclosure responsible. Also his name-calling (ThinkPwn) campaign was inappropriate and premature when the root cause was later discovered in Intel's reference code and propagated to IBVs's products.

I'm much more upset with the vendors that thought UEFI was a good idea and pushed it, than security researches who discover vulnerabilities in UEFI, no matter how they choose to disclose it.

Re: ThinkPwn: System Management Mode arbitrary code execution

#112
post #75

Earlier quoted context omitted.

Yes, with BIOS replaced with free software and wi-fi card replaced with a freedom-respecting one. I do not see any problems in that.

I dislike how it does not do microcode updates though.

You could certainly do the microcode updates yourself.

Re: ThinkPwn: System Management Mode arbitrary code execution

#113

Earlier quoted context omitted.

Well, physical access ranks higher than administrative. If an attacker has physical access, no system is secure, if only because the interface to the system is no longer.

OK, mind telling me how to get root on my iPhone, then? BTW, I have physical access.

The thread above is not talking about a locked down, limited-freedom device like an iPhone. Laptop computers come with the ability to boot from external devices, unlocked and unrestricted.

Re: ThinkPwn: System Management Mode arbitrary code execution

#114
post #75

Earlier quoted context omitted.

I dislike how it does not do microcode updates though.

You could certainly do the microcode updates yourself.

Which would involve needing to reinstall the OS, or at least the kernel, because Trisquel strips out the kernel drivers needed to update the microcode.

Re: ThinkPwn: System Management Mode arbitrary code execution

#115
post #21

Earlier quoted context omitted.

Lenovo has always maintained a higher standard for their Think products, Superfish was only an issue on the Idea line. Doesn't excuse the debacle, but ThinkPad's are their professional line of notebooks and they make every effort to keep a positive image.

Lenovo only maintained the "standard" for their ThinkPads because it was an explicit condition of IBM when they sold the ThinkPad line to Lenovo.

The sale happened ten years ago and it is extremely unlikely that there are any contractual obligations for this anymore. Let's put this meme to rest; Lenovo has been building solid Thinkpads.

Re: ThinkPwn: System Management Mode arbitrary code execution

#116

Earlier quoted context omitted.

Well, physical access ranks higher than administrative. If an attacker has physical access, no system is secure, if only because the interface to the system is no longer.

its not longer fair to call game over with physical access; indeed countermeasure like full disk encryption, computrace and Mac firmware passwords are all examples of things we do to raise the difficulty for a physical attacker.

And the vast majority of them is trivially defeated by a bug inline with your USB keyboard.

Re: ThinkPwn: System Management Mode arbitrary code execution

#117
post #20
post #9

What are we up to now? Three preloaded spyware scandals, possible remote execution via the Intel stack and now this vulnerability. That's just what we know about, who knows what else exists. I don't think I can buy another one, which is sad as I think it was a timeless and great design.

I plan on using my quad core T520 for probably another 5+ years. All of their laptops after the T520 series have the full size keyboard with numberpad which off-sets the center of the keyboard, so now your typing is mostly happing on the left side of the keyboard and that causes wrist strain. Having a numberpad is really lame on a laptop. I won't buy one and I know of no one else that likes the numberpad either.. sad…

Some heavy Excel and Sage users would disagree.

Re: ThinkPwn: System Management Mode arbitrary code execution

#118
post #62

Earlier quoted context omitted.

Perhaps financial compensation was indeed not Cr4sh's motivation for this zero day, but I felt it's a stretch to call this disclosure responsible. Also his name-calling (ThinkPwn) campaign was inappropriate and premature when the root cause was later discovered in Intel's reference code and propagated to IBVs's products.

I'm much more upset with the vendors that thought UEFI was a good idea and pushed it, than security researches who discover vulnerabilities in UEFI, no matter how they choose to disclose it.

UEFI vs BIOS itself isn't the issue. UEFI, the specificaiton, is really a nice interface to the hardware. The issue is with specific implementations of UEFI, and the fact that UEFI firmware vendors (much like traditional BIOS firmware vendors) can churn out hacky code and nobody is the wiser.

Re: ThinkPwn: System Management Mode arbitrary code execution

#119
post #91

> First is the FCC vs WIFI channel selection in firmware. They want the choice to interfere be removed from the user in this occasion. Fuck 'em. > Second is cell carriers are not wild about unknown basebands conversing with their networks. Fuck 'em. > In theory the network should defend against bad phones but they'd rather not test that. ... hard.

Fuck 'em for sure. What can be done, will be done; taking out knobs like that wont prevent the people who would be changing that setting anyway in the long run.

Re: ThinkPwn: System Management Mode arbitrary code execution

#120
post #17

T450S user here. What exactly does this mean for me? I get it's a security issue, but that's about all I understood...

The example exploit is run from an UEFI shell which requires physical control of the device. It mentions exploitation from the OS as a possibility however one would expect that the OS shouldn't allow such operations as a non root user.

Typically physical control is deemed as the game ender. If this is proven to be OS executable it will be a major issue. Many of the Adobe, IE, and other high volume exploit vendors codebase zero-day root exploits would allow one to not only gain access at a root level on a machine, but now also at a much lower level. This level would negate the typical benefits of recovering from a root-level "hack" via HDD erasing or Malware Removal tools or any other method available to even tech-savvy people.
Post reply on HN