Security Industry Incapable of Finding Firmware Attackers

DEAD7

Veteran
Supporter
Joined
Oct 5, 2012
Messages
50,978
Reputation
4,416
Daps
89,067
Reppin
Fresno, CA.
"Research presented at CanSecWest has shown that despite the fact that we know that firmware attackers, in the form of the NSA, definitely exist, there is still a wide gap between the attackers' ability to infect firmware, and the industry's ability to detect their presence. The researchers from MITRE and Intel showed attacks on UEFI SecureBoot, the BIOS itself, and BIOS forensics software. Although they also released detection systems for supporting more research and for trustworthy BIOS capture, the real question is: when is this going to stop being the domain of research and when are security companies going to get serious about protecting against attacks at this level?"
 
Top