3 ms·
Why throw away your computers? Why not remove/disconnect the batteries (if portable) and just store them somewhere in case you eventually no longer suspect a ha
by jhiesey 7y ago
Why throw away your computers? Why not remove/disconnect the batteries (if portable) and just store them somewhere in case you eventually no longer suspect a hardware hack, as in this case?
- maxtaco 7y agohttps://www.welivesecurity.com/2018/09/27/lojax-first-uefi-rootkit-found-wild-courtesy-sednit-group/ https://www.welivesecurity.com/2018/09/27/lojax-first-uefi-r...
- malgorithms 7y agoFurther: Keybase is a security product and it wasn't deemed worth the risk for the CEO. And while Keybase isn't made of money, the $5k was roughly irrelevant compared to the other costs mentioned here and the _magnitude of the risk_. If you haven't been through this kind of thing, it's hard to understand how scary it is to have a break-in of unknown origin. If you use strong, unique passwords as Max did, then you're almost certain it's a server break in (and again, this is why Slack is scary for sensitive info)...but being 99% certain isn't enough. Removing that computer permanently from the team gave peace of mind.
- frivolous 7y agoSorry, but you're just being wasteful. You were looking for an excuse and you know it.
- voiper1 7y agotl;dr: UEFI rootkits can survive operating system reinstallation and even a hard disk replacement. That's why he needed a new physical computer.