Warlock Of Wires

23 Followers
33 Following
364 Posts
Engineering technologist /
analog astronaut

In 2012, an industry-wide coalition of hardware and software makers adopted Secure Boot to protect against a long-looming security threat. The threat was the specter of malware that could infect the BIOS, the firmware that loaded the operating system each time a computer booted up. From there, it could remain immune to detection and removal and could load even before the OS and security apps did.

To this day, key players in security—among them Microsoft and the US National Security Agency—regard Secure Boot as an important, if not essential, foundation of trust in securing devices in some of the most critical environments, including in industrial control and enterprise networks.

On Thursday, researchers from security firm Binarly revealed that Secure Boot is completely compromised on more than 200 device models sold by Acer, Dell, Gigabyte, Intel, and Supermicro. The cause: a cryptographic key underpinning Secure Boot on those models that was compromised in 2022. In a public GitHub repository committed in December of that year, someone working for multiple US-based device manufacturers published what’s known as a platform key, the cryptographic key that forms the root-of-trust anchor between the hardware device and the firmware that runs on it.

The repository included the private portion of the platform key in encrypted form. The encrypted file, however, was protected by a four-character password, a decision that made it trivial for Binarly, and anyone else with even a passing curiosity, to crack the passcode and retrieve the corresponding plain text. The disclosure of the key went largely unnoticed until January 2023, when Binarly researchers found it while investigating a supply-chain incident. Now that the leak has come to light, security experts say it effectively torpedoes the security assurances offered by Secure Boot.

“It’s a big problem,” said Martin Smolár, a malware analyst specializing in rootkits who reviewed the Binarly research and spoke to me about it. “It’s basically an unlimited Secure Boot bypass for these devices that use this platform key. So until device manufacturers or OEMs provide firmware updates, anyone can basically… execute any malware or untrusted code during system boot. Of course, privileged access is required, but that’s not a problem in many cases.”

https://arstechnica.com/security/2024/07/secure-boot-is-completely-compromised-on-200-models-from-5-big-device-makers/

Secure Boot is completely broken on 200+ models from 5 big device makers

Keys were labeled "DO NOT TRUST." Nearly 500 device models use them anyway.

Ars Technica
Slowly but surely things are happening
I am not dead I'm just very busy

Rarely do I see left-wing commentary include
People with disabilities ..
Every other minority the left seems to cuddle but handicapped people.

we're still ignored.....

Yes, TSA can confirm your identity without making you take off your mask too

“With masks, median system performance demonstrated a 77% identification rate, with the best-performing system correctly identifying individuals 96% of the time.” https://www.dhs.gov/science-and-technology/news/2021/01/04/news-release-airport-screening-while-wearing-masks-test

News Release: Airport Screening While Wearing Masks Test

A controlled scenario test by DHS S&T shows promising results for facial recognition technologies to accurately identify individuals wearing protective face masks.

Make the net weird again. Hand write sites like it’s the 90s. Pick interesting domain names and make fan sites or random knowledge known to everyone. Don’t monetize anything. Spearhead new protocols like Gemini. Make mods for games on your site. Make FAQs for obscure games no one knows about. Make public software services available to anyone. Make a news site about a really random subject. Create music in all kinds of different formats. Most of all, do it because you want to!

@kiwa

I think I may have accidentally blocked you.. I was trying to type to you in Discord and I fat fingered the wrong button I'm on a weird computer right now.
I try to adding you back hopefully this will get to you..

Peter...

@kiwa

I think I may have accidentally blocked you.. I was trying to type to you in Discord and I fat fingered the wrong button I'm on a weird computer right now.
I try to adding you back hopefully this will get to you..

Peter...

@kiwa

I think I may have accidentally blocked you.. I was trying to type to you in Discord and I fat fingered the wrong button I'm on a weird computer right now.
I try to adding you back hopefully this will get to you..

Peter...

AI is an unasked for tech looking for a problem to solve. It uses an incredible amount of energy.

Blockchain was an unasked for tech looking for a problem to solve. It uses an incredible amount of energy.

Pursuit of endless growth is pursuit of a cancer.

Moore's Law is dead and we have reached a happy plateau. We dont need more computing power. We can do so much now. If you need something to chew on, work on making it more efficient. Make the code smaller and faster and lighter.

And less of a power draw.

#AI #Blockchain #SolarPunk