CosmicStrand: The discovery of a sophisticated UEFI firmware rootkit
1–10 of 125 posts
Re: CosmicStrand: The discovery of a sophisticated UEFI firmware rootkit
#2I always marvel at the ingenuity and technical complexity of these kinds of attacks, but this is also something that makes me lose sleep at night.
I can’t help but wonder just how utterly compromised we all are, and won’t know it until many years down the line.
Re: CosmicStrand: The discovery of a sophisticated UEFI firmware rootkit
#3It's silly to pretend a BSD OS is going to be immune of the consequences of an EFI which is compromised at birth. Sooner or later there will be a value chain in compromising my OS, through the EFI.
I wish we had better out of band EFI validity checks, based on what the manufacturer thinks should be there, as a reproducible bitstream.
Re: CosmicStrand: The discovery of a sophisticated UEFI firmware rootkit
#4I live in fear of being told my factory delivered Dell rackable servers have been EFI infected since inception on my network. It's silly to pretend a BSD OS is going to be immune of the consequences of an EFI which is compromised at birth. Sooner or later there will be a value chain in compromising my OS, through the EFI. I wish we had better out of band EFI validity checks, based on what the manufacturer thinks shou…
https://www.dell.com/support/kbdoc/en-us/000126098/what-is-d...
Re: CosmicStrand: The discovery of a sophisticated UEFI firmware rootkit
#5And so... this could be undetected just because kaspersy isn't being used anymore?
Re: CosmicStrand: The discovery of a sophisticated UEFI firmware rootkit
#6ugh
Re: CosmicStrand: The discovery of a sophisticated UEFI firmware rootkit
#7(A rain of downvotes falls on me)
Seriously, even good old BIOS is susceptible to rootkits, there has been tons of them. So no crying over UEFI please.
We need a fully signed and auditable chain of trust for booting OSes.
Of course all this crap needs to be open source but it needs to be locked down to prevent not trusted binaries as much as possible.
And for the 1% of people who are going to bang about their right own the hardware and run Linux and what not (I'm definitely one of those), we need to be able to do it but in an obvious way (computer should boot but display a clear message that it's been tinkerer with).
I really like software freedom, but the fact that I can disable secure boot on pretty much any computer I have physical access to and that the user will never know about it is not okay.
Re: CosmicStrand: The discovery of a sophisticated UEFI firmware rootkit
#8That's why things like the Pluton processor and TPMs are useful. (A rain of downvotes falls on me) Seriously, even good old BIOS is susceptible to rootkits, there has been tons of them. So no crying over UEFI please. We need a fully signed and auditable chain of trust for booting OSes. Of course all this crap needs to be open source but it needs to be locked down to prevent not trusted binaries as much as possible. A…
Alert fatigue is real.
Re: CosmicStrand: The discovery of a sophisticated UEFI firmware rootkit
#9That's why things like the Pluton processor and TPMs are useful. (A rain of downvotes falls on me) Seriously, even good old BIOS is susceptible to rootkits, there has been tons of them. So no crying over UEFI please. We need a fully signed and auditable chain of trust for booting OSes. Of course all this crap needs to be open source but it needs to be locked down to prevent not trusted binaries as much as possible. A…
"I'm sorry but your computer is not running Genuine Windows 11:tm:. You may not be secure." will be the new "An application is attempting to make changes to your computer..." Alert fatigue is real.
Also, it's not just about booting windows or the OS, it's about the UEFI, which even fewer people are going to want to tinker with.
Re: CosmicStrand: The discovery of a sophisticated UEFI firmware rootkit
#10That's why things like the Pluton processor and TPMs are useful. (A rain of downvotes falls on me) Seriously, even good old BIOS is susceptible to rootkits, there has been tons of them. So no crying over UEFI please. We need a fully signed and auditable chain of trust for booting OSes. Of course all this crap needs to be open source but it needs to be locked down to prevent not trusted binaries as much as possible. A…
- it's proprietary
- it's controlled by entities that have a terrible track record
- it's going to be, as usual, forced upon everybody without consent