Hacker News new | ask | show | jobs
by throwaway7737 4354 days ago
I'm very concerned about the mass surveillance revealed by Snowden, but based on those links I can't really see that any cooperation was needed.

The last link makes it quite clear that this is about the NSA reflashing machine BIOS with a compromised version ("Through remote access or interdiction"). If the NSA decides to reroute your shipment of a new computer to their facility to mess with it, no amount of BIOS security is going to stop that. The same applies if they already have remote access (I'm guessing in that case it's about implanting a persistent backdoor in case the targeted user wipes his machine).

I would expect that they have ready-to-go compromised BIOS replacements with persistent backdoors for most popular machines.

The tomsitpro article suggests that this has been "solved" by UEFI signed BIOS firmware, which is just ridiculous. Does anyone really believe that the NSA does not have access to means to get stuff signed by CAs? Just looking at what they're trying to do they would be seriously incompetent if they did not (the CA system is a joke!). And even if they were so incompetent, what's to stop them from using a hardware flasher to flash the BIOS chip directly if they already have physical access to the machine through interdiction?