Hacker News new | ask | show | jobs
by PrimaryAlibi 550 days ago
How would it be done externally? Is it done same way as flashing the boot rom? You just need to know where the chip is for the other components? No 0-days needed? Or do you need a 0-day to do this? Is that why you think only foreign intelligence agencies are the ones who can do this? Also assume that the bios is password protected and it's configured in bios to not boot from a USB drive.
1 comments

> How would it be done externally? Is it done same way as flashing the boot rom?

Depends on the device.

> Is that why you think only foreign intelligence agencies are the ones who can do this?

Because it's enough work that nobody else would bother.

> Also assume that the bios is password protected and it's configured in bios to not boot from a USB drive.

BIOS password is an administrative control. It doesn't stop anyone with the ability to flash firmware from doing anything.

These are the type of vague answers i said i didn't want because they are not helpful. How do i know if you really know what you are talking about? No explanations or links to sources. "depends on the device" is almost not an answer at all.

BIOS password does help if they need to be able to boot from usb drive to flash firmware. Or do you know another way? Again, not talking about boot rom.

> "depends on the device" is almost not an answer at all.

If you ask extremely general questions, you're going to get extremely general answers. This is a discussion board, not a personal research service. You need to go and figure this out for the specific hardware you are concerned about.

> BIOS password does help if they need to be able to boot from usb drive to flash firmware.

That's the only circumstance in which it helps, but that's rarely necessary on modern machines.

https://en.m.wikipedia.org/wiki/Fwupd

But my questions aren't extremely general, i even asked very specifically if you are supposed to attach an external programmer to the component like keyboard or cam etc but you can't even answer that. You can't even give one example. Are you saying there is nothing at all in common with different device models like camera model b and camera model c? You don't physically manipulate with them in any way? Don't attach anything or what? Or do you shine a light on one model and breath on another? When you can't even make one example that makes it hard to believe you. You are just constantly deflecting and refusing to explain. It just seems like you are spreading FUD when you say it can be done but wont explain how. I'm not even asking for full step by step instruction, just a simple overview of what kind of process it is in general.
> keyboard or cam etc but you can't even answer that

They are not all built the same. It depends on the SPECIFIC device.