24 ms·
CosmicStrand: The discovery of a sophisticated UEFI firmware rootkit
- haswell 4y ago> The most striking aspect of this report is that this UEFI implant seems to have been used in the wild since the end of 2016 – long before UEFI attacks started being publicly described. This discovery begs a final question: if this is what the attackers were using back then, what are they using today? I always marvel at the ingenuity and technical complexity of these kinds of attacks, but this is also something that makes me lose sleep at night. I can’t help but wonder just how utterly compromised we all are, and won’t know it until many years down the line.
- joshspankit 4y agoThis has been echoed in physical security for as long as it’s been around. Look at “bump keys” for example. Those who have the knowledge walk right through security barriers like they aren’t there and meanwhile security companies make optimistic claims of safety just to sell more locks.
- loldk 4y ago
- teawrecks 4y agoYeah, I assume that either everything is infected and backdoored and there's no way to detect it until it's too late, or almost nothing is infected because doing so would be the cross platform compatibility nightmare of all nightmares. I don't know which one it is.
- rtev 4y agoDefinitely the first. Beacons have better cross-platform support than most Microsoft products.
- eikenberry 4y agoMicrosoft sets an extrememly low bar as they only want one platform, theirs.
- ActorNightly 4y agoMost modern exploits on this level are extremely difficult to get onto users machines - without any conspiracy at play, you would have to essentially get users to run untrusted code, and for general use case there are a whole bunch of blockades against this. For private entities seeking financial gain, its completely pointless to burn a zero day like this for the return that you would get.
- hulitu 4y agoReally ? On some of my computers the UEFI partition is a FAT32 partition writable by anyone by default.
- hgazx 4y agoWhat systems are those? Windows doesn’t allow you to do that by default unless you’re an admin.
- Arnavion 4y agoAny systemd-using Linux distro will also automount /efi as writable only by root (assuming the mount was generated by GPT auto generator, not by a specific fstab entry), so it's not that either.
- tinus_hn 4y agoNormal home users are administrators, they have to go through the pop-up to run things with escalated privileges but that, according to Microsoft, is not a security boundary.
- Arnavion 4y agoIf we're considering Administrator / root access as trivially available, then any exploit becomes trivial itself. Even on a BIOS machine root can overwrite the MBR / kernel / initramfs to contain an exploit.
- 4y ago
- bitwize 4y agoYou know what'll help? Pluton. The future of computing is a signed code path from power on to end-user application code with multiple layers of sandboxing in between. With so many hostile actors, from script kiddies to government agencies out there, "general purpose computing" (which, from a security standpoint, is just arbitrary code execution) just isn't viable anymore. We need provable attestation that no layer of the software stack has been tampered with.
- eikenberry 4y agoAs long as we control each layer this sounds great. What are you thinking, some sort of physical switches on the computer that turns on and off access to the layers from software so you can control them individually? That's the tricky part, how to switch those layers on and off so you can work with them in a non-software controlled way.
- rolph 4y agoyes that is a problem, even bigger is that pluton is intended to make this as close to impossible as is possible. pluton is about burying TPM and keys in the processor package rather than as a separate host on the bus. this could be defeated by using microsurgical technique to reveal the die and alter the connections, an extreme effort requireing an extreme motivation.
- hulitu 4y agoSo you will have backdoored SW but you will not be able to replace it because it is "secure".
- OneLeggedCat 4y ago“With so many hostile actors” Like Microsoft? And like government actors compelling Microsoft via things like NSL’s?
- fsflover 4y agoIf you care about security, consider using Qubes OS. It will be extremely hard to infect your UEFI from a VM.
- agiacalone 4y agoShameless self-plug here. I wrote about the potential for this problem in 2014 for my graduate thesis. https://search.proquest.com/openview/cd06aab6e06951ba6cdc064f959e8cb9/1?pq-origsite=gscholar&cbl=18750 https://search.proquest.com/openview/cd06aab6e06951ba6cdc064... Edit: to the parent, I shared many of the same concerns back then, too. I tried to speak to those anxieties in my final product.
- saltminer 4y ago> I can’t help but wonder just how utterly compromised we all are, and won’t know it until many years down the line. It's not hard to imagine. USB-C 3.0+ cables all need chips inside them for negotiating USB-PD, among other things. Imagine what could be done with an infected USB-C cable. Yes, of course, keyloggers are possible (that's been done plenty in the past with regular old USB-A 2.0), but think about one of USB-C's common applications: docking stations. If you hooked up your laptop to a docking station with a malicious USB-C cable and you had ethernet, an external monitor, and a keyboard plugged into the dock, you would basically be giving an attacker a VNC session. It could scoop up everything you type, everything on your screen, and communicate via a connection that is entirely transparent to the OS. At that point, your only hope is a firewall flagging the connection, otherwise you'll be completely oblivious to the ongoing surveillance. And it could compromise a network connection to insert a malicious payload into a file you're downloading, just to make the surveillance persistent when you're not plugged in.
