web analytics

Micro-Star International Signing Key Stolen – Source: www.schneier.com

micro-star-international-signing-key-stolen-–-source:-wwwschneier.com
#image_title
Rate this post

Source: www.schneier.com – Author: Bruce Schneier

Micro-Star International—aka MSI—had its UEFI signing key stolen last month.

This raises the possibility that the leaked key could push out updates that would infect a computer’s most nether regions without triggering a warning. To make matters worse, Matrosov said, MSI doesn’t have an automated patching process the way Dell, HP, and many larger hardware makers do. Consequently, MSI doesn’t provide the same kind of key revocation capabilities.

Delivering a signed payload isn’t as easy as all that. “Gaining the kind of control required to compromise a software build system is generally a non-trivial event that requires a great deal of skill and possibly some luck.” But it just got a whole lot easier.

Tags: , ,

Posted on May 15, 2023 at 7:18 AM
13 Comments

Sidebar photo of Bruce Schneier by Joe MacInnis.

Original Post URL: https://www.schneier.com/blog/archives/2023/05/micro-star-international-signing-key-stolen.html

Category & Tags: Uncategorized,ransomware,signatures,supply chain – Uncategorized,ransomware,signatures,supply chain

LinkedIn
Twitter
Facebook
WhatsApp
Email

advisor pick´S post