6 ms·
What’s scary about UEFI is that it has both direct hardware access and a massive attack surface: GUI, Ethernet stack, occasionally an 802.11 stack, etc.
by profile53 5y ago
What’s scary about UEFI is that it has both direct hardware access and a massive attack surface: GUI, Ethernet stack, occasionally an 802.11 stack, etc.
- blibble 5y agocustomers want to be able to boot their machines off the network this would be difficult without a network stack if you're so inclined: you can remove unneeded modules from your UEFI firmware
- bayindirh 5y ago> this would be difficult without a network stack This was possible with Ethernet cards with boot ROMs for more than two decades. Network booting via UEFI is nothing new, nothing revolutionary. I've been installing fleets of servers with PCI ethernet cards w/ boot ROMs a decade before. Token ring systems were booting from network two decades before.
- blibble 5y agowhat's the difference between having the code running in ring0 in a ROM vs the code running in ring0 from UEFI?
- bayindirh 5y agoWhen a boot ROM fires (it was via INT19 IIRC), the boot ROM runs, terminates and leaves the system. The size is smaller, it's not persistent, and it can't communicate with anything on the OS. When booted from the ROM, it just downloads pxelinux.0 binary in most cases, and transfers control to it, and just vanishes. The UEFI is persistently running at the background, has communication pipes with the OS (some of it is visible via /sys/firmware/efi), and has much larger surface like direct access to disks and network stack via drivers (it can directly read your files and work on them via proper FS driver modules). There's also at least one open source sound driver too (https://github.com/Goldfish64/AudioPkg https://github.com/Goldfish64/AudioPkg), so it can listen to your environment if it wants, at least in theory.
- blibble 5y ago> The UEFI is persistently running at the background, has communication pipes with the OS this isn't true, it ceases running once it transfers execution you're thinking of the SMM, which is something else entirely
- bonzini 5y agoSMM is also part of the firmware, it is set up by UEFI.
- blibble 5y agoyes, the UEFI initialises the machine such that it is in a state that it can boot that's it's job it's not the fault of the UEFI as a standard or implementation that your processor manufacturer chose to require the SMM to have its firmware loaded to boot the UEFI also isn't suddenly persistent because there are other devices inside the machine that had firmware loaded into them (would you say the UEFI is persistent because it uploaded new third-party supplied microcode into the CPU?)
- p_l 5y agoUEFI provides an interface to register code that runs in SMM, true. SMM being a requirement is a side effect of x86 history and platform design, not UEFI (which doesn't actually require SMM).
- hackmiester 5y agoI don't think SMM requires UEFI, either, actually... I believe there have been BIOSes that initialized SMM also.
- p_l 5y agoIndeed. SMM exists because it was unfeasible to require the OS to provide necessary power management features at a time when running DOS and unmodified Win2.x and Win3.x were crucial features. Thus 386SL was born, with SMM mode so that the firmware could hijack DOS without being stopped by accidental modification of interrupt table. A bunch of stuff was later loaded into SMM for various reasons, both more and less benign. Turion X2 CPUs used SMM resident handler to synchronise cpus when going into deeper sleep levels (iirc C3 required the SMM handler, C1 and C2 were doable without, but C1E required it as well)
- perryizgr8 5y agoThere's a huge difference. The network card does not need unrestricted access to the entire system.
- blibble 5y agoit has it because the code running from its ROM is running in ring0 exactly the same as the UEFI
- p_l 5y agoThere's less unrestricted access with UEFI than with old-fashioned option rom, especially with how you can 1) prevent loading of an option rom by banning its signature 2) register override for the device. Also, now there's much less code in option rom, leading to much more coherent system. Yes, it is easier to attack, but so is any system where you can expect a standard ABI&API vs. one where you need to randomly poke things.
- ikiris 5y agoYou do know how DMA works right?
- dijit 5y ago> if you're so inclined: you can remove unneeded modules from your UEFI firmware this is so disingenuous as to be offensive. I'm not saying you're wrong, but the practical options for replacing a UEFI BIOS are vanishingly small. Also: booting over the network is a feature of a smaller ROM on a network card, that ROM usually had a much smaller surface area and had to be explicitly called as a boot option. Given the people who care most about network boot are people running servers: IPMI/iDRAC/iLO are much stronger options for initiating network boot.
- blibble 5y ago> this is so disingenuous as to be offensive. > I'm not saying you're wrong, but the practical options for replacing a UEFI BIOS are vanishingly small. what? you can download a GUI editor, click remove on the modules you don't want and then save it https://www.trishtech.com/2017/12/uefitool-view-and-edit-uefi-firmware-for-motherboard/ https://www.trishtech.com/2017/12/uefitool-view-and-edit-uef... I've done it
- dataflow 5y agoDoes it not need a digital signature or something?
- dijit 5y agoCool tool, didn’t know it existed but there are so many variations on UEFI bios’s that I can’t help but feel it will not universally work, and it depends a lot on things being compartmentalised. I also draw your attention to: > UEFITool is only meant for the advanced users who have all the knowledge needed to modify the UEFI BIOS files. Because of you make any mistake and flash the faulty file to your motherboard, it can turn the motherboard into a dead brick. Which is more worrying when you look at what is presented (just a bunch of UUIDs). Not exactly usable for average person who wants to minimise the attack surface of their machine. Given that average people aren’t networking booting, wouldn’t it be wiser to have it enableable? Instead of on by default.
- lmz 5y ago
- Filligree 5y ago> if you're so inclined: you can remove unneeded modules from your UEFI firmware I’ll bite. How, concretely, do I do this? What’s the procedure to follow? How can I get the new BIOS image signed, so my motherboard will accept it?
- blibble 5y agothere are plenty of forums dedicated to this, here is a guide to do exactly what I described above: https://www.win-raid.com/t3061f16-Guide-How-to-extract-insert-replace-EFI-BIOS-modules-by-using-the-UEFITool.html https://www.win-raid.com/t3061f16-Guide-How-to-extract-inser... they don't need to be signed or you can dig through the manufacturers official documentation (often accessible behind NDA) don't blame me if you brick your hardware
- tomc1985 5y agoYou can boot to a stub OS on the system that can chainload whatever you want afterwards. This is how GRUB et al work.
- saghm 5y agoYeah, every time I have to update my bios over ethernet, I kind of just shudder internally. Downloading and flashing is a pain, but it still just feels wrong for some reason.
- m463 5y agoMany uefi systems do lots of "fun things" because they have network access. Take a look at ASUS motherboards, which has Armory Crate in UEFI. It will download and install software in your windows install. ...automatic bloatware from the bios.
- profile53 5y agoLenovo’s superfish was my favorite example of that