That MSI Data Breach Included Some Really Bad Private Code Signing Keys

Intel Boot Guard is no longer so secure

Sadly, we’ve learned a lot more from last month’s MSI data breach. Because sadly the people behind it are starting to release content. The scary news is that the data contained Intel Boot Guard’s private signing key used in 116 of his MSI products. Intel Boot Guard is used to prevent UEFI tampering. This should take into account various vulnerabilities that can infect UEFI and cannot be simply removed.

Affected products include MSI’s various 11th Tiger Lake, 12th Adler Lake, and 13th Raptor Lake motherboards. Keys are currently for sale on the dark web, but unfortunately nothing stands in the way of available patches. Be very careful of people who sometimes claim to represent MSI.

Source link

Leave a Reply

Your email address will not be published. Required fields are marked *