Earlier quoted context omitted.
Make it a button, so the customer can apply updates, but they need to press a button to make it happen. Add another button which, using only software stored in ROM, reloads the firmware from ROM. Then you have updates, but only when the customer knows and wants it, and if they ever screw it up then they can get back to a known good state.
The customer has no way of knowing whether they are installing genuine update, or MITM-modified malicious update. Public key cryptography solves that but then you have a problem how to protect the keys and crypto algorithms from tampering. Update buttons ain't a good replacement for TPM hardware.
Researchers crack open malware that hid for 5 years
221–230 of 232 posts
Re: Researchers crack open malware that hid for 5 years
#222Earlier quoted context omitted.
Are you including the capability to control it over a network? Burning potentially unfixable 0-day exploits into ROM would probably be a non-starter.
If you can update the firmware over a network, you have an uncloseable exploit vector. ROMs are not unfixable. They do require physical access, though, which eliminates nearly all of the risk.
Re: Researchers crack open malware that hid for 5 years
#223Earlier quoted context omitted.
What do you mean "attack"? Is there some specific harm being done that you want to protect against? Breach of defenses isn't itself an attack. A foreign agent inside your castle isn't an attacker until they start stabbing people, right? I'm not personally worried about what Chinese and Russian hackers know about me, because none of that information is particularly useful for taking valuables from me. I am curious wha…
How do you assume that the information isn't useful? That implies that all your valuables are fully isolated from the digital world - really? I really have trouble understanding the "I have nothing to hide" attitude. What's the difference to saying "there is this guy always standing in the corner of my living room, but I'll just assume he's benign..."
Re: Researchers crack open malware that hid for 5 years
#224Re: Researchers crack open malware that hid for 5 years
#225Earlier quoted context omitted.
And that's why you can still buy new i7 and Xeon motherboards with PS2 keyboard connectors--because some sites don't want there to be USB ports on the computers.
My computer is locked in a mesh cage anyway. Well, the thin client is.
Re: Researchers crack open malware that hid for 5 years
#226Earlier quoted context omitted.
SUSE is owned by Novell.
Not anymore, IIRC. When Novell was acquired by ... that company whose name I forgot (AttachMate?), SUSE was spun off as an independent company again. At least that is how I remember it.
Novell bought Suse, then Novell merged with Attachemate, in the process Suse became a business unit (wholly owned company?) under Attachemate, then there was a merger between Attachemate and Micro Focus in 2014.
Anyways, i suspect that as Suse is FOSS, and was initially Germany based, and now is UK based, both being NATO allies, that DOD has few issues with continued usage.
Re: Researchers crack open malware that hid for 5 years
#227Earlier quoted context omitted.
There's also value in being able to visually inspect it and say "Yep, that USB port's disabled" versus digging through EFI settings. Every motherboard is going to have that option in a slightly different place, but if you can put epoxy in one USB port you're pretty well set for any piece of hardware.
This scales to ${number_of_devices_you_can_see}. A hundred or more? Easier to manage remotely. You're also likely to have a very limited number of models in that case.
Consider another instance of the problem: verifying that your webcam isn't being used to spy on you. Since a surprising number of hardware designers were negligent and made that software controllable it is orders of magnitude easier to simply deploy a piece of tape than try to prove that malware hasn't disabled the status LED:
http://security.stackexchange.com/questions/6758/can-webcams... http://blog.erratasec.com/2013/12/how-to-disable-webcam-ligh...
How much skill and diligence does it take to confirm that you have disabled the controller using each manufacturer's interface (if they even have one documented), that there isn't some way to re-enable it later (or that something like a sleep/resume cycle didn't reset the controller), and that all of that continues to be true for every subsequent configuration change or software/firmware update?
I would suggest that any organization with this level of risk would be better off paying someone $15/hour to check the ports along with the rest of their physical status checks and put the security engineers in charge of other improvements with a higher return.
Re: Researchers crack open malware that hid for 5 years
#228Earlier quoted context omitted.
If you just leave away the USB mass storage kernel module when compiling the kernel, the mass storage device won't work anymore while the mouse still works. I wonder if this is a solution to this problem or not since it seems quite naive.
Any USB device gets to be a keyboard and mouse. If it comes down to it, the device could just "type" its payload.
In fact, all of this would work equally well with a PS/2 port.
Re: Researchers crack open malware that hid for 5 years
#229Earlier quoted context omitted.
The customer has no way of knowing whether they are installing genuine update, or MITM-modified malicious update. Public key cryptography solves that but then you have a problem how to protect the keys and crypto algorithms from tampering. Update buttons ain't a good replacement for TPM hardware.
It's an enormously harder problem to convince the customer to push the "update firmware" button on the front panel than it is to insert malware remotely without any action or knowledge on the customer's part.
For the end user, it’s extremely easy to NOT push that button.
Re: Researchers crack open malware that hid for 5 years
#230Earlier quoted context omitted.
Russia, Iran, Rwanda... Let's assume the latter is a vector, not the target. (The attacker is sophisticated enough that we can assume Rwanda itself is of little interest). Rwanda also has fairly close ties to Russia, which strengthens the vector hypothesis. Russia+Iran suggests a western actor. Their biggest shared interest is Syria, I'd think. And look, the Syrian conflict is on since March '11, and the activity acc…
> and also isn't friends with Iran or Russia Actually Israel is on very friendly terms with Russia. There are a ton of Russian immigrants in Israel to the point that Putin called them "Russian ambassadors". It didn't start that way - part of the history of the creation of the modern state of Israel is Russia vs US proxy conflict (of sorts) via Egypt. But it's not like that anymore, not for a long time. (The US and Ru…