Skip to main content

Secure Boot Key Flaw Exposes Windows Devices to Attack: Report


Secure Boot Key Flaw Exposes Windows Devices to Attack: Report

Highlights

  • Secure Boot policies are signed and validated by Microsoft
  • The leaked golden key can bypass operating system checks
  • Golden key allows attackers to boot any OS or self-signed binary
A leak has gone horribly wrong for Microsoft and the company is scrambling to fix the mess. Microsoft unwittingly leaked a 'golden key' that can unlock Windows-powered PCs, tablets, and phones protected by Secure Boot.
For the uninitiated, Secure Boot, a part of Unified Extensible Firmware Interface (UEFI), secures every component of a device's boot process by checking it is validated and signed by Microsoft. This protects the system from being booted by any other OS (malicious or non-malicious) an attacker or user wants to install. Secure Boot, once enabled, cannot be disabled by the user due to policies that are also validated by Microsoft and are loaded and obeyed once the Windows startup process is executed.
Microsoft, however, allowed an exception to the rule that has since become a nightmare for the company. The tech giant signed a special Secure Boot policy that disables the operating system checks, meant to allow developers to test new operating systems without having to sign each one. This policy essentially bypasses the standard checks.
Understandably, the special policy isn't available on commercial products. However, it has been leaked online - where it is now available for attackers to misuse. A curious person may find this 'golden key' - which essentially allows a backdoor into a Secure Boot-enabled Windows system - load it into a Windows firmware and trick Microsoft into believing the person is loading a valid and verified OS while actually installing a malicious one, even a self-signed binary. In simple terms, the golden key can unlock Secure Boot, and gives attackers unfettered access to install bootkits or rootkits alongside.


Security researchers my123 (@never_released) and slipstream (@TheWack0lian) were the ones to warn Microsoft that its Windows machines products were vulnerable due to the leak. After months of ignoring the issue, the researchers said Microsoft issued a bug bounty award and created two patches (one in July, and another in August). The Register claimed even the second patch does not actually resolve the vulnerability, only removing access to certain boot manager systems while leaving the policy flaw intact.
A third patch is expected to come out in September. However, the researchers believe the vulnerability cannot be completely fixed. Until the third patch comes out, the only thing users can do to protect their systems is to make sure their Microsoft patches are up-to-date on all Windows devices.
The leak of the golden key signals a bigger threat, one which puts into question the safety and security of devices and the need for such backdoor entries that can render your phones and computers vulnerable to hacks. To this effect, one of the researchers, Slipstream, issued a statement to the FBI:
"About the FBI: are you reading this? If you are, then this is a perfect real world example about why your idea of backdooring cryptosystems with a "secure golden key" is very bad! Smarter people than me have been telling this to you for so long, it seems you have your fingers in your ears. You seriously don't understand still? Microsoft implemented a 'secure golden key' system. And the golden keys got released from MS own stupidity. Now, what happens if you tell everyone to make a 'secure golden key' system?"

Comments

Popular posts from this blog

Airtel To Offer Free 3GB Mobile Data Per Month to Bring Customers to Its 4G Network

  03 January 2017 HIGHLIGHTS Offer is valid to both existing and new Airtel subscribers Both prepaid and postpaid users can avail the benefits Customers will get 3GB of free data over and above their pack Airtel on Tuesday unveiled an offer under which users can avail of free mobile data worth up to Rs. 9,000 for 12 months. The offer is meant to attract users to the  Airtel 4G  network, and is targeted at 4G handset users currently on other networks, as well as Airtel customers upgrading to a new 4G handset. India's biggest telecom operator, Airtel said that the free data offer will be available across India starting Wednesday, and will be valid till February 28. Under the free data offer, customers will get 3GB of free data every month till December 31, 2017, as long as they are using select Airtel 4G prepaid and postpaid plans. Airtel is providing the free mobile data over and above the subscribed plan's benefits. Free ...

Nokia 6.1 Gets a Price Cut in India Ahead of Next Week's Nokia 6.1 Plus Launch

  Dated: 18 August 2018   HMD Global is selling the Nokia 6.1 at a reduced price in India via its official site Highlights Nokia 6.1 seen to get up to a Rs. 1,500 price cut 3GB RAM variant is priced at Rs. 15,499 & the 4GB model costs Rs. 17,499 Nokia 6.1 Plus has been spotted online ahead of its launch Nokia 6.1 Plus is expected to be unveiled in India on August 21 and ahead of the launch, Nokia licensee HMD Global has dropped the price in India of the Nokia 6.1 or Nokia 6 (2018). Launched in India in April, the Nokia 6.1 was globally unveiled at MWC 2018 in February, but had first been launched in China in January. Later in May, HMD Global had launched another variant of the smartphone. Now, both the variants have received up to a Rs. 1,500 price cut in India. Meanwhile, Nokia 6.1 Plus, the global variant of Nokia X6 that was launched in China in May, has now surfaced online with that name. ...

Hello Moto: A Look Back at Six Classic Moto Phones

  12 December 2016 HIGHLIGHTS Motorola was the first company to ship a cellphone Its biggest hit was the Moto RAZR V3 Today, Motorola is a part of Chinese electronics giant Lenovo Recently, we relived the past with Nokia’s most memorable phones of all time. Although there may be a lot of fanboys and fangirls of the Finnish brand, many have equally strong feelings for the daddy of all mobile phone brands - Motorola. Its name will forever be etched in history as the  first company  to sell a mobile phone - the DyanTAC 8000X - in 1983. Since then, Motorola has been an easily identifiable brand to almost everybody in the world. Its designs were often strikingly unique and at the same time, Motorola phones often gave out a vibe that these devices mean business. Today, we’ve handpicked some of the most memorable Motorola phones we’ve come across. Here are our picks for the six most memorable Motorola phones of all time. 1) Motorola ...