Installing LibreBoot the (Very) Lazy Way

Recently I was given a somewhat crusty looking ThinkPad T400 that seemed like it would make a good knock around machine to have on the bench, if it wasn’t for the fact the person who gave it to me had forgotten (or perhaps never knew) the BIOS password. Cleaning the machine up, putting more RAM in it, and swapping the wheezing hard drive for an SSD would be a relatively cheap way to wring a few more years of life from the machine, but not if I couldn’t change the boot order in BIOS.

Alright, that’s not entirely true. I …read more

Continue reading Installing LibreBoot the (Very) Lazy Way

What are the options to reduce the potential attack surface introduced by complex and closed-source firmware? [on hold]

Complex closed-source firmware has the potential to be a security nightmare.

Let’s take for example the possible security and privacy implications of:

Intel ME firmware in Intel processors (and AMD equivalent: PSP)
the fir… Continue reading What are the options to reduce the potential attack surface introduced by complex and closed-source firmware? [on hold]

Watch a Hacker Install a Firmware Backdoor on a Laptop in Less Than 5 Minutes

This demo shows that “evil maid attacks,” hacks where an attacker has physical access to a target computer, are not as complicated as you may think. Continue reading Watch a Hacker Install a Firmware Backdoor on a Laptop in Less Than 5 Minutes