SoylentNews
SoylentNews is people
https://soylentnews.org/

Title    Millions of PC Motherboards Were Sold With a Firmware Backdoor
Date    Friday June 02 2023, @12:27PM
Author    janrinok
Topic   
from the dept.
https://soylentnews.org/article.pl?sid=23/06/01/1453230

upstart writes:

Hidden code in many Gigabyte motherboards invisibly and insecurely downloads programs:

Hiding malicious programs in a computer's UEFI firmware, the deep-seated code that tells a PC how to load its operating system, has become an insidious trick in the toolkit of stealthy hackers. But when a motherboard manufacturer installs its own hidden backdoor in the firmware of millions of computers—and doesn't even put a proper lock on that hidden back entrance—they're practically doing hackers' work for them.

Researchers at firmware-focused cybersecurity company Eclypsium revealed today that they've discovered a hidden mechanism in the firmware of motherboards sold by the Taiwanese manufacturer Gigabyte, whose components are commonly used in gaming PCs and other high-performance computers. Whenever a computer with the affected Gigabyte motherboard restarts, Eclypsium found, code within the motherboard's firmware invisibly initiates an updater program that runs on the computer and in turn downloads and executes another piece of software.

While Eclypsium says the hidden code is meant to be an innocuous tool to keep the motherboard's firmware updated, researchers found that it's implemented insecurely, potentially allowing the mechanism to be hijacked and used to install malware instead of Gigabyte's intended program. And because the updater program is triggered from the computer's firmware, outside its operating system, it's tough for users to remove or even discover.

"If you have one of these machines, you have to worry about the fact that it's basically grabbing something from the Internet and running it without you being involved, and hasn't done any of this securely," says John Loucaides, who leads strategy and research at Eclypsium. "The concept of going underneath the end user and taking over their machine doesn't sit well with most people."

In its blog post about the research, Eclypsium lists 271 models of Gigabyte motherboards that researchers say are affected. Loucaides adds that users who want to see which motherboard their computer uses can check by going to "Start" in Windows and then "System Information."

From my understanding of the problem it appears to affect Windows OS, but any insecurity in the UEFI firmware is a major cause for concern [JR]

[Edited to remove duplicate paragraph-JR 2023-06-02 16:46:23Z]


Original Submission

Links

  1. "upstart" - https://soylentnews.org/~upstart/
  2. "Hidden code in many Gigabyte motherboards invisibly and insecurely downloads programs" - https://arstechnica.com/security/2023/06/millions-of-pc-motherboards-were-sold-with-a-firmware-backdoor/
  3. "blog post about the research" - https://eclypsium.com/blog/supply-chain-risk-from-gigabyte-app-center-backdoor/
  4. "Original Submission" - https://soylentnews.org/submit.pl?op=viewsub&subid=59841

© Copyright 2024 - SoylentNews, All Rights Reserved

printed from SoylentNews, Millions of PC Motherboards Were Sold With a Firmware Backdoor on 2024-04-25 17:48:50