Jump to content

MSI Leak of Intel BootGuard & OEM Image Signing Keys

nonme

I apologize if this has already been posted, but I have not been able to find it so far.

 

Summary

MSI has leaked their BootGuard and OEM Image Signing keys. With possession of the signing key, an attacker could potentially distribute malicious updates that seem legitimate. Though none have been reported yet, the possession of MSI's signing key could result in attacks on the supply chain.

 

The hackers also acquired a private encryption key used in an MSI version of Intel Boot Guard, which is designed to prevent the loading of malicious firmware. Possession of both keys could allow an attacker to self-sign malicious firmware and gain far-reaching access to systems, bypassing security measures.

 

Quotes
From Wccftech:

Quote

 

The leaked files contain signing keys for a total of over 200 MSI products which can be used to access the firmware of these devices. These include a total of 57 devices whose Firmware Image Signing Keys have leaked out and 116 devices whose Intel BootGuard Keys have leaked.

These keys can be used to tag malicious software with malware as trusted and handed over to the system which ends up compromising its security.

 

From Ars Technica:
 

Quote

The intrusion came to light in April when, as first reported by Bleeping Computer, the extortion portal of the Money Message ransomware group listed MSI as a new victim and published screenshots purporting to show folders containing private encryption keys, source code, and other data. A day later, MSI issued a terse advisory saying that it had “suffered a cyberattack on part of its information systems.” The advisory urged customers to get updates from the MSI website only. It made no mention of leaked keys.

 

 

Sources

Wccftech https://wccftech.com/msi-breach-leaks-intel-bootguard-oem-image-signing-keys-compromises-security-of-over-200-devices-major-vendors/

Ars Technica https://arstechnica.com/information-technology/2023/05/leak-of-msi-uefi-signing-keys-stokes-concerns-of-doomsday-supply-chain-attack/

Sophos (Security Company) https://nakedsecurity.sophos.com/2023/05/09/low-level-motherboard-security-keys-leaked-in-msi-breach-claim-researchers/

Intel Core i9-9900K, ASUS PRIME Z270-A, 64 GB G.SKILL Trident Z, NVIDIA GeForce RTX 2080 (MSI GAMING X TRIO) all in a white InWin 303 case

 

Read the following if you want, but I warn you, it may be complete nonsense.

Link to comment
Share on other sites

Link to post
Share on other sites

3 hours ago, jagdtigger said:

This reminds me, @LinusTech whats up with that plastic dragon? 😄

  Reveal hidden contents

For those who dont know what i am talking about:

 

 

I vote for lighting it on 🔥

Link to comment
Share on other sites

Link to post
Share on other sites

I was hoping to hear something about this on WAN Show. We're in After Dark, now, and I haven't heard anything yet....

Link to comment
Share on other sites

Link to post
Share on other sites

Has anyone noticed MSI seems to get hacked/compromised in some way like all the time? I feel like I hear *something* about them every year

"If a Lobster is a fish because it moves by jumping, then a kangaroo is a bird" - Admiral Paulo de Castro Moreira da Silva

"There is nothing more difficult than fixing something that isn't all the way broken yet." - Author Unknown

Spoiler

Intel Core i7-3960X @ 4.6 GHz - Asus P9X79WS/IPMI - 12GB DDR3-1600 quad-channel - EVGA GTX 1080ti SC - Fractal Design Define R5 - 500GB Crucial MX200 - NH-D15 - Logitech G710+ - Mionix Naos 7000 - Sennheiser PC350 w/Topping VX-1

Link to comment
Share on other sites

Link to post
Share on other sites

Well but how it affect if you downlaod from legit MSI website ? Mostly is people fault that they downlaod random trash from random website.
I think this leak not affect at all if you always download app only from legit website.

Rule number 1 always double check on what you click before open website. That some result appears on top  for example in Google search is not all time mean that they are legit website. Over all don't download any pirate software, game, movies, music, etc and you will reduce risk to very minimal.

Link to comment
Share on other sites

Link to post
Share on other sites

Does this make ASRock the least problematic?

Specs: Motherboard: Asus X470-PLUS TUF gaming (Yes I know it's poor but I wasn't informed) RAM: Corsair VENGEANCE® LPX DDR4 3200Mhz CL16-18-18-36 2x8GB

            CPU: Ryzen 9 5900X          Case: Antec P8     PSU: Corsair RM850x                        Cooler: Antec K240 with two Noctura Industrial PPC 3000 PWM

            Drives: Samsung 970 EVO plus 250GB, Micron 1100 2TB, Seagate ST4000DM000/1F2168 GPU: EVGA RTX 2080 ti Black edition

Link to comment
Share on other sites

Link to post
Share on other sites

1 hour ago, williamcll said:

Does this make ASRock the least problematic?

Least relevant*

"Put as much effort into your question as you'd expect someone to give in an answer"- @Princess Luna

Make sure to Quote posts or tag the person with @[username] so they know you responded to them!

