27 ms·
The update service inside ASUS was broken, so it doesn’t matter what ASUS intended or implemented; the attackers would have just changed that. The second stage
by c256 8y ago
The update service inside ASUS was broken, so it doesn’t matter what ASUS intended or implemented; the attackers would have just changed that. The second stage installer was totally owned by the attacker.
Perhaps interesting to note: this is a situation where a blockchain could have been helpful.
- tyfon 8y agoYeah I understand that, but how is it possible for a company to put such a service on the network so that it _can_ be breached, that was really my question. It shouldn't have the place where you put the update files exposed to the internet at all. Unless it was an inside job somehow. The way it's described it almost sounds like the service exposed to the internet had write access to the files.
- ecpottinger 8y agoBecause stupid managers see security as a cost, and possible future security breaks as something that will not happen to them.
- justinclift 8y ago> The way it's described it almost sounds like the service exposed to the internet had write access to the files. A service exposed to the internet gets to decide what it sends to end users. Compromise that, it can replace the stuff sent on the fly. Not saying that's what happened here, just pointing out that not having "write access to the files" isn't a guaranteed win either. Depending on what else the attackers had access to (executables key signing pieces?), likely determines the approaches they took.