Elektrine lite

← Feed

@ralfmaximus@mastodon.social

Post #3187087

2024-07-25 20:05 UTC

@dangoodin@infosec.exchange Honest question, promise I'm not trolling: again, how would an attack in the wild occur using the compromised key? I've got Windows Defender, UAC, and Malwarebytes running. I try to install an infected firmware update via its exe. One or all 3 of those tools should intercept the attempt. If I ignore the warning(s) and proceed to install compromised firmware, that's on me at that point. Right?

Replies (2)

  • @Zoarial94@infosec.exchange 2024-07-25 20:57

    @ralfmaximus@mastodon.social @dangoodin@infosec.exchange Sorry, I answered a question you didn't even ask in my last post. Such a low-level attack would probably mean that you are a person of interest. It's probably the kind of thing where a state sponsored actor would use zero-days to get installed. But also, yes, there are people who are willing to bypass everything or turn off an anti-virus to install cheat software or whatever else they think they're installing.

    Open ##3187088

  • @vathpela@better.boston 2024-07-26 01:07

    @ralfmaximus@mastodon.social @dangoodin@infosec.exchange with PKpriv you can sign updates to the trust databases and (for example) install your own bootloader that backdoors everything.

    Open ##3187090