Hacker News new | ask | show | jobs
by tuetuopay 926 days ago
What make this vulnerability frightening is

- the persistence that’s nearly perfect

- an av cannot detect it ever

- it bypasses all forms of secure boot by getting code exec at the earliest of stages in the boot chain of trust

- the disassemblies show that the bios vendors did not even remotely try to make the parser secure. it is a joke. and if an image parser is that bad, I can’t even imagine the quality of usb or network stacks