Live data from Hacker News

After CIA leak, Intel Security releases detection tool for EFI rootkits

pcworld.com

41–50 of 61 posts

Re: After CIA leak, Intel Security releases detection tool for EFI rootkits

#41
post #16

Finally some tools for this. Very good. Would this be the first reasonably doable method for extracting all the blobs? Seem like it must be a well-needed foundation to build on for security companies. But... We recommend generating an EFI whitelist after purchasing a system or when you are sure it has not been infected Not that I have a better suggestion, but with interdicted shipments and other vulnerable points alo…

If you have access to more than one identical system they can be compared. Or there could be a public list of known good hashes as you suggest.

In any case having a tool to even perform the check is great.

Re: After CIA leak, Intel Security releases detection tool for EFI rootkits

#42
post #23
post #12

Earlier quoted context omitted.

Reproducible builds is a very important part of knowing you are secure, and in the absence of that at least being able to flash on your own compilation.

Well even with reproducible builds how do you check what actually is running there? That'd be the ME reporting "I'm running version X" without a way to really verify it. Also if you flashed it you cannot be 100% sure there is no other component that is still running a rootkit.

Good analysis of this issue in Halvar Flake's https://www.slideshare.net/hashdays/why-johnny-cant-tell-if-... ("Why Johnny can't tell if he is compromised").

Re: After CIA leak, Intel Security releases detection tool for EFI rootkits

#43
post #29

Nice try CIA and Intel, but I'm not falling for this.

and.... what alternative could you possibly have? There's a reason the Russians reportedly moved to typewriters. https://www.theguardian.com/world/2013/jul/11/russia-reverts... The entire computing ecosystem appears to be P0wned by various intelligence services. And, its not unique to the CIA or NSA. The Chinese are assumed to have backdoors into most of what ships from their country.

There's a reason the Russians reportedly moved to typewriters.

Hopefully the Russians still remember how they bugged US typewriters in the US Embassy in Moscow. Then they'll be able to check that their own typewriters aren't bugged in a similar fashion: http://www.cryptomuseum.com/covert/bugs/selectric/

Re: After CIA leak, Intel Security releases detection tool for EFI rootkits

#44
post #17
post #7

Earlier quoted context omitted.

Of all the attacks a nation state could do, surely finding a few talented people to get PhDs in the appropriate fields and go to work at Intel and collect a paycheck along with a nice stipend from the nation state is likely among the easiest.

Why bother with employees - just go give money to intel to do this. Intel as a system is designed to produce chips that work a certain way, and my understanding is that said system is rather good at what it does, dedicating the time and energy of many rather smart people to making sure things work the way they're supposed to. Why risk throwing a monkey wrench into such a system when you can just point it in a differe…

>Why bother with employees - just go give money to intel to do this.

Risk of refusal. Risk of intentional or unintentional leaks.

Re: After CIA leak, Intel Security releases detection tool for EFI rootkits

#45
post #17
post #7

Earlier quoted context omitted.

Of all the attacks a nation state could do, surely finding a few talented people to get PhDs in the appropriate fields and go to work at Intel and collect a paycheck along with a nice stipend from the nation state is likely among the easiest.

Why bother with employees - just go give money to intel to do this. Intel as a system is designed to produce chips that work a certain way, and my understanding is that said system is rather good at what it does, dedicating the time and energy of many rather smart people to making sure things work the way they're supposed to. Why risk throwing a monkey wrench into such a system when you can just point it in a differe…

Plausible deniability goes a long way toward preventing a mass exodus from one's platform.

Re: After CIA leak, Intel Security releases detection tool for EFI rootkits

#47
post #42
post #23

Earlier quoted context omitted.

Well even with reproducible builds how do you check what actually is running there? That'd be the ME reporting "I'm running version X" without a way to really verify it. Also if you flashed it you cannot be 100% sure there is no other component that is still running a rootkit.

Good analysis of this issue in Halvar Flake's https://www.slideshare.net/hashdays/why-johnny-cant-tell-if-... ("Why Johnny can't tell if he is compromised").

Or Ken Thompsons's Reflections on Trusting Trust.

Re: After CIA leak, Intel Security releases detection tool for EFI rootkits

#48
post #37

Macs lack Secure Boot. This tools seems to be for non-Secure Boot computers. IF it's a Secure Boot system, rootkits aren't supposed to happen, and if they do then there's a hole somewhere that needs fixing.

I thought secure boot was about verifying the OS at boot time. Does it also self-verify the EFI code?

Re: After CIA leak, Intel Security releases detection tool for EFI rootkits

#49
post #41
post #16

Finally some tools for this. Very good. Would this be the first reasonably doable method for extracting all the blobs? Seem like it must be a well-needed foundation to build on for security companies. But... We recommend generating an EFI whitelist after purchasing a system or when you are sure it has not been infected Not that I have a better suggestion, but with interdicted shipments and other vulnerable points alo…

If you have access to more than one identical system they can be compared. Or there could be a public list of known good hashes as you suggest. In any case having a tool to even perform the check is great.

This doesn't preclude the infect-at-the-factory issue: you'd end up verifying you HAVE the rootkit (and reverting to that if it changes).

Re: After CIA leak, Intel Security releases detection tool for EFI rootkits

#50
post #7

Earlier quoted context omitted.

Of all the attacks a nation state could do, surely finding a few talented people to get PhDs in the appropriate fields and go to work at Intel and collect a paycheck along with a nice stipend from the nation state is likely among the easiest.

Isn't it unlikely that an individual engineer (or even a handful) could effect a design level compromise on such a massive project as building a processor? Not only because of the managerial oversight they'd have to circumvent, but because of the overall system complexity. As sibs have pointed it, it would seem much more practical to just compromise Intel at a corporate/managerial level.

> Isn't it unlikely that an individual engineer (or even a handful) could effect a design level compromise on such a massive project as building a processor?

Yes, very unlikely. Something like the Intel Management Engine would be a much easier target.

Post reply on HN