Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Did anyone verify any of these? The whole thing reeks.


Good question. They call the "MASTERKEY attack" that requires a reflashed BIOS "remotely exploitable" because on some systems, the BIOS can be flashed from the OS. They then speculate "On motherboards where re-flashing is not possible because it has been blocked, or because BIOS updates must be encapsulated and digitally signed by an OEM-specific digital signature, we suspect an attacker could occasionally still succeed in re-flashing the BIOS." Page 9 in the PDF.

I'm not a professional security researcher but this is looking pretty darn flimsy. I also don't see any proof of concept code anywhere -- the "whitepaper" seems to just claim these things exist with very little mention of how to exploit them. Compare against Meltdown/Spectre, which was highly technical and had lots of PoC code. This just says "Upload malware to the processor" without further comment.

I'm not saying they didn't find anything, but whatever they found, they've hardly disclosed it.





Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: