5 ms·
This reinforces my policy of buying laptops with the cheapest drive offered and replacing the drive with an SSD before the first boot. I run Linux anyway, so bo
by faster 12y ago
This reinforces my policy of buying laptops with the cheapest drive offered and replacing the drive with an SSD before the first boot. I run Linux anyway, so booting Windows has no value for me.
- beagle3 12y agoYou also have to reflash all firmware with known-trusted versions using a known-trusted reflasher to be safe. ... and replace the CPU with one that is known not to have backdoors. You'll have to craft it from Silicon yourself, though, because there aren't any available for sale anymore.
- unethical_ban 12y agoThis is what it looks like when people don't recognize that security is a spectrum.
- acadien 12y agoCan't you just write all 0's to the drive or just reformat it? Genuine question here, why would you need to physically replace the drive to ensure security when you can write to the whole thing?
- toomuchtodo 12y agoWould have to re-write/re-flash the firmware as well.
- acadien 12y agoWhat is it that the firmware can achieve? Is the firmware capable hijacking data, communicating with the NIC and transmitting data? Or is it somehow injecting harmful code? I feel like I'm missing something here.
- bzbarsky 12y agoThe drive firmware can change the bits going to/from the drive, no? For example, it could binary-patch (either at write time or read time) your kernel image on disk to communicate with the NIC, etc...
- toomuchtodo 12y agoYes. http://www.theregister.co.uk/2015/02/17/kaspersky_labs_equation_group/ http://www.theregister.co.uk/2015/02/17/kaspersky_labs_equat...
- ohazi 12y agoBrilliant demonstration from a few years ago of what's possible with a hard drive firmware hack. You're basically completely fucked. http://spritesmods.com/?art=hddhack&page=1 http://spritesmods.com/?art=hddhack&page=1
- acadien 12y agoThanks, exactly the kind of information I was trying to elicit.
- panarky 12y agoRipped from yesterday's headlines ... ... rewrote the hard-drive firmware of infected computers—a never-before-seen engineering marvel that worked on 12 drive categories from manufacturers including Western Digital, Maxtor, Samsung, IBM, Micron, Toshiba, and Seagate. The malicious firmware created a secret storage vault that survived military-grade disk wiping and reformatting, making sensitive data stolen from victims available even after reformatting the drive and reinstalling the operating system. The firmware also provided programming interfaces that other code in Equation Group's sprawling malware library could access. Once a hard drive was compromised, the infection was impossible to detect or remove. http://arstechnica.com/security/2015/02/how-omnipotent-hackers-tied-to-the-nsa-hid-for-14-years-and-were-found-at-last/ http://arstechnica.com/security/2015/02/how-omnipotent-hacke...
- 12y ago
- viraptor 12y ago> with the cheapest drive offered and replacing the drive with an SSD I expect the "cheapest drive" is not an SSD.
- tdurden 12y agohence "replacing the drive with an SSD"
- viraptor 12y agoI don't understand the downvotes. The gp probably asked why not just zero-out the bytes. Sure, there's the firmware modification issue. But what I was responding to is why replace. This is the easiest option.
- DanBC 12y agoPost says "buy the laptop with the cheapest drive; then replace that cheapest drive with an SSD". You said "the cheapest drive is not an SSD". The point is to minimise the money spent on the drive supplied with the machine because you're not going to use that drive, you're going to throw it away.
- mojoe 12y agoI recently did this exact thing -- bought a Lenovo laptop with a 5400 RPM disk drive, and immediately popped it out and replaced it with a Crucial MX100 SSD. Installed Linux, it works great :)
- x0x0 12y agoor a mac. Apple will do something like this when hell freezes over.