Live data from Hacker News

MSI firmware signing keys leaked

github.com

11–20 of 37 posts

Re: MSI firmware signing keys leaked

#11
post #7

Why were these keys not in a HSM I wonder..

It's possible they did, in any case keys can be exported from HSMs to ensure availability in the event that your HSM becomes inoperable and needs to be replaced.

For example here are instructions on how to do so with a Thales HSM https://thalesdocs.com/gphsm/ptk/5.4/docs/Content/PTK-C_Admi...

Re: MSI firmware signing keys leaked

#20

Is it wrong that my immediate reaction to this is, "Sweet, so I can finally do things with my board I was prevented from before!"

[flagged]

Secure Boot was already very broken on these boards. By default it does nothing and even if you change settings so that it actually does validation, it should be possible to reset it back from the OS by updating the firmware from the OS as there are no locks for the firmware region.
Post reply on HN