Nearly 300 MSI motherboards will run any code in Secure Boot, no questions asked
(2023/01/17)
- Reference: 1673985672
- News link: https://www.theregister.co.uk/2023/01/17/msi_motherboards_secure_boot/
- Source link:
The Secure Boot process on almost 300 different PC motherboard models manufactured by Micro-Star International (MSI) isn't secure, which is particularly problematic when "Secure" is part of the process description.
Dawid Potocki, an open source security researcher and student based in New Zealand, [1]found last month that some MSI motherboards with certain firmware versions allow arbitrary binaries to boot despite Secure Boot policy violations.
Secure Boot is a PC security standard intended to ensure that devices boot only software trusted by the maker of the hardware. The device firmware is supposed to check the cryptographic signature of each piece of boot software, including UEFI firmware drivers, EFI applications, and the operating system.
[2]
That's the theory, anyway.
[3]
[4]
"On 2022-12-11, I decided to set up Secure Boot on my new desktop with [the] help of [5]sbctl , [the secure boot key manager on Linux]," Potocki explained in a [6]blog post last week. "Unfortunately I have found that my firmware was… accepting every OS image I gave it, no matter if it was trusted or not."
After finding that the [7]MSI PRO Z790-A WIFI failed to verify binaries, Potocki began looking into other MSI motherboards to see if they had similarly lax settings. He found [8]close to 300.
[9]
According to Potocki, MSI by default sets "Always execute" on policy violation for everything, making Secure Boot worthless under default settings. In an email to The Register , Potocki confirmed that the motherboards he listed in his GitHub issues post are still affected.
"[MSI's] laptops are not affected, only their desktop motherboards," Potocki wrote. "I suspect this is because they probably knew that Microsoft wouldn't approve of it and/or that they get less tickets about Secure Boot causing issues for their users."
[10]Microsoft's Secure Boot fix sends some PCs into BitLocker Recovery
[11]Intel Alder Lake BIOS code leak may contain vital secrets
[12]Microsoft tries again to ignite interest in DevOps cloud security
[13]ESET uncovers vulnerabilities in Lenovo laptops
He allows that he may have missed some models, but says users of MSI boards should be able to guess based on other affected motherboards using the same chipset that were built around the same time.
"The list consists mostly of beta firmware versions as they often were the first to introduce this issue," said Potocki. "I could have missed some, as getting beta firmware required me to guess URLs on which they reside, as MSI removes links to them after some time from their 'Support' page."
He added that he's unaware of any firmware build before September 2021 that would be affected.
[14]
Potocki said he tried to contact Taiwan-based MSI about his findings but hasn't heard back. He added that he has requested a CVE related to the use of insecure defaults.
"They didn't get in touch with me and I believe that they made this change deliberately, which just makes it worse," he said. "This is because I'm not sure how they would do it by mistake and also have it pass their testing."
He added that he tried to use MSI's web ticketing system and email, and even tried to contact the company through Twitter. But he has received no response.
The Register 's attempt to contact MSI has also not prompted any response. ®
Get our [15]Tech Resources
[1] https://github.com/Foxboron/sbctl/issues/181
[2] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2Y8cok-SAx2agOegUjX-fwwAAANE&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0
[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44Y8cok-SAx2agOegUjX-fwwAAANE&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33Y8cok-SAx2agOegUjX-fwwAAANE&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[5] https://github.com/Foxboron/sbctl
[6] https://dawidpotocki.com/en/2023/01/13/msi-insecure-boot/
[7] https://www.msi.com/Motherboard/PRO-Z790-A-WIFI/support
[8] https://github.com/Foxboron/sbctl/issues/181#issue-1489435549
[9] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44Y8cok-SAx2agOegUjX-fwwAAANE&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[10] https://www.theregister.com/2022/08/15/bitlocker_microsoft/
[11] https://www.theregister.com/2022/10/10/alder_lake_bios_code_leaked/
[12] https://www.theregister.com/2022/10/12/microsoft_ignite_security/
[13] https://www.theregister.com/2022/04/19/eset_lenovo/
[14] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33Y8cok-SAx2agOegUjX-fwwAAANE&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[15] https://whitepapers.theregister.com/
Dawid Potocki, an open source security researcher and student based in New Zealand, [1]found last month that some MSI motherboards with certain firmware versions allow arbitrary binaries to boot despite Secure Boot policy violations.
