Nobody Cares: Technology-only Edition

Noodles

The sequel will probably be better.
Joined
Sep 20, 2018
Messages
5,955
Location
Illinois
SL Rez
2006
Joined SLU
04-28-2010
SLU Posts
6947
lol, I was reading an article on Vice when I encountered an autoplay ad that would not let me scroll past to continue reading. New form of enshitification.
This sort of thing makes me want to just quit the internet completely sometimes.
 

Dakota Tebaldi

Well-known member
VVO Supporter 🍦🎈👾❤
Joined
Sep 19, 2018
Messages
9,763
Location
Ohio
Joined SLU
02-22-2008
SLU Posts
16791
Just about every Windows and Linux device vulnerable to new firmware attack

The exploit was developed by researchers, not actual hackers, so this is a vulnerability and not a threat yet. At some point soon the UEFI makers will be releasing some way to patch it - I guess you'd have to flash your motherboard, which is always a fun and anxiety-inducing experience.

Basically - you know how when you first boot up your computer, a logo of some kind pops up? Usually the motherboard manufacturer's logo, or a vendor's logo if you bought your computer pre-built. Well, that logo is an image file, and it can be replaced with an identical-looking one that can run arbitrary code. This is a problem because the instruction that displays the logo runs before almost anything else on your system, including firmware security routines.

---


There are several ways to exploit LogoFAIL. Remote attacks work by first exploiting an unpatched vulnerability in a browser, media player, or other app and using the administrative control gained to replace the legitimate logo image processed early in the boot process with an identical-looking one that exploits a parser flaw. The other way is to gain brief access to a vulnerable device while it’s unlocked and replace the legitimate image file with a malicious one.

In either case, the malicious logo causes the UEFI to execute attacker-created code during the all-important DXE phase each time the device boots. By executing code in this early stage, when most of the system initialization is performed, an exploit hijacks all execution flow that follows, allowing it to bypass security defenses such as Secure Boot and hardware-based verified boot mechanisms such as Intel Boot Guard, AMD Hardware-Validated Boot, or ARM TrustZone-based Secure Boot.

Depending on how the UEFI is configured, a simple copy/paste command, executed either by the malicious image or with physical access, is in many cases all that’s required to place the malicious image into what’s known as the ESP, short for EFI System Partition, a region of the hard drive that stores boot loaders, kernel images, and any device drivers, system utilities, or other data files needed before the main OS loads.

There are major benefits to this approach. One is that no executable code ever touches the hard drive, a technique known as fileless malware that hampers detection by antivirus and other types of endpoint protection software. Another benefit: Once the image is in place, it ensures a device remains infected even when an operating system is reinstalled or the main hard drive is replaced.


Awesome...
 

Knutz Scorpio

Well-known member
Joined
Sep 20, 2018
Messages
452
SL Rez
2010
Joined SLU
02-15-2014
Maybe we should go back to using clay tablets and abacuses.
 

Noodles

The sequel will probably be better.
Joined
Sep 20, 2018
Messages
5,955
Location
Illinois
SL Rez
2006
Joined SLU
04-28-2010
SLU Posts
6947
Good luck getting 99% of people to manage updating the motherboard.

Also, I love that feature, I made mine into a little happy ramen noodles bowl cartoon. This one I think.

 
Joined
Sep 19, 2018
Messages
6,769
Location
NJ suburb of Philadelphia
SL Rez
2003
SLU Posts
4494
Just a short mention of my internet hosting provider, nearlyfreespeech.net. If you know what you are doing and need a host for a low volume, very low cost website with no hand holding they are the place to go. I host my Criterion Channel page there and fool around in various ways to see what works on the web there. They are pay for usage. My bill for December was $1.86. My account was getting low so I sent them $20. I sent them $10 in all of 2023.
 
  • 1Like
Reactions: Noodles

Noodles

The sequel will probably be better.
Joined
Sep 20, 2018
Messages
5,955
Location
Illinois
SL Rez
2006
Joined SLU
04-28-2010
SLU Posts
6947
I guess they gotta fill the hole where the old cup holder was when people used CD ROMs.
 

Dakota Tebaldi

Well-known member
VVO Supporter 🍦🎈👾❤
Joined
Sep 19, 2018
Messages
9,763
Location
Ohio
Joined SLU
02-22-2008
SLU Posts
16791
It's a cute idea but who's gonna dig out one of those old computer cases just to use this?
 

Free

*censored*
VVO Supporter 🍦🎈👾❤
Joined
Sep 22, 2018
Messages
42,228
Location
Moonbase Caligula
SL Rez
2008
Joined SLU
2009
SLU Posts
55565
It's a cute idea but who's gonna dig out one of those old computer cases just to use this?
New towers are not all that different framework-wise as old towers.

 
  • 1LOL
Reactions: Cindy Claveau

Dakota Tebaldi

Well-known member
VVO Supporter 🍦🎈👾❤
Joined
Sep 19, 2018
Messages
9,763
Location
Ohio
Joined SLU
02-22-2008
SLU Posts
16791
Framewise maybe not, but that thing needs a 5.75" drive bay to slide into, and I don't think I've seen a new case with optical drive bays for like....5 or 6 years. Like the case in that pic is 11 years old.
 

Free

*censored*
VVO Supporter 🍦🎈👾❤
Joined
Sep 22, 2018
Messages
42,228
Location
Moonbase Caligula
SL Rez
2008
Joined SLU
2009
SLU Posts
55565
  • 2Agree
Reactions: Cindy Claveau and Govi

Knutz Scorpio

Well-known member
Joined
Sep 20, 2018
Messages
452
SL Rez
2010
Joined SLU
02-15-2014
All this prompted me to try opening the DVD drive in my old cranky workstation only to get the mechanical uhg-thunk of a stuck tray. Well, shit.
 
  • 1Hug
Reactions: Cindy Claveau

Noodles

The sequel will probably be better.
Joined
Sep 20, 2018
Messages
5,955
Location
Illinois
SL Rez
2006
Joined SLU
04-28-2010
SLU Posts
6947
New towers are not all that different framework-wise as old towers.

My main PC has a big flat panel on the front.

My old one has drive bays though.

Besides, you can but external USB CD drives if you need a drink tray.
 

Dakota Tebaldi

Well-known member
VVO Supporter 🍦🎈👾❤
Joined
Sep 19, 2018
Messages
9,763
Location
Ohio
Joined SLU
02-22-2008
SLU Posts
16791

Free

*censored*
VVO Supporter 🍦🎈👾❤
Joined
Sep 22, 2018
Messages
42,228
Location
Moonbase Caligula
SL Rez
2008
Joined SLU
2009
SLU Posts
55565
Oh yeah I know you can still BUY them.

But like, that case right there is 10 years old. It's nooooot a new case. It has a FLOPPY drive bay!
I'm not sure I get your point.

It's an older design, but it's new in that it's not a used or refurbished case. They are still producing them. You can use it to build a pretty modern pc setup. The design being a decade old doesn't negate any of that.
 
  • 1Like
Reactions: Govi