 RGB Build Post 2019 --- Rainbow 🦆 2020 --- Velka 5 V2.0 Build 2021

Purple Build Post ---  Blue Build Post --- Blue Build Post 2018 --- Project ITNOS

CPU i7-4790k    Motherboard Gigabyte Z97N-WIFI    RAM G.Skill Sniper DDR3 1866mhz    GPU EVGA GTX1080Ti FTW3    Case Corsair 380T   

Storage Samsung EVO 250GB, Samsung EVO 1TB, WD Black 3TB, WD Black 5TB    PSU Corsair CX750M    Cooling Cryorig H7 with NF-A12x25

Link to comment
Share on other sites

Link to post
Share on other sites

On 5/12/2023 at 11:09 PM, tzenrick said:

I was hoping to hear something about this on WAN Show. We're in After Dark, now, and I haven't heard anything yet....

Honestly the wan show isn't what it used to be. Half of the important tech news goes unreported on that show

Link to comment
Share on other sites

Link to post
Share on other sites

2 hours ago, TVwazhere said:

Least relevant*

Hey, some of the best memory overclocking I have ever done has been on an ASRock board. I'll take their OC Formula's over any Apex board any day and I'll die on that hill, lol.

 

Sure, their LLC might not be functional when not using auto, and sometimes their context menus break and change to Korean in between overclocking sessions, but 50% of the time, their hardware works every time.

My (incomplete) memory overclocking guide: 

 

Does memory speed impact gaming performance? Click here to find out!

On 1/2/2017 at 9:32 PM, MageTank said:

Sometimes, we all need a little inspiration.

 

 

 

Link to comment
Share on other sites

Link to post
Share on other sites

On 5/15/2023 at 6:20 AM, williamcll said:

Does this make ASRock the least problematic?

*least everything

you dont need an aio for anything but i9 cpus or heavy oc jobs just get an nh-d15 or peerless assassin

MARK THE SOLUTION AS SOLUTION

 

 

i am 14 so i may be wrong sometimes

 

@Bob__ is a w

 

 

 

 

 

 

Link to comment
Share on other sites

Link to post
Share on other sites

On 5/15/2023 at 11:10 AM, MageTank said:

Korean

mandarin

you dont need an aio for anything but i9 cpus or heavy oc jobs just get an nh-d15 or peerless assassin

MARK THE SOLUTION AS SOLUTION

 

 

i am 14 so i may be wrong sometimes

 

@Bob__ is a w

 

 

 

 

 

 

Link to comment
Share on other sites

Link to post
Share on other sites

16 hours ago, spaghet rat said:

mandarin

No, it was definitely Korean, unless "KR" means something else now.

My (incomplete) memory overclocking guide: 

 

Does memory speed impact gaming performance? Click here to find out!

On 1/2/2017 at 9:32 PM, MageTank said:

Sometimes, we all need a little inspiration.

 

 

 

Link to comment
Share on other sites

Link to post
Share on other sites

56 minutes ago, MageTank said:

No, it was definitely Korean, unless "KR" means something else now.

Kinda Really Mandarin?

/s

I'm not actually trying to be as grumpy as it seems.

I will find your mentions of Ikea or Gnome and I will /s post. 

Project Hot Box

CPU 13900k, Motherboard Gigabyte Aorus Elite AX, RAM CORSAIR Vengeance 4x16gb 5200 MHZ, GPU Zotac RTX 4090 Trinity OC, Case Fractal Pop Air XL, Storage Sabrent Rocket Q4 2tbCORSAIR Force Series MP510 1920GB NVMe, CORSAIR FORCE Series MP510 960GB NVMe, PSU CORSAIR HX1000i, Cooling Corsair XC8 CPU block, Bykski GPU block, 360mm and 280mm radiator, Displays Odyssey G9, LG 34UC98-W 34-Inch,Keyboard Mountain Everest Max, Mouse Mountain Makalu 67, Sound AT2035, Massdrop 6xx headphones, Go XLR 

Oppbevaring

CPU i9-9900k, Motherboard, ASUS Rog Maximus Code XI, RAM, 48GB Corsair Vengeance LPX 32GB 3200 mhz (2x16)+(2x8) GPUs Asus ROG Strix 2070 8gb, PNY 1080, Nvidia 1080, Case Mining Frame, 2x Storage Samsung 860 Evo 500 GB, PSU Corsair RM1000x and RM850x, Cooling Asus Rog Ryuo 240 with Noctua NF-12 fans

 

Why is the 5800x so hot?

 

 

Link to comment
Share on other sites

Link to post
Share on other sites

28 minutes ago, IkeaGnome said:

Kinda Really Mandarin?

/s

i mean asrock is taiwanese idk why korean bios lmao

you dont need an aio for anything but i9 cpus or heavy oc jobs just get an nh-d15 or peerless assassin

MARK THE SOLUTION AS SOLUTION

 

 

i am 14 so i may be wrong sometimes

 

@Bob__ is a w

 

 

 

 

 

 

Link to comment
Share on other sites

Link to post
Share on other sites

4 hours ago, spaghet rat said:

i mean asrock is taiwanese idk why korean bios lmao

You are aware that you can select many different languages in your BIOS, right? The manufacturers language doesn't matter. My point is, poor memory training can allow a system to POST but breaks the context menu of the BIOS to change the entire language despite never being touched manually. Happened several times on my old Z370 Fatality K6. 

My (incomplete) memory overclocking guide: 

 

Does memory speed impact gaming performance? Click here to find out!

On 1/2/2017 at 9:32 PM, MageTank said:

Sometimes, we all need a little inspiration.

 

 

 

Link to comment
Share on other sites

Link to post
Share on other sites

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now

×