First Sednit UEFI Rootkit Unveiled [video]
media.ccc.de
media.ccc.de
Here's how BIOS works: basically, the computer loads the first 512 bytes of disk into memory and jumps to it. The OS takes over from there and does whatever it needs to, like bootstrapping stage 2 and loading the kernel from the filesystem. The spec[0] is 46 pages long and you are granted the rights to reproduce, distribute, and implement it free of charge.
Want to know how UEFI works? The spec[1] is a 2,899 page PDF which you have to pay to use in any way, including writing an implementation.
[0] https://web.archive.org/web/20110715081320/http://www.phoeni...
[1] https://uefi.org/specifications
Every copy of this specification should be found and burned. The ashes should be buried deep in a dark place and the earth above salted. Anyone who thinks this is the first rootkit made for it is completely insane. This thing was probably explicitly designed with rootkits in mind.
You may be misleading here, AFAIK the spec is free to implement (which helped spread its adoption) or else things like this would not exist or be sued out of existence:
https://github.com/tianocore/tianocore.github.io/wiki/Corebo...
On the other hand, I agree with you and Linus on the actual spec itself:
Quote from the link above
A search for "UEFI royalties" also does not yield anything.
We get it, you hate UEFI as much as anyone else, but this is not really a valid issue to complain about.
But remember Hanlon's Razor: "Never attribute to malice that which is adequately explained by stupidity" (https://en.wikipedia.org/wiki/Hanlon%27s_razor).
UEFI smells like it was designed by a committee, so the value it adds (if any) seems far outweighed by the added complexity (and corresponding security challenges) it creates... to paraphrase Douglas Adams: (and replacing the word "Universe" with "BIOS":)
“There is a theory which states that if ever anyone discovers exactly what the BIOS is for and why it is here, it will instantly disappear and be replaced by something even more bizarre and inexplicable... There is another theory which states that this has already happened...” <g>
I'm not sure why others who respond think if something is old it isn't applicable, I suppose I'm on the X/millennial border so I don't get it though.
>Each time the system restarts, the code executes on boot, before the OS loads and before the system’s antivirus software is launched. That means that even if the device’s hard drive is replaced, the LoJack software will still operate.
AFAIK on my systems the BIOS launches code in the EFI partition to boot the rest of the OS. an HDD/SSD wipe or replacement would defeat code installed in the EFI partition. Of course as you say, something added to the BIOS would run regardless.
Apparently LoJack installs itself in the BIOS as well.
Don't forget systemd.
The original URL (https://threatpost.com/uefi-rootkit-sednit/140420/) looks like a short writeup, but I'm not sure if it adds any new content. And given the tendency to link back directly to source, it's probably worth a change.
Looks like this work was discussed a few months ago: https://news.ycombinator.com/item?id=18090651
"Secure Boot" mode also doesn't protect against the rootkit, because it considers the contents of the UEFI Bios in the SPI Flash the root of trust, and does not do any verification at that stage. It only verifies the bootloader, which loads the OS.
It abuses platforms that do not implement the BIOS Write Lock mechanism incorrectly. (the BIOS is supposed to be write protected after UEFI Boot services hands stuff over to the Operating system)
Incidentally, (according to the video) BitLocker disk encryption can defeat it, though the legitimate LoJack system has a way of working with BitLocker. I think the implication is that a more advanced version of the rootkit may, in the future, work with BitLocker.
To someone who perhaps does not fully understand the implications of a uefi rootkit, the article might seem to imply that it wouldn't work on anything but windows.
I agree that post-boot the BIOS should be read-only.
> The UEFI payload would work on Linux systems, yes. But the delivery system described would not.
There was a case of rm -rf / erasing UEFI variables on linux system, rendering the system unbootable. Mapping the BIOS into the file-system doesn't strike me as too clever, but then again what do I know.
Promise?
I keep my signing key on my machine, but gpg-encrypted bound to a yubikey. Is that frictionless? No, certainly not. Does it provide perfect security? No, certainly not. A dedicated attacker can root my box and wait until I need to sign a module. Does it protect me from loading random kernel modules if I get hit by an automated attack? Most likely. Good enough for what I currently expect as threats.
> Some kernels may require that kernel modules be cryptographically signed by a key trusted by the kernel in order to be loaded. In particular, many distributions require modules to be signed when loaded into kernels running on UEFI systems with Secure Boot enabled.[0]
[0]: http://download.nvidia.com/XFree86/Linux-x86/390.48/README/i...
Instead third party stuff like this comes very occassionally
The name is a misnomer
Reading the old Jargon File entry for the word might clue you in: http://www.catb.org/jargon/html/H/hacker.html
I.e. 'cracker' is used for people that 'crack' software protections (games or applications). I've never heard about "warez d00dz", and none of my friends from the "warez scene" did. Also the Jargon files describe crackers in a very pejorative meaning, while in reality the cracker's social circle contain lots of very skilled individuals, as well as is pretty well filtered-out from anyone that doesn't dedicate themselves to the cracker community. Maybe this is the reason why Eric Raymond didn't have much info about this topic.
So I wouldn't put much faith in Jargon file entries in the same way I wouldn't trust any other urban dictionary. Maybe it's good to get a general grasp at some subject but taking definitions from it is pretty misleading.
A) Either people dont post that kind of stuff here, which is still ironic anytime this century
B) People do post and it doesn't get upvoted
C) People do post and it gets moderated away
I get that it was an all encompassing term, but it hasnt been colloquially this entire century
But to be fair, the Pedantic News wouldnt be a misnomer