this post was submitted on 27 Nov 2024
206 points (96.8% liked)

Technology

59675 readers
3293 users here now

This is a most excellent place for technology news and articles.


Our Rules


  1. Follow the lemmy.world rules.
  2. Only tech related content.
  3. Be excellent to each another!
  4. Mod approved content bots can post up to 10 articles per day.
  5. Threads asking for personal tech support may be deleted.
  6. Politics threads may be removed.
  7. No memes allowed as posts, OK to post as comments.
  8. Only approved bots from the list below, to ask if your bot can be added please contact us.
  9. Check for duplicates before posting, duplicates may be removed

Approved Bots


founded 1 year ago
MODERATORS
 

“Whether a proof of concept or not, Bootkitty marks an interesting move forward in the UEFI threat landscape, breaking the belief about modern UEFI bootkits being Windows-exclusive threats,” ESET researchers wrote. “Even though the current version from VirusTotal does not, at the moment, represent a real threat to the majority of Linux systems, it emphasizes the necessity of being prepared for potential future threats.”

you are viewing a single comment's thread
view the rest of the comments
[–] nyan@lemmy.cafe 17 points 10 hours ago

Attacks only machines running specific Ubuntu kernels and using specific boot methods. Plus no actual payload. This doesn't yet represent a real risk.

Where we'll be in ten years' time is unknowable, however. I think the Ars commentors who suggested going back to forcing jumper cap swaps or other hardware-mediated access requirements before overwriting the mobo's boot firmware might be on the right track, even if it's inconvenient for large corporate deployments. It's normal for security and convenience to pull in opposite directions, and sometimes you just have to grin and bear it.