news.volyx.in

Intel OEM Private Key Leak: A Blow to UEFI Secure Boot Security (securityonline.info)

658 points by transpute · 1211 days ago · 373 comments on HN

Article summary

A cyberattack on MSI resulted in the leak of Intel's OEM private key, which could compromise UEFI secure boot security on Intel's 11th, 12th, and 13th generation processors. The leaked key was part of a 1.5TB data breach, predominantly comprising source code. This leak could allow attackers to modify firmware boot policies and bypass hardware security measures. The full extent of the damage is currently unknown.

Main themes

  • Intel OEM private key leak
  • UEFI secure boot security
  • Cyberattack and data breach
  • Open source projects and litigation
  • Secure boot and malware protection
  • Hardware security and firmware modification
  • Security through secrecy and its limitations
  • General purpose computing hardware and custom software

What commenters say

  • The leak of the Intel OEM private key is a significant security risk that could allow attackers to bypass secure boot measures.
  • Secure boot is a valuable feature that protects against malware and should not be disabled.
  • The leaked key could be used by open source projects to disable secure boot, but this may open them up to litigation.
  • The key is not copyrightable and can be shared freely in some jurisdictions.
  • Secure boot does not protect against all types of attacks, such as modifying the bootloader.
  • The leak of the key could allow owners of hardware to read and modify the firmware, including checking for backdoors.
  • Relying on secrecy for security is not effective and accidents or leaks are inevitable.
  • There is no legitimate reason to run custom software on general purpose computing hardware, and secure boot is in place for the user's protection.