Secure Boot is completely broken on 200+ models from 5 big device makers

Discussion in 'other security issues & news' started by stapp, Jul 26, 2024.

  1. stapp

    stapp Global Moderator

    Joined:
    Jan 12, 2006
    Posts:
    25,131
    Location:
    UK
    Article lists affected models

    https://arstechnica.com/security/20...mised-on-200-models-from-5-big-device-makers/
     
  2. stapp

    stapp Global Moderator

    Joined:
    Jan 12, 2006
    Posts:
    25,131
    Location:
    UK
  3. reasonablePrivacy

    reasonablePrivacy Registered Member

    Joined:
    Oct 7, 2017
    Posts:
    2,110
    Location:
    Member state of European Union
    I glanced over article. It seems that keys used for testing purposes were leaked... and at the same time they are used by multiple OEM/motherboard vendors.
    On one hand this is each and every motherboard vendor fault.
    Still, the best practice, or even compliance requirement, not fulfilled by AMI is to not include credentials in product and test code repository. Then you deliver source code to customer that basically doesn't work until they generate their own keys or other credentials. At least you would reasonably suspect that each and every customer has separate key pairs by doing this.
     
    Last edited: Jul 26, 2024
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.