Second Chinese Firm in a Week Found Hiding Backdoor in Android Devices
bleepingcomputer.com
bleepingcomputer.com
http://www.techworm.net/2015/08/lenovo-pcs-and-laptops-seem-...
Even the ISP provided routers are backdoored:
http://www.computersolutions.cn/blog/2014/09/hacking-shangha...
Some of the obvious backdoors are easy to circumvent. e.g. If a Linux distribution is your operating system of choice, you automatically bypass that Lenovo backdoor.
http://www.zdnet.com/article/former-pentagon-analyst-china-h...
Such firmware could for example scan system memory for cryptographic keys and send them over wifi or ethernet connection, without main OS even knowing.
SMM code is going to be executed at arbitrary times at highest possible privileges regardless of operating system.
Also any microcontrollers inside laptop manufacturers' ASICs can also do pretty much anything the manufacturer wants them to do (or possibly even some other party compromises them to do).
Manufacturer itself might not even be aware they're shipping compromised systems.
SMM interrupt code comes from the very same BIOS image and is executed at arbitrary times regardless of operating system. SMM code can do pretty much anything it pleases, it runs at the highest privilege and priority level possible.
I think it's just silly to talk about some ACPI table payload, when there's a greater threat controlled by the same binary blob.
SMM can do anything that ACPI payload could do and more. And we need to trust the same entity for its integrity.
SMM is also operating system independent. It'll run no matter what operating system end user runs.
> So, hypothetically speaking, say a laptop firmware has an SMM backdoor, how does using Linux bypass it in any way?
Aside from that, good point.
I think it's UEFI mounting the Windows partition and dropping some files there before booting the OS. ACPI executes on a virtual machine inside the kernel and afaik it's not supposed to be able to write to files.
Even if nobody from China intends to kill you, those backdoors will be used by other spy agencies/drug cartels/criminals, too, whether China intends for it to happen or not. At the very least they may be used for ransomware that asks for $1,000 to unlock your car - or not drive you off a cliff.
As far as the geostrategic component of telecommunications choice, when was it not like this? Postal letter: address logging, letter opening; telegram: logging, transcription; land telephone: call logs and wiretapping; wireless telephone: call logs and wiretapping; email (without STARTTLS): metadata logging and interception; social network: government search order.
The modern encrypted methods of communication (iMessage, PGP, Signal) are the first methods where one could feel comfortable about the local government having extreme difficulty intercepting your communication.
I think it is essential to consider geography when deciding telecommunications hardware, software, and service. There may have been a local maximum in the early-mid 2000s, but this is only part of a long-term trend of improving privacy in telecommunications.
Maybe some actor did add the goto fail for nefarious reasons, but it can quite easily be explained by a merge error.
It's not easy to explain this particular backdoor as anything but a backdoor. From the article:
"The binary responsible for the firmware OTA update operations also includes code to hide its presence from the Android OS, along with two other binaries and their processes. A developer looking at active Android processes won't be able to tell when there's an update coming to his phone."
They don't need to, if they can put malicious code into the hardware, and bypass the software stack entirely.
Didn't they backdoor a crypto standard on the said OSes?
If a device downloads updates over a non-secured channel, it doesn't automatically mean that it will execute the update unconditionally. For example, a package might be signed with vendor's key, the public part of which is shipped with the device. If the sig is missing or invalid, the device will discard the package.
[0] http://blog.anubisnetworks.com/blog/ragentek-android-ota-upd...
It's really past time for Google to take control of Android and stop crap like this.
Last time I checked creating a Google account was optional when setting up an Android device. Can the same be said on iOS?
And more importantly, are there any kits/apps to detect or remove these?
I don't even know where to start....
Here's a vulnerability which completely owns the phones it runs on. This is the kind of thing which a few years ago would have been the scandal that would destroy companies - the pre-SP1 Windows XP Microsoft vulnerabilities were much, much less serious than this and yet Gates saw them as an existential threat to the company.
But apparently vulnerabilities now are so common that - even when they are deliberately put in - the company neglected to pay the ~$20/year to make sure they kept access.
Additionally, for all the talk of how state-sponsored agencies are continually grabbing every resource they could, here is one where they could have taken over a large number of phones and yet failed to.
Additionally, for all the talk of how organized the PLA is.. clearly this wasn't them.
"Little is known about the Ragentek firmware. BitSight researchers said code in the firmware goes out of its way to conceal the presence of the underlying binary file. For example, it deliberately attempts to remain excluded from the list of running processes returned by the Linux PS command."
http://arstechnica.com/security/2016/11/powerful-backdoorroo...