Earlier quoted context omitted.
Making the hardware you bought secure is the opposite of it being used against you.
I am not interested in securing my hardware again changes I want to make.
MSI firmware signing keys leaked
31–37 of 37 posts
Re: MSI firmware signing keys leaked
#32Does this mean that we can now custom firmwares (e.g. coreboot) on those MSI boards?
It's really fucked up that we can't disable secure boot on boards we've bought, and we have to hope their security is compromised instead. What would be the issue with requiring a very manual process to add my own CA to the board so I can load up whatever I want? Ah, vendor lockin, got it.
Re: MSI firmware signing keys leaked
#33Earlier quoted context omitted.
Not at all, in this case. There is a giant pile of hardware in the world that relies on unsigned hardware. Meanwhile, MSI uses its hardware signing to hurt its customers. Will some MSI users get tricked into using malicious firmware? Doubtless, eventually. That's sad. But not nearly as sad as the millions of users who can't use their own computers in a manner of their choosing. Celebrate, without remorse.
I get that argument, but I'm not sure you have the relative population sizes right. It seems a bit doubtful that millions of MSI users are interested in flashing custom firmware on their motherboards, but every user is potentially impacted by signed malware. Particularly since the firmware signing is a known thing and there's less restricted hardware available. People really interested in being able to do whatever th…
Asus seems to have had several design issues, qc flaws and other support issues lately. MSI have had data breaches, and even then bully reviewers to the point you really can't trust a lot of their product reviews or them. Gigabyte treats their Linux using customers like hot garbage, and then there's the exploding PSU coverup/downplay. I'm not sure how many options that's leaving on the table at this point. I know there's ASRock for MBs and haven't seen anything bad about them lately.
Re: MSI firmware signing keys leaked
#34Earlier quoted context omitted.
Making the hardware you bought secure is the opposite of it being used against you.
Me doing whatever I want with stuff I bought is the definition of ownership. I'm starting to think that these sort of "CVE bro" posts are part of an intentional campaign by manufacturers trying to hold on to their rent seeking scheme. John Deere et al was definitely trying to use those arguments recently.
Re: MSI firmware signing keys leaked
#35Earlier quoted context omitted.
Making the hardware you bought secure is the opposite of it being used against you.
I am not interested in securing my hardware again changes I want to make.
Re: MSI firmware signing keys leaked
#36Earlier quoted context omitted.
Making the hardware you bought secure is the opposite of it being used against you.
Me doing whatever I want with stuff I bought is the definition of ownership. I'm starting to think that these sort of "CVE bro" posts are part of an intentional campaign by manufacturers trying to hold on to their rent seeking scheme. John Deere et al was definitely trying to use those arguments recently.
You aren’t a farmer and your crappy MSI consumer hardware isn’t a tractor.
Re: MSI firmware signing keys leaked
#37Earlier quoted context omitted.
If I recall correctly, at boot time CPUs retrieve the firmware along with a cryptographic signature that verifies the firmware came from the signer. Some boards choose to burn this signature into the hardware using e-fuses. If the signing key is leaked, that means someone can flash custom firmware into the chip and the CPU would be none the wiser, all while operating at Ring 0.
CPU firmware (microcode) is signed by Intel, so it would not be affected by this leak, only motherboard firmware.