Microsoft Leaks Secure Boot Key, Raises Security Concerns

...

In this webinar, we'll give you the latest on how to handle security concerns in your Office 365 d

Microsoft has accidentally leaked a key that can enable users to unlock Secure Boot-protected smartphones and tablets running Windows 8.1 or later.

Microsoft is causing major cyber-security concerns with the accidental leak of a "golden key" intended to protect devices equipped with Secure Boot.

The Secure Boot feature is intended to protect Windows devices by making sure they only use software trusted by the PC maker or user. It's part of Microsoft's Unified Extensible Firmware Interface (UEFI) and ensures each component loaded during the boot process is validated.

The all-access keys were discovered by MY123 and Slipstream in March 2016. A recent blog post (animated site with tinny, arcade-style music) by researchers at MY123 and Slipstream dives into the details of Microsoft's security problems and the errors it made in addressing them.

[Google: QuadRooter threat is blocked on most Android devices.]

Note that the golden key isn't an actual key, but a means of changing the tasks launched by UEFI during the boot process, as explained in a report by Ars Technica. The policy has been made available online. It will enable anyone to disable the Secure Boot feature.

Secure Boot can be disabled on several types of desktop PCs, but is hard-coded into most devices running Windows. It seems the golden key is intended to turn off OS checks so programmers can test new projects. However, it can also leave Windows devices vulnerable.

The keys leaked by Microsoft will allow users with admin rights to install any operating system -- like Linux or Android -- on their Windows PCs, smartphones, or tablets.

This leak has dangerous implications for a machine if an attacker has physical access to it. If this is the case, a hacker could install and deploy bootkits and rootkits at deep levels, as described in the blog post.

The worst part? There's a chance Microsoft will not be able to reverse the problem.

Redmond has attempted to fix the problem through security patches, but MY123 and Slipstream believe there is no chance Microsoft will be able to make the golden keys entirely unusable for those who want to commit harm.

MY123 and Slipstream used this situation as an opportunity to warn the Federal Bureau of Investigation about the dangers of implementing a backdoor into smartphones, tablets, and PCs.

The idea of creating a device backdoor was a hot topic earlier this year, following the December 2015 shooting in San Bernardino, Calif. FBI officials ordered Apple to create code to unlock an iPhone so they could access data on a device owned by one of the shooters. Apple firmly refused to create what it called a "backdoor" to the device.

In their blog post, the MY123 and Slipstream researchers noted that Microsoft put a backdoor into Secure Boot and in doing so, allowed Secure Boot to be disabled in all Windows devices.

"About the FBI: are you reading this? If you are, then this is a perfect real world example about why your idea of backdooring cryptosystems with a 'secure golden key' is very bad!" the researchers emphasized.

"Microsoft implemented a 'secure golden key' system" with Secure Boot, they continued. "And the golden keys got released from MS own stupidity. Now, what happens if you tell everyone to make a 'secure golden key' system?"

Categories
APPLICATIONS
0 Comment

Leave a Reply

Captcha image


RELATED BY

  • 5300c769af79e

    Microsoft Windows Defender 4.9

    If you're using Windows 8 or Windows 10, you've got Microsoft Windows Defender already, right?Compare Similar ProductsCompare Avast Free Antivirus 2016 %displayPrice% AVG AntiVirus Free (2016) %displayPrice% Panda Free Antivirus (2016) %displayPrice% Bitdefender Antivirus Free Edition (2014) %displayPrice% Check Point ZoneAlarm Free Antivirus + Firewall 2016 %displayPrice% Lavasoft Ad-Aware Free Antivirus+ 11 %displayPrice% Sophos Home %displayPrice% Avira Antivirus 2016 %displayPrice% Qihoo 360 Total Security Essential %displayPrice% Comodo Antivirus 8 %displayPrice% FortiClient 5.
  • 5300c769af79e

    Nexus 6's Android 7.1.1 March Patch is Back After Brief Pull

    On Monday, Google pushed out March’s security patch to its Nexus and Pixel devices.Most of the updates pushed through without issue, except for the Nexus 6’s Android 7.
  • 5300c769af79e

    How An Agricultural Data Firm Puts The Cloud To Work

    The agricultural industry abounds with data, which can be gathered through employees, sensors, and other sources, both public and private.Analyzing that data and turning it into useful information requires data science, IT talent, and IT infrastructure.
  • 5300c769af79e

    Sony Brings Unlocked Xperia XZ, X Compact to the US

    Sony is bringing an unlocked version of its flagship Xperia XZ smartphone to the US.An unlocked Xperia X Compact will also be available to US consumers starting this Sunday for $500.