Intel's Alder Lake BIOS Source Code Reportedly Leaked Online
tomshardware.com
Intel's Alder Lake BIOS Source Code Reportedly Leaked Online
1–9 of 9 posts
Re: Intel's Alder Lake BIOS Source Code Reportedly Leaked Online
#2(Of course the owner of the system might still want to secure their system e.g. by digital signatures. Open source does not mean open write access.)
Re: Intel's Alder Lake BIOS Source Code Reportedly Leaked Online
#3This is according to user @hardenedlinux on Twitter.
The GitHub repository that refers to has since been removed.
Re: Intel's Alder Lake BIOS Source Code Reportedly Leaked Online
#4Re: Intel's Alder Lake BIOS Source Code Reportedly Leaked Online
#5Re: Intel's Alder Lake BIOS Source Code Reportedly Leaked Online
#6This article seems to assume that computers are secure as long as source code is secret. The opposite is true, only open source can give maxium security. (Of course the owner of the system might still want to secure their system e.g. by digital signatures. Open source does not mean open write access.)
Citation needed, open source can just have as problematic security problems as closed source even when they are high profile.
Re: Intel's Alder Lake BIOS Source Code Reportedly Leaked Online
#7This article seems to assume that computers are secure as long as source code is secret. The opposite is true, only open source can give maxium security. (Of course the owner of the system might still want to secure their system e.g. by digital signatures. Open source does not mean open write access.)
Re: Intel's Alder Lake BIOS Source Code Reportedly Leaked Online
#8This article seems to assume that computers are secure as long as source code is secret. The opposite is true, only open source can give maxium security. (Of course the owner of the system might still want to secure their system e.g. by digital signatures. Open source does not mean open write access.)
> This article seems to assume that computers are secure as long as source code is secret. The opposite is true, only open source can give maxium security. Citation needed, open source can just have as problematic security problems as closed source even when they are high profile.
Nobody said that open source has no security bugs. No software that does something useful is bug-free.
Re: Intel's Alder Lake BIOS Source Code Reportedly Leaked Online
#9"Our proprietary UEFI code appears to have been leaked by a third party. We do not believe this exposes any new security vulnerabilities as we do not rely on obfuscation of information as a security measure. This code is covered under our bug bounty program within the Project Circuit Breaker campaign, and we encourage any researchers who may identify potential vulnerabilities to bring them our attention through this program. We are reaching out to both customers and the security research community to keep them informed of this situation." — Intel spokesperson.
It is almost as if they are expecting some major holes to exist and just per-emptively attempt to defuse it.