Jump to content

[News] UEFI and Secure Boot - The Linux users are not happy!


Recommended Posts

Posted
I don't buy Apple products, or Blackberry because you are "not allowed" to monkey around with them. I know this, that's why I don't buy them.

The fact that the Acer W510's (and other 'Clover Trail' tablets) only support Windows 8 would have been a deal breaker for me. As you say, research is very important (probably more so than ever).

 

Posted
I dont know if any of you have IBM Flex Series or x3500 series servers but they take an age to get past the post screen, It's really annoying as on some of out blade servers UEFI is enabled with legacy mode. Some versions of Linux want Legacy only so this means you have to go all the way back to the BIOS to change the settings - It's annoying and takes longer to build a system.
Posted

Motherboard manufacturer Jetway has done something really stupid. They put their UEFI private signing key on a publicly accessible FTP server along with the source code for their latest American Megatrends (AMI) firmware. :eek:

 

Security Done Wrong: Leaky FTP Server « Adam Caudill

 

By leaking this key and the firmware source, it is possible (and simple) for others to create malicious UEFI updates that will be validated & installed for the vendor’s products that use this ‘Ivy Bridge’ firmware. If the vendor used this same key for other products - the impact could be even worse. Even with a quick reaction, odds are users will be unprotected for some time. As users often don't install firmware updates unless they are having issues - I expect this one to be around for a while.

 

This kind of leak is a dream come true for advanced corporate espionage or intelligence operations. The ability to create a nearly undetectable, permanent hole in a system’s security is an ideal scenario for covert information collection.

 

This vendor’s lax (non-existent?) security could have much broader repercussions though. For AMI, they now have a major piece of intellectual property freely available for download by competitors. For users, this code could now be subject to new scrutiny - if a security issue is found in the firmware, it could potentially impact all users whose firmware is based on the leaked code.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...