top | item 35835697

MSI firmware signing keys leaked

137 points| seizethegdgap | 2 years ago |github.com

34 comments

order
[+] rkagerer|2 years ago|reply
Is it wrong that my immediate reaction to this is, "Sweet, so I can finally do things with my board I was prevented from before!"
[+] xbar|2 years ago|reply
Not at all, in this case.

There is a giant pile of hardware in the world that relies on unsigned hardware. Meanwhile, MSI uses its hardware signing to hurt its customers.

Will some MSI users get tricked into using malicious firmware? Doubtless, eventually. That's sad. But not nearly as sad as the millions of users who can't use their own computers in a manner of their choosing.

Celebrate, without remorse.

[+] lakomen|2 years ago|reply
It was mine as well.

They artificially limited both discrete and on board GPU being active at the same time in my GT72's BIOS.

[+] hexagonwin|2 years ago|reply
Does this mean that we can now custom firmwares (e.g. coreboot) on those MSI boards?
[+] stavros|2 years ago|reply
It's really fucked up that we can't disable secure boot on boards we've bought, and we have to hope their security is compromised instead. What would be the issue with requiring a very manual process to add my own CA to the board so I can load up whatever I want?

Ah, vendor lockin, got it.

[+] mailey|2 years ago|reply
I'm interested as well in finding out about being able to flash custom firmware. Is there any other resources to follow?
[+] ewokone|2 years ago|reply
I would love to learn more about that.

How would someone use those keys? What's beneficial, what could be useful possible cases for me? And Are my workstations in my company at risk?

[+] leohonexus|2 years ago|reply
If I recall correctly, at boot time CPUs retrieve the firmware along with a cryptographic signature that verifies the firmware came from the signer. Some boards choose to burn this signature into the hardware using e-fuses. If the signing key is leaked, that means someone can flash custom firmware into the chip and the CPU would be none the wiser, all while operating at Ring 0.
[+] josteink|2 years ago|reply
Unfortunately this leak seems to be for Intel-based boards only, not the AMD ones :(
[+] rasz|2 years ago|reply
Intel BootGuard Keys? that sounds intriguing