On Friday, December 15, 2017 at 8:25:53 PM UTC-5, [email protected] wrote:
> On 12/15/2017 12:54 PM, Matteo wrote:
> 
> >> I disagree when you say nooone is going to backdoor your bios.   I think 
> >> its very common nowadays.
> Actually no it isn't - unless you have managed to ruffle the feathers of 
> a state actor such as the FSB or MSS.
> 
> I have never heard of a real proven BIOS hack of anyone even a serious 
> military intelligence target let alone a common law abiding citizen who 
> simply managed to piss off some guy in a chat-room or what not, I am 
> sure it has been done many times but despite being active in the 
> firmware modification community I haven't heard about it.
> > as far as i know there is computrace that is an anti theft system that
> > gain persistence over the os by dropping an exe that windows will load
> > at boot time but this works only over fat32 and ntfs (not encrypted).
> > i heard also about lenovo doing the same thing for ads or whatever. and
> > after people got angry they released a bios patch to opt-out.
> > but i wouldn't say "very common".
> Computrace uses a windows utility to do this not direct code injection 
> so using linux or simply disabling it in your vendor BIOS would solve 
> the issue of an out-dated problematic exe being forcibly loaded.
> 
> If you wish for better security you can use a coreboot board with open 
> source silicon init (not purism, get the libre RYF kcma-d8 or the lenovo 
> g505s laptop for instance) otherwise while you can use an external flash 
> clip to read back the BIOS and make sure it hasn't been modified you 
> still would be vulnerable to manufacturer security problems, ME etc.

I would get the same responses from people in the 90s.  Can't believe its still 
parroted in 2017 when we see so many real life examples and poc's. Bios devs 
claim bios's are more safer now, but I think they are less safe.   Its why I'm 
a big fan of ITL, they keep it real.

   You forget all the hacking teams out there getting their data pilfered by 15 
year olds. Or the story about intel's backdoor that has been there for years 
and years, who knows how many people knew.  Its also holiday season right now.  
Satans claws are coming to town and everything is on sale for everyone lol

I think part of the problem is old school mentalities like yours have a hard 
time not only admitting that a bios can be infected in the first place,  but 
also that it can be infected remotely.

Its also very hard to admit to something like this,  because what can we really 
do against it?   I still remember the look on everyones face on the panel of 
the Logan CIJ Symposium 2016 when Joanna said maybe there is no point if we 
can't trust companies or developers or the hardware is backdoored.   



Doesn't purism use secure boot on their latest model?

-- 
You received this message because you are subscribed to the Google Groups 
"qubes-users" group.
To unsubscribe from this group and stop receiving emails from it, send an email 
to [email protected].
To post to this group, send email to [email protected].
To view this discussion on the web visit 
https://groups.google.com/d/msgid/qubes-users/5d814b0f-85ff-49e2-9b52-18b9022cf20e%40googlegroups.com.
For more options, visit https://groups.google.com/d/optout.

Reply via email to