4 ms·
Is there a way to detect such big brother firmware and flash it?
by nessunodoro 6y ago
Is there a way to detect such big brother firmware and flash it?
- gruez 6y agoIt's a non-issue if you're not using windows. Basically it's a windows "feature" where if a certain ACPI table is present in the firmware, it will download and execute it. There isn't actually any malware/spyware executing on the firmware itself.
- airstrike 6y ago> Basically it's a windows "feature" where if a certain ACPI table is present in the firmware, it will download and execute it. What in the actual fuck... this seems straight off a dystopian graphic novel
- sneak 6y agohttps://www.gnu.org/philosophy/right-to-read.en.html https://www.gnu.org/philosophy/right-to-read.en.html When I play movies I've paid for on my iPad I've paid for, if I want to screenshot frames from them to share or reference or meme, the screenshots come out as black rectangles.
- TheSpiceIsLife 6y agoSarcasm: That’s because it would be trivial to screenshot every frame and reassemble the video from there. No fair use for you!
- toast0 6y agoThe intent is that manufacturers would use this to provide critical drivers for windows users. Stuff that wasn't on the retail OS cd, but you would need to get to windows update. Or something, I dunno. Of course, the race to the bottom being what it is, if you can get $20/unit to put sketchy garbage in it, it's going to happen. Just because you're paying for something doesn't mean you're not also the product.
- schoolornot 6y agoThe original intent seems OK. Why the hell does this mechanism need the capability to execute arbitrary .exe files and not just load the most basic type of driver required (INF/DLL/etc. whatever Windows calls it)?
- freeone3000 6y agoIt's still arbitrary code running as a driver, it doesn't matter what form it takes, you can abuse the process to host whatever you want.
- mikepurvis 6y agoA DLL is also executable code; there's really no difference between that and running an arbitrary EXE. Inf files are slightly different, since they're just text-based configuration, but I doubt that you could get your theft-recovery (or whatever other) functionality using just configuration of something built-in.
- gruez 6y agoAFAIK the original purpose was for anti-theft solutions (eg. computrace) to re-install themselves after a wipe. Before this, they would mount the boot drive and rewrite chkdsk.exe (which gets executed each boot) with their program. That way, their tracking software stays on the system even if you wiped the computer.
- bluegreyred 6y agoSome large motherboard vendors do this too. They'll happily drop an autoupdater onto any fresh Windows installation booted from the board. https://www.techpowerup.com/248827/asus-z390-motherboards-automatically-push-software-into-your-windows-installation https://www.techpowerup.com/248827/asus-z390-motherboards-au...