After CIA leak, Intel Security releases detection tool for EFI rootkits
1–10 of 61 posts
Re: After CIA leak, Intel Security releases detection tool for EFI rootkits
#2Re: After CIA leak, Intel Security releases detection tool for EFI rootkits
#3https://securingtomorrow.mcafee.com/business/chipsec-support...
It includes a few more details about what was released:
It extracts EFI firmware from flash ROM memory
automatically if the firmware file is not
specified.
We recommend generating an EFI whitelist after
purchasing a system or when you are sure it has
not been infected:
# chipsec_main -m tools.uefi.whitelist -a generate
Then check the EFI firmware on your system
periodically or whenever you are concerned, such
as when a laptop was left unattended:
...An analysis of the approach they are taking would lead to some pretty easy improvements.
Re: After CIA leak, Intel Security releases detection tool for EFI rootkits
#4And what if intel is compromised? Mass rootkit installation!
The code is here: https://github.com/chipsec/chipsec
Re: After CIA leak, Intel Security releases detection tool for EFI rootkits
#5And what if intel is compromised? Mass rootkit installation!
Re: After CIA leak, Intel Security releases detection tool for EFI rootkits
#6Unless Intel provides source code for the ME, it is impossible to 100% know whether unauthorized code is running.
Re: After CIA leak, Intel Security releases detection tool for EFI rootkits
#7And what if intel is compromised? Mass rootkit installation!
Re: After CIA leak, Intel Security releases detection tool for EFI rootkits
#8No amount of EFI rootkit detection will ever remove the possibility that malicious code is running inside the Intel Management Engine (ME), because code inside the ME would run side-by-side with the bootloader and with unlimited permissions. Unless Intel provides source code for the ME, it is impossible to 100% know whether unauthorized code is running.
Re: After CIA leak, Intel Security releases detection tool for EFI rootkits
#9And what if intel is compromised? Mass rootkit installation!
Of all the attacks a nation state could do, surely finding a few talented people to get PhDs in the appropriate fields and go to work at Intel and collect a paycheck along with a nice stipend from the nation state is likely among the easiest.
That said, the main hurdles seem to be managing people and funds, which government agencies seem pretty good at figuring out. So maybe not all that easy, but maybe not particularly hard either. The biggest problem might be keeping it secret, given the number of people that might need to be involved that are clandestinely working for a TLA but not as their main job and not steeped in the culture of secrecy.
Re: After CIA leak, Intel Security releases detection tool for EFI rootkits
#10And what if intel is compromised? Mass rootkit installation!
Of all the attacks a nation state could do, surely finding a few talented people to get PhDs in the appropriate fields and go to work at Intel and collect a paycheck along with a nice stipend from the nation state is likely among the easiest.