- ggm 4y agoI live in fear of being told my factory delivered Dell rackable servers have been EFI infected since inception on my network. It's silly to pretend a BSD OS is going to be immune of the consequences of an EFI which is compromised at birth. Sooner or later there will be a value chain in compromising my OS, through the EFI. I wish we had better out of band EFI validity checks, based on what the manufacturer thinks should be there, as a reproducible bitstream.
- Harvesterify 4y agoYou can use the Dell Trusted Agent to to do just that: https://www.dell.com/support/kbdoc/en-us/000126098/what-is-dell-trusted-device https://www.dell.com/support/kbdoc/en-us/000126098/what-is-d...
- extrapickles 4y agoIt would also help if there was a standard header on the mainboard that you can use to verify all of the flash chips when the computer is powered off to minimize the amount of the computer you have to trust. While some may argue that this header would be the perfect place to install a implant, doing so is vastly harder than popping some manufacturers computer. Also, since the header will be specifically checked by some users, it becomes a very risky place to install an implant.
- yjftsjthsd-h 4y agoI think it would be easier to do it safely if you made it so that the number of chips to be flashed was small and they were easy to pop on and off the motherboard. I grant that this is more work to use than a single master connector, but it removes that point of vulnerability both for undermining the ability to flash things and the massive backdoor that is a single port with the ability to reimage every chip in the machine.
- woliveirajr 4y agoRegarding the alegation that sems to be chinese actor: isn't kaspersky gone from the western world after russia x ukraine? And so... this could be undetected just because kaspersy isn't being used anymore?
- mistrial9 4y agoas a civilian, I am repeatedly amazed at the relentless, intrusive and manipulative tactics that the "heroes" use on the "sheep" .. I am quite capable of managing my own affairs and have invented and solved using computers for decades. I have a sense of personal sovreignty that is offended and threatened by one-way-mirror, controlling, destructive Spy-vs-Spy comic books being played out by eternally funded jerks. I am not running to DELL to save me from "scary" hacks -- indeed, I am being victimized and trodden on by DELL and "state actors" .. DELL is a "state actor" .. ugh
- reedjosh 4y agoThis! ^ Tech companies are all subjects to the government in which they operate. They have become spies. The real terror is when you can't buy chips that don't spy on you.
- Schroedingersat 4y ago> The real terror is when you can't buy chips that don't spy on you. So about 5 years ago?
- reedjosh 4y agoNo joke
- fguerraz 4y agoThat's why things like the Pluton processor and TPMs are useful. (A rain of downvotes falls on me) Seriously, even good old BIOS is susceptible to rootkits, there has been tons of them. So no crying over UEFI please. We need a fully signed and auditable chain of trust for booting OSes. Of course all this crap needs to be open source but it needs to be locked down to prevent not trusted binaries as much as possible. And for the 1% of people who are going to bang about their right own the hardware and run Linux and what not (I'm definitely one of those), we need to be able to do it but in an obvious way (computer should boot but display a clear message that it's been tinkerer with). I really like software freedom, but the fact that I can disable secure boot on pretty much any computer I have physical access to and that the user will never know about it is not okay.
- vorpalhex 4y ago"I'm sorry but your computer is not running Genuine Windows 11:tm:. You may not be secure." will be the new "An application is attempting to make changes to your computer..." Alert fatigue is real.
- fguerraz 4y agoAlert fatigue is real but silent rootkits are way worse. Also, it's not just about booting windows or the OS, it's about the UEFI, which even fewer people are going to want to tinker with.
- BiteCode_dev 4y ago
- robotnikman 4y agoSuch sophisticated attacks always amaze me, and I've always wondered how people go about developing them in the first place.
- mistrial9 4y agosomeone who worked on the UEFI implementation writes it
- j16sdiz 4y agohooking into win32 kernel is not something uefi developers usually do
- unnouinceput 4y agoYou say it like the kernel is, at that moment in time, running, when in fact is just a simple .dll file just sitting there and is being manipulated by the uefi no different than what Notepad does to a text file. Also the article says it clearly that the uefi rootkit is searching and replacing functions within the kernel and then putting them back once the next phase is complete, in order to avoid security check. Hooking in windows is a technique allowed by the OS, while this "hooking" is nothing more than just simple search/replace file operation. That's being taught like in 1st month on any coding school.
