No amount of EFI rootkit detection will ever remove the possibility that malicious code is running inside the Intel Management Engine (ME), because code inside the ME would run side-by-side with the bootloader and with unlimited permissions. Unless Intel provides source code for the ME, it is impossible to 100% know whether unauthorized code is running.
After CIA leak, Intel Security releases detection tool for EFI rootkits
11–20 of 61 posts
Re: After CIA leak, Intel Security releases detection tool for EFI rootkits
#12No amount of EFI rootkit detection will ever remove the possibility that malicious code is running inside the Intel Management Engine (ME), because code inside the ME would run side-by-side with the bootloader and with unlimited permissions. Unless Intel provides source code for the ME, it is impossible to 100% know whether unauthorized code is running.
Even if Intel gave you the source code, you still wouldn't know if there was any unauthorised code running.
Re: After CIA leak, Intel Security releases detection tool for EFI rootkits
#13Re: After CIA leak, Intel Security releases detection tool for EFI rootkits
#14No amount of EFI rootkit detection will ever remove the possibility that malicious code is running inside the Intel Management Engine (ME), because code inside the ME would run side-by-side with the bootloader and with unlimited permissions. Unless Intel provides source code for the ME, it is impossible to 100% know whether unauthorized code is running.
Even if Intel gave you the source code, you still wouldn't know if there was any unauthorised code running.
Re: After CIA leak, Intel Security releases detection tool for EFI rootkits
#15Re: After CIA leak, Intel Security releases detection tool for EFI rootkits
#16But...
We recommend generating an EFI whitelist after
purchasing a system or when you are sure it has
not been infected
Not that I have a better suggestion, but with interdicted shipments and other vulnerable points along the supply chain before a system is in the care of its owner, it doesn't exactly seem like a sure bet that it's clean on arrival.
How would one otherwise be "sure it has not been infected"? Any feasible ways?Next step would be to provide lists of known good signatures from some controlled environment, or at least a consensus system to know whether the version one finds matches the version others have?
Re: After CIA leak, Intel Security releases detection tool for EFI rootkits
#17And what if intel is compromised? Mass rootkit installation!
Of all the attacks a nation state could do, surely finding a few talented people to get PhDs in the appropriate fields and go to work at Intel and collect a paycheck along with a nice stipend from the nation state is likely among the easiest.
AT&T and Verizon don't have 'plant' employees. Much simpler - and legally, safer - to just give the bag of money straight to the corporation.
Re: After CIA leak, Intel Security releases detection tool for EFI rootkits
#18And what if intel is compromised? Mass rootkit installation!
Re: After CIA leak, Intel Security releases detection tool for EFI rootkits
#19Re: After CIA leak, Intel Security releases detection tool for EFI rootkits
#20And what if intel is compromised? Mass rootkit installation!
You can reverse engineer the EFI modules, build a whitelist based on known safe code, and then detect subversion at Intel, so this is not a good strategy for serious adversaries.
Wouldn't the malicious alterations introduced in a scenario like that most likely be exploitable defects that could be explained away as mistakes? If they accumulate too much around certain people that's suspicious of course, but it seems like it would often be difficult to downright prove that someone intentionally broke the security of a rather complex system.