4 ms·
That's... not really it. Do you really think there are backdoors hiding in firmware blobs from reputable vendors?
by rossy 3y ago
That's... not really it. Do you really think there are backdoors hiding in firmware blobs from reputable vendors?
- lrvick 3y ago100%. I have plenty of insider knowledge here I sadly cannot share, but search for supply chain attacks and the sheer number of public headlines of known attacks can keep you busy for days. State actors are constantly trying to get footholds in software supply chains, and often succeed. Consider Intel ME firmware is a literal well documented backdoor we do not allow on US government systems... only civilians. Most of the time our adversaries do not need to be covert enough to mess with firmware. Consider OMA-DM apps that run on most phones with insane permissions taking orders from cell towers. https://gist.github.com/thestinger/171b5ffdc54a50ee44497028aa137ed8 https://gist.github.com/thestinger/171b5ffdc54a50ee44497028a... We cannot even keep public open source repos like NPM free of supply chain attacks. Proprietary blobs make it that much easier to hide things. Also all you need to backdoor every encrypted messenger is a kernel module that ensures /dev/urandom is a bit less random on the devices of targeted dissidents and journalists. Now look at how many proprietary blobs from piles of random vendors we load into modern phone operating systems, even "open" android roms, and think about SolarWinds for a second.