Live data from Hacker News

CosmicStrand: The discovery of a sophisticated UEFI firmware rootkit

securelist.com

1–10 of 125 posts

Re: CosmicStrand: The discovery of a sophisticated UEFI firmware rootkit

#2
> The most striking aspect of this report is that this UEFI implant seems to have been used in the wild since the end of 2016 – long before UEFI attacks started being publicly described. This discovery begs a final question: if this is what the attackers were using back then, what are they using today?

I always marvel at the ingenuity and technical complexity of these kinds of attacks, but this is also something that makes me lose sleep at night.

I can’t help but wonder just how utterly compromised we all are, and won’t know it until many years down the line.

Re: CosmicStrand: The discovery of a sophisticated UEFI firmware rootkit

#3
I live in fear of being told my factory delivered Dell rackable servers have been EFI infected since inception on my network.

It's silly to pretend a BSD OS is going to be immune of the consequences of an EFI which is compromised at birth. Sooner or later there will be a value chain in compromising my OS, through the EFI.

I wish we had better out of band EFI validity checks, based on what the manufacturer thinks should be there, as a reproducible bitstream.

Re: CosmicStrand: The discovery of a sophisticated UEFI firmware rootkit

#4
post #3

I live in fear of being told my factory delivered Dell rackable servers have been EFI infected since inception on my network. It's silly to pretend a BSD OS is going to be immune of the consequences of an EFI which is compromised at birth. Sooner or later there will be a value chain in compromising my OS, through the EFI. I wish we had better out of band EFI validity checks, based on what the manufacturer thinks shou…

You can use the Dell Trusted Agent to to do just that:

https://www.dell.com/support/kbdoc/en-us/000126098/what-is-d...

Re: CosmicStrand: The discovery of a sophisticated UEFI firmware rootkit

#6
as a civilian, I am repeatedly amazed at the relentless, intrusive and manipulative tactics that the "heroes" use on the "sheep" .. I am quite capable of managing my own affairs and have invented and solved using computers for decades. I have a sense of personal sovreignty that is offended and threatened by one-way-mirror, controlling, destructive Spy-vs-Spy comic books being played out by eternally funded jerks. I am not running to DELL to save me from "scary" hacks -- indeed, I am being victimized and trodden on by DELL and "state actors" .. DELL is a "state actor" ..

ugh

Re: CosmicStrand: The discovery of a sophisticated UEFI firmware rootkit

#7
That's why things like the Pluton processor and TPMs are useful.

(A rain of downvotes falls on me)

Seriously, even good old BIOS is susceptible to rootkits, there has been tons of them. So no crying over UEFI please.

We need a fully signed and auditable chain of trust for booting OSes.

Of course all this crap needs to be open source but it needs to be locked down to prevent not trusted binaries as much as possible.

And for the 1% of people who are going to bang about their right own the hardware and run Linux and what not (I'm definitely one of those), we need to be able to do it but in an obvious way (computer should boot but display a clear message that it's been tinkerer with).

I really like software freedom, but the fact that I can disable secure boot on pretty much any computer I have physical access to and that the user will never know about it is not okay.

Re: CosmicStrand: The discovery of a sophisticated UEFI firmware rootkit

#8
post #7

That's why things like the Pluton processor and TPMs are useful. (A rain of downvotes falls on me) Seriously, even good old BIOS is susceptible to rootkits, there has been tons of them. So no crying over UEFI please. We need a fully signed and auditable chain of trust for booting OSes. Of course all this crap needs to be open source but it needs to be locked down to prevent not trusted binaries as much as possible. A…

"I'm sorry but your computer is not running Genuine Windows 11:tm:. You may not be secure." will be the new "An application is attempting to make changes to your computer..."

Alert fatigue is real.

Re: CosmicStrand: The discovery of a sophisticated UEFI firmware rootkit

#9
post #7

That's why things like the Pluton processor and TPMs are useful. (A rain of downvotes falls on me) Seriously, even good old BIOS is susceptible to rootkits, there has been tons of them. So no crying over UEFI please. We need a fully signed and auditable chain of trust for booting OSes. Of course all this crap needs to be open source but it needs to be locked down to prevent not trusted binaries as much as possible. A…

"I'm sorry but your computer is not running Genuine Windows 11:tm:. You may not be secure." will be the new "An application is attempting to make changes to your computer..." Alert fatigue is real.

Alert fatigue is real but silent rootkits are way worse.

Also, it's not just about booting windows or the OS, it's about the UEFI, which even fewer people are going to want to tinker with.

Re: CosmicStrand: The discovery of a sophisticated UEFI firmware rootkit

#10
post #7

That's why things like the Pluton processor and TPMs are useful. (A rain of downvotes falls on me) Seriously, even good old BIOS is susceptible to rootkits, there has been tons of them. So no crying over UEFI please. We need a fully signed and auditable chain of trust for booting OSes. Of course all this crap needs to be open source but it needs to be locked down to prevent not trusted binaries as much as possible. A…

The problem with pluton is not the tech. It's that:

- it's proprietary

- it's controlled by entities that have a terrible track record

- it's going to be, as usual, forced upon everybody without consent

Post reply on HN