Skip to content

Comment on Australian customs searched more than 40k devices in 5 yearsparent

Comments

Would a factory reset remove these root kits or backdoors?

Hypothetically? Not necessarily as an attacker can stage malware in places that will survive a factory reset. Eg: Malware can live in firmware; or recovery volume not wiped in Factory Reset. An extremely resourced attacker could write malicious microcode to your CPU. Can’t reset that.

Realistically? it means CoTS gov grade malware like gamma finfisher etc, which should die when all persistent flash or disk storage is reset.

Practically, I would guess that it’s whatever the capabilities of Australian malware vendors are shipping feature wise for the products you are trying to protect.

“It depends on your threat model”.

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.