Secure Boot is a PC security standard intended to ensure that devices boot only software trusted by the maker of the hardware. The device firmware is supposed to check the cryptographic signature of each piece of boot software, including UEFI firmware drivers, EFI applications, and the operating system.
[2]
That's the theory, anyway.
[3]
[4]
"On 2022-12-11, I decided to set up Secure Boot on my new desktop with [the] help of [5]sbctl , [the secure boot key manager on Linux]," Potocki explained in a [6]blog post last week. "Unfortunately I have found that my firmware was… accepting every OS image I gave it, no matter if it was trusted or not."
After finding that the [7]MSI PRO Z790-A WIFI failed to verify binaries, Potocki began looking into other MSI motherboards to see if they had similarly lax settings. He found [8]close to 300.
[9]
According to Potocki, MSI by default sets "Always execute" on policy violation for everything, making Secure Boot worthless under default settings. In an email to The Register , Potocki confirmed that the motherboards he listed in his GitHub issues post are still affected.
"[MSI's] laptops are not affected, only their desktop motherboards," Potocki wrote. "I suspect this is because they probably knew that Microsoft wouldn't approve of it and/or that they get less tickets about Secure Boot causing issues for their users."
[10]Microsoft's Secure Boot fix sends some PCs into BitLocker Recovery
[11]Intel Alder Lake BIOS code leak may contain vital secrets
[12]Microsoft tries again to ignite interest in DevOps cloud security
[13]ESET uncovers vulnerabilities in Lenovo laptops
He allows that he may have missed some models, but says users of MSI boards should be able to guess based on other affected motherboards using the same chipset that were built around the same time.
"The list consists mostly of beta firmware versions as they often were the first to introduce this issue," said Potocki. "I could have missed some, as getting beta firmware required me to guess URLs on which they reside, as MSI removes links to them after some time from their 'Support' page."
He added that he's unaware of any firmware build before September 2021 that would be affected.
[14]
Potocki said he tried to contact Taiwan-based MSI about his findings but hasn't heard back. He added that he has requested a CVE related to the use of insecure defaults.
"They didn't get in touch with me and I believe that they made this change deliberately, which just makes it worse," he said. "This is because I'm not sure how they would do it by mistake and also have it pass their testing."
He added that he tried to use MSI's web ticketing system and email, and even tried to contact the company through Twitter. But he has received no response.
The Register 's attempt to contact MSI has also not prompted any response. ®
Get our [15]Tech Resources
[1] https://github.com/Foxboron/sbctl/issues/181
[2] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2Y8cok-SAx2agOegUjX-fwwAAANE&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0
[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44Y8cok-SAx2agOegUjX-fwwAAANE&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33Y8cok-SAx2agOegUjX-fwwAAANE&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[5] https://github.com/Foxboron/sbctl
[6] https://dawidpotocki.com/en/2023/01/13/msi-insecure-boot/
[7] https://www.msi.com/Motherboard/PRO-Z790-A-WIFI/support
[8] https://github.com/Foxboron/sbctl/issues/181#issue-1489435549
[9] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44Y8cok-SAx2agOegUjX-fwwAAANE&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[10] https://www.theregister.com/2022/08/15/bitlocker_microsoft/
[11] https://www.theregister.com/2022/10/10/alder_lake_bios_code_leaked/
[12] https://www.theregister.com/2022/10/12/microsoft_ignite_security/
[13] https://www.theregister.com/2022/04/19/eset_lenovo/
[14] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33Y8cok-SAx2agOegUjX-fwwAAANE&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[15] https://whitepapers.theregister.com/
Anonymous Coward
No excuse not to run secure by default. Even linux has auto mok enrollment and module signing during dkms install so not even nvidia is an excuse.
MSI
Anonymous Coward
Micro Soft Independence
These are boards intended for system builders, who tend to be enthusiasts that want secure boot off anyway.
This setting is equivalent to secure boot in audit mode on some branded PCs, like Dells. It is a bit of a dirty trick to change someone's setting when you're just doing an update, but that shouldn't bother the people running Windows anymore. Should be used to it by now!
The biggest thing is that people who think they have a handle on their security picture actually won't. Once they know of the issue, they can fix it.