I don't remember the brand(s) exactly --- don't think it was ASUS however --- but I do remember a few years ago of laptops which would automatically and silently download and install BIOS updates, and inevitably some of them would fail, leading to bricked machines. IMHO the BIOS is not something that should ever change unless there's a very important reason to, and even then it should be on the explicit action and co…
ASUS delivers BIOS/UEFI auto-updates over HTTP with no verification
81–90 of 200 posts
Re: ASUS delivers BIOS/UEFI auto-updates over HTTP with no verification
#82Earlier quoted context omitted.
If they wrote and installed remote execution exploit on the Windows they would do the same if they shipped with Ubuntu.
Which is a good reason to always do a fresh OS reinstall before you even boot the system for the first time. That's what I've done the past couple of times I've bought a new PC. the very first boot is off a USB drive to do a clean OS install. Completely wipe the existing disk partitions too.
Re: ASUS delivers BIOS/UEFI auto-updates over HTTP with no verification
#83Earlier quoted context omitted.
If they wrote and installed remote execution exploit on the Windows they would do the same if they shipped with Ubuntu.
Which is a good reason to always do a fresh OS reinstall before you even boot the system for the first time. That's what I've done the past couple of times I've bought a new PC. the very first boot is off a USB drive to do a clean OS install. Completely wipe the existing disk partitions too.
[1] http://arstechnica.com/information-technology/2015/08/lenovo...
Re: ASUS delivers BIOS/UEFI auto-updates over HTTP with no verification
#84Re: ASUS delivers BIOS/UEFI auto-updates over HTTP with no verification
#85Very nice find. What are the business unit motivations behind critical suppliers like ASUS repeatedly violating customer trust in this manner? At what point in the management chain is the decision reached to sacrifice reputation for - whatever cost savings there are from not implementing TLS/blob signing? edit: This is not rhetorical. Actually curious if someone on HN familiar with this class of companies (ASUS is no…
I find there's a pervasive hardware culture that's at odds with both software and security cultures. Hardware culture involves designing it once, testing it once, setting up the supply chain and production line once, and from then on it's just quality control and marketing: totally a fire-and-forget weapon. That means in a hardware dominated organization, where you sell hardware, revenue is in terms of units sold. An…
Re: ASUS delivers BIOS/UEFI auto-updates over HTTP with no verification
#86Didn't Duo Security already expose this? https://duo.com/assets/pdf/out-of-box-exploitation_oem-updat...
Ouch.
Re: ASUS delivers BIOS/UEFI auto-updates over HTTP with no verification
#87Earlier quoted context omitted.
True but it creates business for ThinkPad and I'm loyal to them. They fupped too though
You mean the Lenovo thinkpads which come with tons of malware like superfish and different insecure plain http update mechanisms?
That’s the advantage of using the business line of products: it’s usually not as fucked up.
Re: ASUS delivers BIOS/UEFI auto-updates over HTTP with no verification
#88Earlier quoted context omitted.
I will be honest, I run a small web community of about 20,000 users, so it's different than hardware/firmware updates for potentially mission critical systems... That said, the reason I haven't implemented tighter security practices isn't so much a response to cost-benefit analysis. My users simply haven't made a lot of noise demanding more strict password tolerances, identity verification, or SSL. I have a limited a…
You should definitely set up SSL/TLS for your web site. Let's Encrypt lets you easily do that.
Without authority, you can say "This is a good idea and you're taking a huge security risk without fixing it" as many times as you want and still be told "No new feature, not a development priority."
Re: ASUS delivers BIOS/UEFI auto-updates over HTTP with no verification
#89Earlier quoted context omitted.
It's hard to make a case for long term support of commodity hardware sold into the consumer market because the most shiny things at the lowest first tends to drive purchases. It's as true for laptops as it is for Android phones. BestBuy doesn't care if it stocks ASUS or not. It cares about sales and margins. If there's an extra dollar putting Gateway on the shelf instead of ASUS they will. And their customers won't c…
Except if that were the case, it's even cheaper to not develop a live update capability at all. They went through the process of specifying and developing a automated utility that downloads files, parses manifests and then acts accordingly to install BIOS or other updates, tested it and bundled it with their retail system build, and after all that effort didn't take the one tiny step to sign their files or at least p…
Security risks are harder to quantify for the bottom line.
Re: ASUS delivers BIOS/UEFI auto-updates over HTTP with no verification
#90Damn ASUS that's a real shame, because that Royal Blue Zenbook 3 is god damn sexy https://www.asus.com/Notebooks/ASUS-ZenBook-3-UX390UA/
Ironic that your link to the ASUS site is (working) HTTPS. I checked the liveupdate01.asus.com and dlcdnet.asus.com domains referenced in the article, and they can certainly serve over HTTPS...