Live data from Hacker News

ASUS delivers BIOS/UEFI auto-updates over HTTP with no verification

teletext.zaibatsutel.net

101–110 of 200 posts

Re: ASUS delivers BIOS/UEFI auto-updates over HTTP with no verification

#101
post #10

Earlier quoted context omitted.

I think in many cases there's no conscious decision not to implement TLS or code signing. It could just be that no one who cares enough about security is in a position to drive that change. There are many organizations that quite simply lack any kind of security culture.

I will be honest, I run a small web community of about 20,000 users, so it's different than hardware/firmware updates for potentially mission critical systems... That said, the reason I haven't implemented tighter security practices isn't so much a response to cost-benefit analysis. My users simply haven't made a lot of noise demanding more strict password tolerances, identity verification, or SSL. I have a limited a…

Security is the ultimate technical debt. It's "worthless to your users" for a while, and then one day it's an extinction event.

You don't get the same trial/iterate cycle there is with software features, when it comes to security. Kind of, but mostly not.

Re: ASUS delivers BIOS/UEFI auto-updates over HTTP with no verification

#102

Earlier quoted context omitted.

Doesn't it affect only those who run Windows with this ASUS LiveUpdate thing installed? But perhaps you meant that you must now, as a protest, shun ASUS products. I can sympathise with that.

My reason for not buying one is because the screen res is small :( I usually reformat them on arrival anyway.

Is the screen matte or glossy?

Re: ASUS delivers BIOS/UEFI auto-updates over HTTP with no verification

#103
post #6

Earlier quoted context omitted.

Could be worse, the title made me imagine UEFI firmware itself making HTTP downloads and reflashing itself ;)

I thought that too and then got terrified of the idea that someone trusting an HTTP connection writing (parts of) a damn BIOS. This would be worse than anything. Actually I also don't like BIOS allowing to be flashed from within the OS for convenience. So your computer gets owned and you can't trust your motherboard anymore.

I hate this idea as it usually means that you have to run Windows to upgrade BIOS...

Re: ASUS delivers BIOS/UEFI auto-updates over HTTP with no verification

#104
post #7

Very nice find. What are the business unit motivations behind critical suppliers like ASUS repeatedly violating customer trust in this manner? At what point in the management chain is the decision reached to sacrifice reputation for - whatever cost savings there are from not implementing TLS/blob signing? edit: This is not rhetorical. Actually curious if someone on HN familiar with this class of companies (ASUS is no…

Consumer laptop manufacturers which are not Apple have exactly one game to play: who has the most GHz and GB on the Best Buy shelf for the lowest price?

Other dimensions of quality (screen, keyboard, trackpad, hinge, case, battery, fans, overheating issues, preinstalled rootkits and adware, and certainly BIOS) are not relevant to their customers (who, even if they are frustrated with these things, don't necessarily know that something better exists).

So they go in whichever direction is cheapest (or, in the case of spyware, brings in the most 3rd party revenue).

Re: ASUS delivers BIOS/UEFI auto-updates over HTTP with no verification

#106
post #10

Earlier quoted context omitted.

I think in many cases there's no conscious decision not to implement TLS or code signing. It could just be that no one who cares enough about security is in a position to drive that change. There are many organizations that quite simply lack any kind of security culture.

I will be honest, I run a small web community of about 20,000 users, so it's different than hardware/firmware updates for potentially mission critical systems... That said, the reason I haven't implemented tighter security practices isn't so much a response to cost-benefit analysis. My users simply haven't made a lot of noise demanding more strict password tolerances, identity verification, or SSL. I have a limited a…

You should look at CloudFlare. It would be transparent to the users, free, and would provide (some) security without you having to do anything.

https://www.cloudflare.com/plans/

Re: ASUS delivers BIOS/UEFI auto-updates over HTTP with no verification

#107
post #7

Very nice find. What are the business unit motivations behind critical suppliers like ASUS repeatedly violating customer trust in this manner? At what point in the management chain is the decision reached to sacrifice reputation for - whatever cost savings there are from not implementing TLS/blob signing? edit: This is not rhetorical. Actually curious if someone on HN familiar with this class of companies (ASUS is no…

I think you overestimate the actual security impact of this issue. Think about it, practically everyone who is even remotely technical is going to put a fresh copy of his favorite OS on his computer anyway. No one likes dealing with all the bloatware that is installed on those machines by default.

And the rest? They're infecting themselves by opening dubious email attachments already. For someone looking to make money through viruses, MitM attacks are just not economical.

ASUS really should fix this problem by implementing TLS, but it's just very unlikely that they will lose any amount of customers whatsoever if they don't. And as long as that's the case, nothing will change in that regard.

Re: ASUS delivers BIOS/UEFI auto-updates over HTTP with no verification

#108

Earlier quoted context omitted.

How are Apple actively malicious?

Let's see here: * Started the trend of non-replaceable batteries in phones * Started the trend of non-replaceable batteries in laptops * Started the trend of locked-down devices where the owner can't decide what software to run * Custom screws in order to prevent people from fixing their devices * Custom enclosures in order to prevent people from replacing parts in their devices with commodity devices * Soldering in…

Right. These can also be interpret as their reason to make slimmer devices. People buying these products would presumably know what they're getting into.

Re: ASUS delivers BIOS/UEFI auto-updates over HTTP with no verification

#109
post #58

Earlier quoted context omitted.

Intel NUC has an option to directly pull down/install BIOS updates built into UEFI as well, and thus probably other newer Intel boards. Convenience and security are often orthogonal.

They do that so people with hundreds of servers do not have to spend days in the server room with thumb drives, individually booting servers to flash the BIOS. There is HUGE demand for the ability to do remote BIOS updates over a management network. Now how is the BMC supposed to know whether the network is appropriately secure before accepting those updates?

The only "good" answer to whether the BMC is supposed to know whether the management network is "secure" would be a song and dance like 802.1x and any authentication configured on top of that, before even allowing you to submit an image for flashing, let alone trying to verify it.

(You could argue that the existence of good signature verification on the images is often sufficient, but if you have an older BIOS that's signed but has an exploit vector, you could still make use of that if you had unfettered access other than the signature checking.)

Re: ASUS delivers BIOS/UEFI auto-updates over HTTP with no verification

#110
post #6

Wow. I always knew hardware manufacturers half-assed their software, but this is kind of a new low. I'm not sure whether to laugh or cry.

Could be worse, the title made me imagine UEFI firmware itself making HTTP downloads and reflashing itself ;)

Yeah, thats what the title said to me too. Not the case for me since I don't use any of those windows tools from Asus. (run linux instead on all of them)
Post reply on HN