HomeinetHow the NSA has access to DELL systems

How the NSA has access to DELL systems

A new document leaked by Edward Snowden describes the NSA 's DEITYBOUNCE program . The document describes how the NSA can access Dell systems , specifically PowerEdge servers, by exploiting the motherboard's BIOS and using System Management Mode (SMM). With this technique, the US secret service's malware is loaded during the operating system's boot. The attack, as described, requires physical access to the system with a USB, apparently using the Autorun bugs known from Stuxnet . Once implanted in the system's BIOS, the tool starts working as soon as the operating system starts loading.

According to ZDNet, the document is dated January 2007 (the same date as the document describing the iPhone hack), and the attacks described in it were certainly much more difficult to carry out then than they are today. The specific attacks do not work on all systems and models. They target “Microsoft Windows 2000, 2003, and XP. The affected models are Dell PowerEdge servers 1850/2850/1950/2950 RAID, using BIOS versions A02, A05, A06, 1.1.0, 1.2.0, or 1.3.7.”

Of course, the NSA must have updated the attack technique since 2007, as operating systems and firmware, in today's existing technologies, have the ability to thwart this form of attack. UEFI (Unified Extensible Firmware Interface) technology, along with Secure Boot, implements an authentication check based on the PKI code running on the computer. Of course, if the NSA has access to the keys, it does not need to flash the malicious code into the BIOS. Dell and Microsoft have been using UEFI with Secure Boot for the past few years. Certifying a system with Windows 8 requires UEFI and Secure Boot and is enabled by default using a Microsoft private key.

So if big tech companies don't cooperate with the NSA (by providing authentication keys), it's pretty hard for the intelligence agencies to breach such systems. But with the revelations coming in from Edward Snowden, it's starting to become clear that we shouldn't be using closed source operating systems.

nsa-ant-deitybounce

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SecNews
SecNewshttps://www.secnews.gr
In a world without fences and walls, who needs Gates and Windows

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS