New PC malware loads before Windows, is virtually impossible to detect
extremetech.com
extremetech.com
For malware to be really tricky to remove you'd have to start infecting hardware firmware like BIOS or harddrive controllers, like IRATEMONK or IRONCHEF from NSA TAO do.
http://www.zdnet.com/article/hacker-demos-persistent-mac-key...
Or Thunderstrike ?
http://www.zdnet.com/article/macs-vulnerable-to-virtually-un...
It's a MBR attack and the modern Windows systems aren't typically MBR anymore.
I've found AOEMEI (?) to be good for converting other partitions from MBR to GPT but their shareware version won't do boot partitions without paying ;)
According to stopbadware.org a badware is a "[...] software that fundamentally disregards a user’s choice about how his or her computer or network connection will be used."
This in addition to causing general issues. (On at least two occasions have I fixed what weird computer problems just by removing McAfee.)
Oh, and yes: scammy click-by-installers when you try to install other software.
Even fdisk /mbr from a windows bootdisk wouldn't get it. So I installed Linux and it STILL tried to f'ing load. Had to dd the whole mbr from a live linux disk. That worked. My next step would have been mounting it as a secondary drive on another computer.
So this isn't remotely "new" either. It's what I get for wanting to evaluate a video game before buying.
Quite ironic, considering that I classify attempting to work around client software like uBlock, just as shady of a tactic as boot sector malware.
Additional reloads just have a large gray element taking up 20% of my viewing area.
a trusted boot chain means you can't put malware at the start without a much more sophisticated attack than this.
If we can wade through the power-grabs and social-engineering disguised as erudite commentary and philosophizing (similar to that surrounding national security), increasing transparency and user control remains the answer. Any software can have flaws, but software you can't fix because it's locked into hardware is worse. Worse yet is hardware that turns a computer into an single-purpose (flaws-and-all) appliance.
Any bootloader relies on a chain of trust. If the on-disk (OS) portion of that fails (incidentally, the biggest attack surface) and is vulnerable (likely - proprietary software can be fuzzed like any other), then the hardware-linked protection is at best annoying to the actual hardware owner.
In that sense, SecureBoot is actually an inversion of good security principles, which dictate simplicity and accountability/openness. The better place for signed loader verification is in the on-disk bootloader stub. If the OS were perfect, this would be enough too, but at least it is patchable (and the OS is re-installable) when it isn't.
A computer that can't be re-installed when you brick it is expensive garbage that was at best constraining while it even worked.
FOSDEM 2013 had a worthy social and technical overview of UEFI and SecureBoot I enjoyed:
> The better place for signed loader verification is in the on-disk bootloader stub.
That is already part of the Secure Boot. But who verifies the bootloader stub? The point is that you can't trust anything on the disk.
> Any bootloader relies on a chain of trust. If the on-disk (OS) portion of that fails (incidentally, the biggest attack surface) and is vulnerable (likely - proprietary software can be fuzzed like any other), then the hardware-linked protection is at best annoying to the actual hardware owner.
Firmware verifies the (on-disk) bootloader, bootloader verifies the kernel, kernel verifies the drivers, and so on. The chain of trust is there.
And there is no promise that this will not change.
Might as well ditch TLS since soon you'll only be able to get certs for government approved content.
(In a sense, dropping TLS is the correct response... In the sense, of not using the limited set of services. The corresponding response here is to not buy PCs with SecureBoot present in any imposing way, which may mean boycotting "modern" computers that are no longer general, user-controlled, devices if, in the future, they all are locked to Microsoft out of the box.)
But the disk is where my choice of software lives. I trust my choice of software, by definition. I don't want to be removed from that equation any more than I want someone else sleeping with my wife.
If I don't trust my (current) on-disk bootloader, the appropriate thing to do is clean it and put something I do trust in its place. If I wake up hearing a noise, I check my house for intruders - I don't lock myself out and throw away the keys.
The reality is that any chain of trust has to start somewhere. It should start in the place I have the most control: on physically-removable, writable media.
Same goes for malware on most PC operating systems does it not? How can you know the disk has not been silently compromised?
We can't outsource confidence. It doesn't help improve my self-esteem to watch someone else live my life, and it doesn't work to fight "the terrorists" to let someone else make me safe (for some definition of "safe", that I can seemingly no longer contribute to) - but that all seems to be beside the point. :(
Early 1990s nostalgia strikes back ;)