What's the best way to counteract this? Only plug foreign drives into a dedicated computer, probably running Linux, so you can scan it and copy the files you need before letting them touch other machines?
What's the best way to counteract this? Only plug foreign drives into a dedicated computer, probably running Linux, so you can scan it and copy the files you need before letting them touch other machines?
What's demonstrated in this article is extremely inelegant and clumsy. Truly malicious rootkits and the like are a bit more sophisticated.
The Pi doesn't have a BIOS or EFI on board, it uses a special partition on the SD card to POST from, so there's no worry of the device itself being infected.
The real mode opcodes needed to bring up a kernel are a mess on Arm, with each manufacture using their own instruction set.
What is different is the boot sequence and system register layout. On a PC you can write one bootloader that works across multiple systems because either the peripherals are at the same place or BIOS/UEFI code is provided to sort it out for you. This is not the case on ARM; uboot and devicetree are attempts to fix it.
It might be possible for a malicious script that gains root access to replace the SD card firmware with something that looks clean on the Pi, but delivers malware when some conditions are met.
The SD card is not part of the RPi; there's nothing on the board itself that is writable.
If you're really paranoid, do everything with a separate machine.