They buy this LibreBoot (blob-free CoreBoot, for the uninspired) …and then they go ahead and install Ubuntu on it?!
No, no, actually they run IBM RHEL or its “free” variants!
It’s all about unknown blobs (binary large objects) embedded in the dynamic processor microcode, firmware —even the chips themselves, even the FPGAs, even the sealed SoCs and processors …or is it?
Maybe the LibreBoot Boys will actually load some obscure distro being maintained by some ethically challenged college-aged non-college students sharing an apartment and using a lot of mind altering substances? A few lines of obfuscated code here, a digital signature there and they have a backdoor “because they can.” Maybe they grow up, move on and another, more innocent, maintainer takes over and the backdoored project is incorporated into many more projects. SabreDAV? Arch? <DrEvil Voice> ReiserFS?
So maybe the LibreBoot Boys are “smart” and run barebones Debian, but then…they start downloading containers because “everyone is doing it” Even if the container images are clean and competent (a big IF), the underlying network/firewall tech in their chosen container orchestration system is at a level of complexity many orders of magnitude above most admin competency —and some of those orchestration apps are also one-man bands, running out of a coffee shop by “some guy”, who probably is late on his rent open to a big bag of cash involving container signatures …or maybe they are just so financially distracted, the complex orchestration software that others are running critical infrastructure on is totally being ignored.
How about infected blobs AND containers? Yes, many Chinese network routers/SANs now come this way. They even run forks of mainstream distros (like ImmortalWRT disguised as OpenWRT or some re-adulterated version of Ubuntu, neither of which anyone seems to be able to recreate with a matching binary signature, or even get to boot from the “open source” bits on Github). Some of these devices are then customized by American “brands” and resold to an unsuspecting Western public.
..and the commenters on here talking about wireless cards are spot on, it’s been known for 40 years —-not to mention that here in 2023, the wireless SoCs and network cards in general have reprogrammable firmware, in some cases, remotely reprogrammable firmware. Take a look at ESP32-C6…purpose built to give your devices a mind of their own. Nobody really knows what’s in the firmware. Some have assumptions based on “everyone is doing it” but that’s like eating hotdogs without thinking about how they are made —at least until one day you bite into one and find an eyeball.
What to do? Start eating kosher hotdogs for a start and then use computer hardware and software that has passed similar kinds of checks. Oh, that’s right, there is almost nobody performing such checks on computers like there are on the kosher dogs (though Apple is trying).
The fact is that we are already under attack like the ancient city of Troy (where a massive wooden horse was left outside the gates before being pulled inside as an accepted peace offering when out popped trojans wielding swords who let the rest of the army in). AT THIS HOUR the CCP military surrounds Taiwan using kinetic munitions during “exercises.” We have physical deterrents, they know it, and yet they keep preparing their military, probably because they can imagine “throwing the switch” and injecting (or triggering) viruses in firmware blobs, containers, “rock” chips, etc. throughout the West. As has repeatedly happened in certain US municipalities, someday our Western leaders could receive the “mother of all Chinese ransomware notes” and have to stand down and watch the world be conquered out of fear of another Great Depression triggered by Chinese computer viruses.
Hopefully this saved someone a ticket to RSA (and who wants to get stabbed to death on the streets around Moscone anyway https://www.sfgate.com/bayarea/article/911-audio-released-bo... ). Some good vendors are System 76 (pop_OS!), Apple, DELL and Cisco. Make your companies, industry regulators and local governments aware of these issues and maybe someday…