Free Republic
Browse · Search
General/Chat
Topics · Post Article

Skip to comments.

Lenovo scrambling to get a fix for BIOS vuln
The Register ^ | 4 Jul 2016 at 02:04 | Richard Chirgwin

Posted on 07/04/2016 7:04:05 PM PDT by Utilizer

Lenovo, and possibly other PC vendors, is exposed to a UEFI bug that can be exploited to disable firmware write-protection.

If the claims made by Dmytro Oleksiuk at Github are correct, an attacker can “disable flash write protection and infect platform firmware, disable Secure Boot, [and] bypass Virtual Secure Mode (Credential Guard, etc.) on Windows 10 Enterprise.”

The reason Oleksiuk believes other vendors are also vulnerable is that the buggy code is inherited from Intel. He writes that the SystemSmmRuntimeRt was copied from Intel reference code.

(Excerpt) Read more at theregister.co.uk ...


TOPICS: Business/Economy; Computers/Internet
KEYWORDS: hardware; lenovo; malware; security; windows; windows10; zeroday
This is looking more and more of a major concern as time goes by...
1 posted on 07/04/2016 7:04:05 PM PDT by Utilizer
[ Post Reply | Private Reply | View Replies]

To: Utilizer

buggy code is EVERYWHERE


2 posted on 07/04/2016 7:06:18 PM PDT by butlerweave
[ Post Reply | Private Reply | To 1 | View Replies]

To: butlerweave

Thank you, Savouir Faire, for that illuminative observation, and be sure to give Mal Le Muutte an extra pat on the head when next you see him. :~{p


3 posted on 07/04/2016 7:16:51 PM PDT by Utilizer (Bacon A'kbar! - In world today are only peaceful people, and the muzrims trying to kill them)
[ Post Reply | Private Reply | To 2 | View Replies]

To: Utilizer; butlerweave

Oh, thanks, you two, ya made me laugh and now my face hurts...


4 posted on 07/04/2016 7:33:51 PM PDT by W. (Screw it. Send in the Marines! NOW!)
[ Post Reply | Private Reply | To 3 | View Replies]

To: Utilizer
Is it possible to even buy a modern motherboard that doesn't have UEFI?

I don't think so.

5 posted on 07/04/2016 7:37:42 PM PDT by usconservative (When The Ballot Box No Longer Counts, The Ammunition Box Does. (What's In Your Ammo Box?))
[ Post Reply | Private Reply | To 1 | View Replies]

To: W.

Yeh, well, not smiling for years at a time can kind of atrophy the necessary muscles if you don’t take pains to work them once in awhile. :)

So beware the dread Hawaiian disease Lak-anukki!!!

Because even a Little Brain is a terrible thing to wast!

(Yes, I deliberately misspelled it. /s)


6 posted on 07/04/2016 7:52:52 PM PDT by Utilizer (Bacon A'kbar! - In world today are only peaceful people, and the muzrims trying to kill them)
[ Post Reply | Private Reply | To 4 | View Replies]

To: usconservative
Is it possible to even buy a modern motherboard that doesn't have UEFI?

Certainly!

Why do you think apple computers and atari 2600s are so popular?

(ducks!)

7 posted on 07/04/2016 7:54:18 PM PDT by Utilizer (Bacon A'kbar! - In world today are only peaceful people, and the muzrims trying to kill them)
[ Post Reply | Private Reply | To 5 | View Replies]

To: Utilizer
No worries about my grins, they're constant.

Laughter IS the best medicine, as has been copywrighted....

8 posted on 07/04/2016 8:05:30 PM PDT by W. (Screw it. Send in the Marines! NOW!)
[ Post Reply | Private Reply | To 6 | View Replies]

To: Utilizer

Oh, right: I misspelled the disease (according to some experts).

It’s spelled “lakanukki”, with the “u” pronounced as in “you”.

Sorry for the confusion. ;)


9 posted on 07/04/2016 8:16:40 PM PDT by Utilizer (Bacon A'kbar! - In world today are only peaceful people, and the muzrims trying to kill them)
[ Post Reply | Private Reply | To 6 | View Replies]

To: Utilizer
Why do you think apple computers and atari 2600s are so popular?

SNORT! Hey, my Apple makes a fine doorstop, it's still useful!

10 posted on 07/04/2016 8:21:37 PM PDT by usconservative (When The Ballot Box No Longer Counts, The Ammunition Box Does. (What's In Your Ammo Box?))
[ Post Reply | Private Reply | To 7 | View Replies]

To: dayglored

Ping.


11 posted on 07/04/2016 9:15:55 PM PDT by upchuck (I'm hanging here until my Free Republic 401K is fully vested.)
[ Post Reply | Private Reply | To 1 | View Replies]

To: upchuck

Really? You pinged dayglored to this thread? I thought he was all about the ‘doze platform, and not involved with the chipset side of things.

Isn’t there another FReeper who is managing something I believe is called the Hardware Ping List? Or did dayglored take over that one as well?

Just wondering... :)


12 posted on 07/04/2016 10:15:52 PM PDT by Utilizer (Bacon A'kbar! - In world today are only peaceful people, and the muzrims trying to kill them)
[ Post Reply | Private Reply | To 11 | View Replies]

To: Utilizer; dayglored; Swordmaker

AFAIK, Dayglored manages the windows-centric ping list and Swordmaker manages the Apple-centric list.

If there’s another FReeper whose list would be more appropriate for this thread, please let me know.


