+1 (970) 414-2609
  • Active Campaign
  • Global News
  • Volunteer
Saturday, January 28, 2023
  • Home
  • About Us
  • Our Experts
  • Programs
  • Business Directory
No Result
View All Result
Boys & Girls Clubs of Senegal
No Result
View All Result
Home Africa News

300+ models of MSI motherboards have Secure Boot turned off. Is yours affected?

by dan goodin
January 22, 2023
in Africa News
Reading Time: 3 mins read
A A

secure those boots —

The shortcoming has left users susceptible to malicious bootloaders for 18 months.

Dan Goodin
– Jan 20, 2023 11:00 pm UTC

Secure Boot is an industry standard for ensuring that Windows devices don’t load malicious firmware or software during the startup process. If you have it turned on—as you should in most cases, and it’s the default setting mandated by Microsoft—good for you. If you’re using one of more than 300 motherboard models made by manufacturer MSI in the past 18 months, however, you may not be protected.

Introduced in 2011, Secure Boot establishes a chain of trust between the hardware and software or firmware that boots up a device. Prior to Secure Boot, devices used software known as the BIOS, which was installed on a small chip, to instruct them how to boot up and recognize and start hard drives, CPUs, memory, and other hardware. Once finished, this mechanism loaded the bootloader, which activates tasks and processes for loading Windows.

The problem was: The BIOS would load any bootloader that was located in the proper directory. That permissiveness allowed hackers who had brief access to a device to install rogue bootloaders that, in turn, would run malicious firmware or Windows images.

When Secure Boot falls apart
About a decade ago, the BIOS was replaced with the UEFI (Unified Extensible Firmware Interface), an OS in its own right that could prevent the loading of system drivers or bootloaders that weren’t digitally signed by their trusted manufacturers.

UEFI relies on databases of both trusted and revoked signatures that OEMs load into the non-volatile memory of motherboards at the time of manufacture. The signatures list the signers and cryptographic hashes of every authorized bootloader or UEFI-controlled application, a measure that establishes the chain of trust. This chain ensures the device boots securely using only code that’s known and trusted. If unknown code is scheduled to be loaded, Secure Boot shuts down the startup process.

A researcher and student recently discovered that more than 300 motherboard models from Taiwan-based MSI, by default, aren’t implementing Secure Boot and are allowing any bootloader to run. The models work with various hardware and firmware, including many from Intel and AMD (the full list is here). The shortcoming was introduced sometime in the third quarter of 2021. The researcher accidentally uncovered the problem when attempting to digitally sign various components of his system.

“On 2022-12-11, I decided to setup Secure Boot on my new desktop with a help of sbctl,” Dawid Potocki, a Poland-born researcher who now lives in New Zealand, wrote. “Unfortunately I have found that my firmware was… accepting every OS image I gave it, no matter if it was trusted or not. It wasn’t the first time that I have been self-signing Secure Boot, I wasn’t doing it wrong.”

Potocki said he found no indication motherboards from manufacturers ASRock, Asus, Biostar, EVGA, Gigabyte, and NZXT suffer the same shortcoming.

The researcher went on to report that the broken Secure Boot was the result of MSI inexplicably changing its default settings. Users who want to implement Secure Boot— which really should be everyone—must access the settings on their affected motherboard. To do that, hold down the Del button on the keyboard while the device is booting up. From there, select the menu that says SecuritySecure Boot or something to that effect and then select the Image Execution Policy submenu. If your motherboard is affected, Removable Media and Fixed Media will be set to “Always Execute.”

Getty Images

To fix, change “Always Execute” for these two categories to “Deny Execute.”

In a Reddit post published on Thursday, an MSI representative confirmed Potocki’s findings. The representative wrote:

ADVERTISEMENT

We preemptively set Secure Boot as Enabled and “Always Execute” as the default setting to offer a user-friendly environment that allows multiple end-users flexibility to build their PC systems with thousands (or more) of components that included their built-in option ROM, including OS images, resulting in higher compatibility configurations. For users who are highly concerned about security, they can still set “Image Execution Policy” as “Deny Execute” or other options manually to meet their security needs.