- colinsane 4y agoif you were handed the UEFI implementation codebase like a new-hire, how long would it take to figure out this potential codepath? a couple days? now if you were handed only the binaries, and left to objdump them etc, how long? evidently there’s symbol names since the article uses those. so hopefully no more than an extra order of magnitude: a couple weeks, maybe a full month if my manager’s asking for a deadline and i want to be conservative? also, think about where/how they hooked: it sounds like they hooked at the equivalent of an interface boundary, where it’s easiest to inject a new implementation — but then they have to check the return address to know where in the larger scope of the process they’re currently at: if you had access to the codebase and build tools why wouldn’t you patch your exploit into the code more directly and just rebuild it? why abuse the return address like that? i don’t mean to say it’s not impressive, but it’s not magic. there are lots of competent engineers out there capable of reverse engineering a UEFI implementation.
- m3kw9 4y agoIf you have good info or known to have “good” info, just assume you are being watched.
- denton-scratch 4y ago> One of our industry partners, Qihoo360, Ooh, I recognise that name. They were involved in certificate shenanigans with Startcom. I'm immediately suspicious. (I've barely started reading the article, but I'm predisposed to distrust anything involved with Qihoo)
- deleted 4y ago[deleted]
- rnk 4y agoThe ars technica article said it was windows focused, but the same techniques should work on other OS. If you had network monitoring how hard would it be to see this firmware-kit trying to talk to the internet. Is it sophisticated enough to hide in normal traffic somehow?
- stinkass 4y agoHah, this reminds of a security researcher a few years ago that was reporting malware that he couldn't research without infecting his other machines. I'm fuzzy on the details, but everyone wrote him off as a paranoid delusional and the incident was quickly swept under the rug. Makes me wonder if he found some sophisticated state sponsored stuff and got smeared to hush it up. I mean realistically, we'd be naive to not expect that state-sponsored hackers have rooted machines somewhere in the supply chain (hardware, firmware and of course software). Is everyone being monitored all the time? No, but I'd stay away from electronics if I expected an intelligence agency was interested in me.
- from 4y agoMaybe you're thinking of https://en.wikipedia.org/wiki/BadBIOS https://en.wikipedia.org/wiki/BadBIOS.
- hrgiger 4y agoShutting down everything because of paranoia sounds a bit extreme
- dboreham 4y agoEventually it electrifies its power cord so that if you try to power it off you get zapped.
- numpad0 4y agoI had that kind of megalomaniac fantasy in the past, but the started to think that xkcd.com/2347 (“random person in Nebraska”) should apply to NSA malware too, and there can’t be as much tons of people working on it as in my imagination. Though I’d happily cooperate if me watching team did exist and came out of shadows to clarify their doubts and pass along the taxpayer money saved :)
- tepitoperrito 4y agoFurious searches for BIOS only era hardware are taking place on ebay as we speak. To use with a modified Linux kernel that emulates a bog standard Thinkpad uefi environment of course. EDIT: I forgot to phrase this as a question - besides missing a QubesOS or KickSecure on top, is this a decent plan for airgapped stuff?
- justsomehnguy 4y agoJust run your OS in a VM.
- sitzkrieg 4y agowhat should you run the vm on?
- dboreham 4y agoA turtle.
- justsomehnguy 4y agoOn a trusty prehistoric hardware obtained in Brown Sector.
- Arnavion 4y agoI'm not sure what you mean by "a modified Linux kernel that emulates a bog standard Thinkpad uefi environment". The UEFI environment is provided by the firmware and starts EFI applications, which could be a UKI containing your kernel+initramfs, or grub that then starts your kernel+initramfs from /boot, or anything else. ie the UEFI sits below the kernel. UEFI can be emulated on top of BIOS using something like Clover. But for your BIOS-only mobo, just keep using it with a BIOS-only bootloader, ie GPT disk with grub or whatever written to the MBR + BIOS Boot partition. There's no reason to involve any UEFI, emulated or otherwise. You will obviously not have as good protection from evil maid attacks as you would've gotten from Secure Boot. But presumably you're okay with that, and emulated UEFI will not help in that regard anyway.
- rwaksmunski 4y agoMy hopes of large volume fully open source systems died when I learned that beefy RISC V boards will ship with UEFI.
