Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Wow. I always knew hardware manufacturers half-assed their software, but this is kind of a new low.

I'm not sure whether to laugh or cry.



Could be worse, the title made me imagine UEFI firmware itself making HTTP downloads and reflashing itself ;)


I thought that too and then got terrified of the idea that someone trusting an HTTP connection writing (parts of) a damn BIOS. This would be worse than anything.

Actually I also don't like BIOS allowing to be flashed from within the OS for convenience. So your computer gets owned and you can't trust your motherboard anymore.


I hate this idea as it usually means that you have to run Windows to upgrade BIOS...


You require Windows regardless. I have an old HP dm1z that's started playing up with a recent Linux release.

Solution? New BIOS firmware. Problem? Can only update via Windows binary.

I wish I was joking, but quite a few HP laptops can only be updated via Windows binaries...


Solution: buy computers with "generic" motherboards, not OEM boxes.

I have had like 5 different motherboards in the last 10 years and all could be updated from a flash drive with the BIOS setup.

And yes, this required user action, they didn't just automatically flash random files from pendrives present during POST ;)


Newer motherboards with ASUS EZ Flash can do that. I don't think it's automatic though.


Intel NUC has an option to directly pull down/install BIOS updates built into UEFI as well, and thus probably other newer Intel boards.

Convenience and security are often orthogonal.


They do that so people with hundreds of servers do not have to spend days in the server room with thumb drives, individually booting servers to flash the BIOS. There is HUGE demand for the ability to do remote BIOS updates over a management network. Now how is the BMC supposed to know whether the network is appropriately secure before accepting those updates?


The network shouldn't ever be considered appropriately secure - always treat the network as hostile, and install the updates iff you can be sure that you have received the proper data (with appropriate signatures) over the untrusted network.


You should never trust the network; firmware updates should have to be cryptographically signed and validated against a pinned certificate to be accepted.


The only "good" answer to whether the BMC is supposed to know whether the management network is "secure" would be a song and dance like 802.1x and any authentication configured on top of that, before even allowing you to submit an image for flashing, let alone trying to verify it.

(You could argue that the existence of good signature verification on the images is often sufficient, but if you have an older BIOS that's signed but has an exploit vector, you could still make use of that if you had unfettered access other than the signature checking.)


Convenience and security are often closely related: you need regular updates to maintain security, and if it isn't convenient, people won't do it.

As long as the updates handle security properly (use HTTPS and verify signature), I don't see anything wrong with an "update" button in the BIOS.


Yes it does! Although it doesn't seem to work behind a firewall. LOL. In case direct-from-BIOS flash updates aren't silly enough, imagine having to put your server on the naked internet to boot. No thanks. Even TFTP would be better than that.


Yeah, thats what the title said to me too. Not the case for me since I don't use any of those windows tools from Asus. (run linux instead on all of them)


The fun thing is that this is not about the UEFI BIOS binaries itself, which normally must be signed and the signature is checked during UEFI capsule update. The HN title is not exactly correct.


I am pretty sure that Intel management engine can do that, though obviously it doesn't... Yet


I have a Z77 motherboard that can do that. Not automatically though.


Worst part is that they didn't even respond to responsible disclosure.

I think someone should write a 'virus' that would remove that vulnerable software from users' computers.


Someone should write a virus that replaces the ASUS logo with Goatse, if the damnable thing really is upgradable from within the OS.

That should be enough to make them take security seriously (and not really hurt anybody.)


Or with Apple logo, for some extra confusion and hilarity.


Sadly, with the current state of the law, you'd be prosecuted for hacking and ASUS goes free. Which is ridiculous.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: