Skip to content

Comment on Introducing Ring -3 Rootkits: BIOS rootkit targeting vPro chipsets (2009) [pdf]parent

Comments

such as the ability for userspace programs to downgrade/upgrade the BIOS at will?

I assume some amount of privileges would be required to reflash. By "at will", do you mean that once those privileges are acquired, there is no notification or confirmation to the user? (Or perhaps it is easier than I think to reflash.)

Apparently they've added some downgrade protection[1]:

The recent patch mentioned above solves this problem by displaying a prompt during reflash boot, if reflashing to an older version of BIOS. So now it requires user intervention (a physical presence). This "downgrade protection" works, however, only if we have administrator password enabled in BIOS.

[1]: http://theinvisiblethings.blogspot.com/2009/08/vegas-toys-pa...

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.