- GoOnThenDoTell 4y agoYou can implement something else, riscv is a young isa
- Taniwha 4y agoyup, RISC-V happily boots with just uboot
- buildbot 4y agoYep! You can run linux even on an entirely open source from hardware to software toolchain: https://github.com/litex-hub/linux-on-litex-vexriscv https://github.com/litex-hub/linux-on-litex-vexriscv Though the FPGA IC itself of course is not open, the bitstream generation is, and there are many fully open source hardware board designs, for example the orangecrab. With a Lattice 85K gate FPGA, you can get 4x 32bit riscv cores at 50Mhz or 1 64bit riscv rocket 64 bit core at 20Mhz
- jeroenhd 4y agoUEFI can work open source no problem. You'll still need binary blobs for memory initialisation and such, because no open systems exist for that, but the boot process isn't really closed. Aside from open source UEFI setups like Tiano, you can also use CoreBoot or LinuxBoot where UEFI doesn't work for you.
- deleted 4y ago[deleted]
- zekica 4y agoUEFI is not proprietary. EDK2 is a complete UEFI implementation licensed under the BSD license.
- blueflow 4y agoI remember being called a reactionary naysayer like, 8 years ago, because i told that this would happen.
- fezfight 4y agoA lot of people don't like negativity so strongly that they'd rather be screwed over than have to consider the possibility that something bad is happening.
- blueflow 4y agoA lot of people don't like idealism so strongly that they'd rather stick with old hardware over the newest hyped-to-death shit.
- ccbccccbbcccbb 4y agoWe'll see a lot more 'conspiracy theories' proving out to be perfect practices in the near future, and the funniest thing is that none of those who label critically thinking people as tinfoil hats would admit their fallacy, on the contrary - they'll be ardently asserting that they 'definitely saw it coming' too! Cognitive dissonance is a scary thing, makes people doublethink by repressing the conflict between expectation and observation into the subconscious.
- hoppla 4y agoChipsec (https://github.com/chipsec/chipsec https://github.com/chipsec/chipsec) is a project to check for bugs in your firmware.
- de6u99er 4y ago>We were able to identify victims of CosmicStrand in China, Vietnam, Iran and Russia. I wonder if those computers could be used for false flag operations?
- ineedasername 4y agoThis rootkit is old by computing standards (2016), and apparently found somewhat by chance in that it was found in free (probably consumer) users of their product. Could this indicate a higher likelihood of it being a consumer board supply chain attack? It might explain the lack of detection in business oriented computers, though it also would seem to indicate that it was not precisely targeted.
- figmaheart255 4y agoI wonder why more computers don't use the simple boot model that devices like the Raspberry Pi use. From what I've heard, the RPi is effectively immune from persistent malware. Firmware can't be modified [1], and while the second stage bootloader can be flashed in the RPi 4, the first stage bootloader can't be modified [2]. What this basically means is that no matter what infects your pi, you can always just replace the SD card and restore it to a clean state. In contrast, I've heard so much news about how USB firmware can get reprogrammed [3], how PC malware can survive BIOS reflashing [4], how malware can live in external drive firmware, etc. Of course, if there's a bug in the raspi firmware, it also can't be fixed, but the attack surface is so small I'm willing to make the trade-off (and buy a new pi if it comes to light). [1]: https://raspberrypi.stackexchange.com/questions/8963/are-the-bios-and-firmware-located-on-the-sd-card https://raspberrypi.stackexchange.com/questions/8963/are-the... [2]: https://www.raspberrypi.com/documentation/computers/raspberry-pi.html#raspberry-pi-4-boot-flow https://www.raspberrypi.com/documentation/computers/raspberr... [3]: https://security.stackexchange.com/questions/97246/badusb-why-are-firmware-writeable-in-the-first-place-manufacturers-backdoor https://security.stackexchange.com/questions/97246/badusb-wh... [4]: https://security.stackexchange.com/questions/44750/malware-that-can-survive-bios-re-flashing https://security.stackexchange.com/questions/44750/malware-t...
- yjftsjthsd-h 4y agoI would actually be on board with that, if the boot/firmware (micro)SD was separate from the main OS drive, because the annoying thing about the Pi is that it can't take generic images - you have to flash a pi-specific image to your card because it has to include the firmware. There's a part of me that says by the time you've put the boot firmware on a dedicated card and made that card robust enough to survive the lifetime of the machine you've just reinvented built-in flash chips, but I agree that the ability to trivially remove it and have all the (changable) firmware in one card is an improvement over the status quo.
- shadowpho 4y agoRaspberry pi has firmware on the USB hub AFAIK :)
- buildbot 4y agoThis is something that Pluton /TPMs can help prevent via attestation. Pretty funny to read comments here saying that they wish there was a way to plug something into a motherboard to verify all of the software/firmware components.
- richardfey 4y agoThis exploit would only work when CSM is enabled? Nowadays with SecureBoot I think it would have to be much more complex? (patching all functions in UEFI, bootloader and OS to bypass the verification).