Mac OS High Sierra automatically checks EFI firmware each week
eclecticlight.co
eclecticlight.co
Seems the collection behaviour is also pretty straightforward to avoid, since you could just have an NVRAM region with the actual code in it, or a decryption stub.
Then again, at least it's something, no use raining on their parades.
The correct solution to this is secureboot. No need for ME shenanigans.
Specifically, the Touchbar updates have no concept of proxies and will cause the machine to appear to hang for a while (~20 minutes, IIRC) on boot when they can't directly phone home. This is a big problem on some large corporate networks.
They had the exact same problem with installing system images via proxied networks a little over a decade ago. I wonder if they're utilizing the same coders.
As to whether or not this tool will flag it, I suppose you'll find out shorty after installing High Sierra.
/usr/libexec/firmwarecheckers/ethcheck/ethcheck:
usage: ethcheck: [ --save -b <eth nvram bin output file> ] [ --integrity-check [ -b <eth nvram bin input file> ] ] [ --show-hashes [ -b <eth nvram bin input file> ] ] [ --cleanup -b <eth nvram bin input/output file> [ --send-change-in-firmware enable/disable] [ --version]
Also, it would be helpful if PCIe, HDMI, USB, Thunderbolt, etc. drivers ask permission of the user before automatically connecting devices inserted into PCs... basically a peripheral "firewall." There are too many buses that are happy to give up the FSB and PCIe-side without authorization. Hell, it would be even better if buses used some sort of minimal-but-essential PKI and encryption.
Isn’t that what Intel ME is? The only difference being we don’t know what exactly it does?
Thunderbolt 3 does exactly this (at least on Windows). When connected to new hardware it asks whether to approve it or not (e.g. for Dell dock I had to approve both the dock and the cable).
Then again with quotes also works, as long as you balance them.
> sw_vers -productVersion
10.10.5
> uptime
22:37 up 58 days, 14:45, 7 users, load averages: 2.65 2.87 2.36For me that would be waaaay less often than weekly. Doing both would make some sense. Though a large sample like almost all OS users should mean everyone's week is different and an attack that involves multiple machines should start triggering reports very quickly.
My Macbook has been up and running without a reboot for almost a year.
I suspect that either the 2017 spec bump fixed the issues present in the 2016 version or the crashes you mention are tied to specific software.
Dell, HP and Lenovo all have such machines.
Crash almost always occurs on wake from sleep (when plugging in monitors and other USB C peripherals)
I've found that it is actually much less annoying in the morning to start from scratch than to wake from sleep, because when I start from scratch I only have to enter my password once and it covers all of those aforementioned things.
This wasn't the case before I replaced the original hard disk with an SSD. It was then slow enough to boot that I'd find myself waiting with nothing to do.
The SSD is fast enough that it gets through the boot and to the password prompt while I'm still busy unpacking the breakfast I bring in to the office with me, and after I enter the password gets all my startup items launched and ready while I'm still finishing up unpacking breakfast.
I’ve been running the High Sierra GM since it was released a week ago.
Here's the command:
usage: eficheck: [ --save -b <EFI bin output file> ]
[ --cleanup -b <EFI bin input/output file> ]
[ --generate-hashes [ -b <EFI bin input file> ] [ -p <Output folder path> ] ]
[ --integrity-check [ -h <EFI hash input file> [ -b <EFI bin input file> ] ] ]
[ --show-hashes [ -h <EFI hash input file> ] | [ -b <EFI bin input file> ] ]Long term, I could potentially see this being modified to pop up every time on startup, as a "We know what you're doing, and we don't like it" signal to the Hackintosh users out there. However, that seems like kind of a dick move for such a small (and passionate) fraction of your market.
Pleasantly surprised.