13 posted on 07/05/2016 5:46:46 AM PDT by upchuck (I'm hanging here until my Free Republic 401K is fully vested.)
[ Post Reply | Private Reply | To 12 | View Replies]

To: upchuck; Utilizer; Swordmaker; ThunderSleeps; ShadowAce
>> Really? You pinged dayglored to this thread? I thought he was all about the ‘doze platform, and not involved with the chipset side of things. Isn’t there another FReeper who is managing something I believe is called the Hardware Ping List? Or did dayglored take over that one as well? Just wondering... :)

> AFAIK, Dayglored manages the windows-centric ping list and Swordmaker manages the Apple-centric list. If there’s another FReeper whose list would be more appropriate for this thread, please let me know.

Okay, here's how I believe it's laid out:

There are no hard-and-fast boundaries or "territories", just areas of primary interest as above. These lists (and we FReepers who run them) cooperate in the sense that we all alert each other to threads that might be of interest to our respective list members.

For example, this thread would be appropriate for my Windows/Microsoft list because Lenovo machines are primary Windows-based, so this BIOS vulnerability affects people who run Windows on Lenovos. It would be appropriate for ShadowAce's Tech list because it's about BIOS software, and because Lenovos are often used to run Linux. It would likely be of lower interest to Swordmaker's list because Lenovo hardware rarely runs Apple software; same likely in the case of ThunderSleeps and the Android list.

So upchuck's ping to me was appropriate, and a ping to ShadowAce would also be appropriate. A ping to Swordmaker and/or ThunderSleeps is not "out of line" but they would (I think) be unlikely to turn that into a ping to their respective lists.

Note, chipset stuff is of interest to the lists whose members might have hardware that includes that chipset, even if it isn't a personal computer (e.g. a set-top box or other embedded processor system).

Also note:

ShadowAce suffered a very serious cycle accident a short time ago and is only posting occasionally (and in lowercase!). Please send up some prayers for his recovery, and for strength and peace of mind for both him and his wife.

14 posted on 07/06/2016 6:19:21 AM PDT by dayglored ("Listen. Strange women lying in ponds distributing swords is no basis for a system of government.")
[ Post Reply | Private Reply | To 13 | View Replies]

To: dayglored

Hey, stranger, good to know you were about and thanks for the pinglist references. Good to know.

A minor point, AFAIK ShadowAce was involved in a Biking accident (motorcycle), I believe a collision with an object of considerable weight at about 50mph, but he survived so good on him for that. Difficult for his wife as well, of course, but to paraphrase an old saying: “Any landing you can walk away from is a good landing”.

Same when a biker takes a tumble.

Also, no offence to any cycling enthusiasts out there, this is not meant to belittle your hobby at all. Just correcting the record.


15 posted on 07/06/2016 7:32:08 AM PDT by Utilizer (Bacon A'kbar! - In world today are only peaceful people, and the muzrims trying to kill them)
[ Post Reply | Private Reply | To 14 | View Replies]

To: Utilizer
> ...AFAIK ShadowAce was involved in a Biking accident (motorcycle),...

Correct, I should have specified "motorcycle". In the decades I rode, I referred to my vehicle variously as "motorcycle", "cycle", and "bike", so I guess I'm a bit sloppy in that regard.

I had a 1981 3-cylinder (850cc) Yamaha 850xs Midnight Special:

I had a serious highway accident in which I shattered my right wrist and only the Grace of God saved me from being flattened, as I flipped over the handlebars and landed prone in the on-coming lane. The bike's considerable weight and high CG were fine when I was younger, but increasing peripheral neuropathy in my feet made it increasingly difficult to manage. I gave the bike away to a friend a couple years ago.

16 posted on 07/06/2016 8:23:51 AM PDT by dayglored ("Listen. Strange women lying in ponds distributing swords is no basis for a system of government.")
[ Post Reply | Private Reply | To 15 | View Replies]

To: dayglored

Mine looked quite a bit like this one. 1972 Harley-Davidson Sportster -with many custom features. :)

17 posted on 07/06/2016 10:10:15 AM PDT by Utilizer (Bacon A'kbar! - In world today are only peaceful people, and the muzrims trying to kill them)
[ Post Reply | Private Reply | To 16 | View Replies]

To: dayglored

Thank you.


18 posted on 07/06/2016 11:58:15 AM PDT by upchuck (I'm hanging here until my Free Republic 401K is fully vested.)
[ Post Reply | Private Reply | To 14 | View Replies]

To: ShadowAce

Here’s to a rapid and complete recovery!


19 posted on 07/06/2016 1:11:03 PM PDT by Darnright (When a system acts illegally, its dictates are not the law of the land, they are the law of force)
[ Post Reply | Private Reply | To 14 | View Replies]

To: dayglored; upchuck; Utilizer
So upchuck's ping to me was appropriate, and a ping to ShadowAce would also be appropriate. A ping to Swordmaker and/or ThunderSleeps is not "out of line" but they would (I think) be unlikely to turn that into a ping to their respective lists.

Yes, I saw this thread, but for the reasons Dayglored outlined, I did not ping the Apple list.

20 posted on 07/06/2016 4:55:08 PM PDT by Swordmaker (This tag line is a Microsoft insult free zone... but if the insults to Mac users continue..)
[ Post Reply | Private Reply | To 14 | View Replies]

Disclaimer: Opinions posted on Free Republic are those of the individual posters and do not necessarily represent the opinion of Free Republic or its management. All materials posted herein are protected by copyright law and the exemption for fair use of copyrighted works.

Free Republic
Browse · Search
General/Chat
Topics · Post Article

FreeRepublic, LLC, PO BOX 9771, FRESNO, CA 93794
FreeRepublic.com is powered by software copyright 2000-2008 John Robinson