The post said that MSI will release new firmware versions that will change the default settings to “Deny Execute.” The above-linked subreddit contains a discussion that may help users troubleshoot any problems.

As mentioned, Secure Boot is designed to prevent attacks in which an untrusted person surreptitiously gets brief access to a device and tampers with its firmware and software. Such hacks are usually known as “Evil Maid attacks,” but a better description is “Stalker Ex-Boyfriend attacks.”

news image

Previous Post

Tom Brady Fined $16,444 for Trying to Trip Cowboys’ Malik Hooker in Bucs’ Loss

Next Post

This odd phishing scam targets victims with a blank image

Related Posts

What the alarming arrest of a former FBI spy catcher

by cointelegraph by derek andersen
January 26, 2023

The FBI arrested one of its former agents Saturday on the suspicion that, before and after he left the bureau,...

Read more

Germany Says Quiet Part Out Loud About Ukraine War

by christeen pepper
January 26, 2023

German Foreign Minister Annalena Baerbock isn't bashful about laying blame on Russia as its war in Ukraine surpasses 11 months....

Read more

Hammer blow for Vladimir Putin as Ukraine to get 200

by yuri kucera
January 26, 2023

Kyiv to become the ‘real punching fist of democracy’ after breakthrough donations from Germany and US that could turn tide...

Read more

Putin puts up ‘air defences close to his secret forest

by rida fatima
January 26, 2023

Russian president, Vladimir Putin has put up major air defences close to his secret forest palace to ‘protect him and...

Read more

Evidence required for ethical social science | Science

by chantal da silva and reuters
January 26, 2023

www.science.org Checking if the site connection is secure www.science.org needs to review the security of your connection before proceeding.

Read more

Gio Reyna is blocking out the noise for Dortmund

by jenna yow
January 26, 2023

It is no secret that United States Men’s Soccer is in turmoil. After being knocked out of the World Cup...

Read more
Next Post

This odd phishing scam targets victims with a blank image

ADVERTISEMENT

Trending Posts

Technology

What is computer coding?

by BGC Senegal
January 28, 2023

What is Computer Coding? Computer coding, also known as programming, is the process of writing instructions that enable a computer...

Read more

What is computer coding?

What is cyber security?

Who was Queen Ndaté Yalla Mbodj of Senegal?

How to become a Senegalese citizen?

How to become a US citizen?

How to surf the internet safely?

Load More

Popular Posts

How to deal with anger?

by BGC Senegal
January 26, 2023

  How to Deal With Anger   When anger takes over, it can be difficult to understand and manage. We...

How to learn new skills?

by BGC Senegal
January 26, 2023

How to Learn New Skills Being able to learn new skills is essential for a successful career, which is why...

How to become a Senegalese citizen?

by BGC Senegal
January 27, 2023

  How to Become a Senegalese Citizen? Senegal, located in West Africa, is well known for its vibrant culture and...

Facebook Twitter LinkedIn Youtube

NEWSLETTER

Subscribe to our newsletter and be the first to know about our upcoming events and programs.

QUICK LINKS

  • About Us
  • Learning Center
  • Active Campaign
  • Privacy Policy
  • Terms and Conditions
  • Contact us
  • Global News

CONTACT INFO

  • info@senegalbgc.org
  • For donations contact us at: donate@senegalbgc.org

© 2019-2023 Boys & Girls Clubs of Senegal. We are a 501 (C)(3) organization and donations are tax deductible. - EIN: 83-3699796

No Result
View All Result
  • 2020 HACKATHON
  • About Us
  • Active Campaign
  • AFRICA HACKATHON 2020 CODE OF CONDUCT
  • Blog
  • Checkout-Result
  • Contact Us
  • COVID-19
  • Global News
  • Home
  • Our Experts
  • Privacy Policy
  • Privacy Policy
  • Terms and Conditions
  • The African Community Center of Ohio
  • UKRAINE EVACUATION FOR AFRICAN CITIZENS
  • Volunteer

© 2019-2023 Boys & Girls Clubs of Senegal. We are a 501 (C)(3) organization and donations are tax deductible. - EIN: 83-3699796