MSI firmware signing keys leaked
github.com
MSI firmware signing keys leaked
1–10 of 37 posts
Re: MSI firmware signing keys leaked
#2Re: MSI firmware signing keys leaked
#3How would someone use those keys? What's beneficial, what could be useful possible cases for me? And Are my workstations in my company at risk?
Re: MSI firmware signing keys leaked
#4Re: MSI firmware signing keys leaked
#5I would love to learn more about that. How would someone use those keys? What's beneficial, what could be useful possible cases for me? And Are my workstations in my company at risk?
Re: MSI firmware signing keys leaked
#6Re: MSI firmware signing keys leaked
#7Re: MSI firmware signing keys leaked
#8Does this mean that we can now custom firmwares (e.g. coreboot) on those MSI boards?
Re: MSI firmware signing keys leaked
#9Does this mean that we can now custom firmwares (e.g. coreboot) on those MSI boards?
Ah, vendor lockin, got it.
Re: MSI firmware signing keys leaked
#10I would love to learn more about that. How would someone use those keys? What's beneficial, what could be useful possible cases for me? And Are my workstations in my company at risk?
If I recall correctly, at boot time CPUs retrieve the firmware along with a cryptographic signature that verifies the firmware came from the signer. Some boards choose to burn this signature into the hardware using e-fuses. If the signing key is leaked, that means someone can flash custom firmware into the chip and the CPU would be none the wiser, all while operating at Ring 0.