Here is my Security update blog post… of this year, or decade, or ever 🙂
Most of us know viruses and even computer viruses, malwares, spywares, and use anti-virus software. Some of us even know rootkits, that run hidden from us (userspace) and sometimes from even the OS.
Do you know what your computer actually does when it boots up, and what is SMM or what the SMI Handler does? (I didn’t.)
The latest and greatest rootkits now run in System Management Mode (developed and supplied by hackers, NSA …) started straight from the BIOS. (Before your OS even has a chance to load.)
So don’t even trust your trusty Live CDs (pendrives…) to run clean.
So this is the research paper I found:
Are You Giving Firmware Attackers a Free Pass? from legbacore
Stealing encryption keys after booting into Tails Live OS Video
Other Info:
The Boot up process explained in detail [part 2]
System Management Mode
NSA implants
Tools & SW:
Copernicus (License Request)
chipsec
biosbits
hwlatdetect
Coreboot
Your Phones are not better either…
Using NAND Flash Bad Block Table to Hide stuff