Hackers Publish MSI Source Code and Private Keys on the Dark Web

  Рет қаралды 255,909

Mental Outlaw

Mental Outlaw

Күн бұрын

Пікірлер: 808
@snugasapugonarug
@snugasapugonarug Жыл бұрын
Can't fall for this if you just don't update anything 🧠
@mikoajszczepanik2197
@mikoajszczepanik2197 Жыл бұрын
That's why i still encrypt using a sheet of paper and a pencil
@leek5682
@leek5682 Жыл бұрын
My iPhone IOS version is as outdated as my dementia meds
@ConsensusX
@ConsensusX Жыл бұрын
Too bad, it's mandatory to update software nowadays. Oh, and everything requires internet access.
@carnivorebear6582
@carnivorebear6582 Жыл бұрын
@@mikoajszczepanik2197 never roll your own crypto
@swagmuffin9000
@swagmuffin9000 Жыл бұрын
@@mikoajszczepanik2197 when people made fun of me in the past for not knowing how to spell, looks like joke's on them. Turns out I was just practicing encrypting my work from a young age.
@cyrilio
@cyrilio Жыл бұрын
The Dutch police came out with a warning two days ago about this. Had no idea they were on top of this.
@hubudubebububububeubub
@hubudubebububububeubub Жыл бұрын
Gekoloniseerd.
@longnamedude3947
@longnamedude3947 Жыл бұрын
Well it is good to hear that they are being proactive about sharing the news with the wider public directly. Where did you see the warning shared? TV News? Internet News Website? TV Advert? Social Media Post by News Media? Social Media Post by the National Police?
@Jeromin
@Jeromin Жыл бұрын
Dutch cyber security is some of the best in the world, not surprised.
@SirPeterlll
@SirPeterlll Жыл бұрын
Dutch police are working closely on some projects with major providers like KPN, KPN has been consistent in being in the top 5 of the cyberlympics.
@IdkG7
@IdkG7 Жыл бұрын
Props to the Dutch police
@RRICKYSPANISH
@RRICKYSPANISH Жыл бұрын
Fun fact. If you tell the hacker no, they can’t legally hack you 👍
@TheHighborn
@TheHighborn Жыл бұрын
well i don't think black hat guys really care that deeply about legality.
@thetroll1129
@thetroll1129 Жыл бұрын
^ they can’t not care about the law that’s illegal
@RRICKYSPANISH
@RRICKYSPANISH Жыл бұрын
@@thetroll1129 this guy gets it
@iDeparture
@iDeparture Жыл бұрын
this is true has saved my ass many times though some aren't as honorable so i just send them a screen shot of my junk and bhole and thats worked so far every time
@JamesFox1
@JamesFox1 Жыл бұрын
Best Joke of the Day = Literally
@acceptablecasualty5319
@acceptablecasualty5319 Жыл бұрын
Oh boy i love the fact that google ad services never checks their clients!
@dr.michaelmorbius2400
@dr.michaelmorbius2400 Жыл бұрын
google is slowly trading their credibility for money, i wonder if it'll be worth it in the long-term.
@Chinothebad
@Chinothebad Жыл бұрын
Makes one wonder how long does it take for Google to feel the heat for all of this with its ad services letting scammers link their bait sites.
@wearr_
@wearr_ Жыл бұрын
Except for when it's a legit website, and then that gets flagged as malware 🙃 (ask me how I know)
@nwerd7584
@nwerd7584 Жыл бұрын
Thats their whole existing MO since the beginning.. make a google walled garden where they "control" the scams while feigning ignorance. Their motto used to be dont be veil and was changed for a reason.
@acceptablecasualty5319
@acceptablecasualty5319 Жыл бұрын
@@wearr_ how do you know
@TheTundraTerror
@TheTundraTerror Жыл бұрын
Security through obscurity. Works great until it doesn't.
@barrett-si4zq
@barrett-si4zq Жыл бұрын
Signing code with a private key isn't the same as obsfucation. That would be more similar to not releasing code or hw schematics and making your code/hw intentionally hard to hard to reverse engineer. I really don't see a better way to make sure what you're downloading is legit other than checking signatures.
@carnivorebear6582
@carnivorebear6582 Жыл бұрын
@Barrett Dude don't bust the FOSS fanatics bubble... now the poor guy might have to think critically
@Akab
@Akab Жыл бұрын
@@barrett-si4zq downloading only from official sources seems to be a pretty good way too 😁
@barrett-si4zq
@barrett-si4zq Жыл бұрын
@@Akab to be fair I would much rather have both the official download page and a public key to verify it wasn't compromised. Not to say both couldn't be compromised at the same time.
@Akab
@Akab Жыл бұрын
@@barrett-si4zq yeah, that's even better👍
@AshnSilvercorp
@AshnSilvercorp Жыл бұрын
_Hey guys, our security team recommends a really great way to lock down our private keys we got from Intel. They said backup the drives, don't isolate them from our primary network to a local one, and just leave them plugged in and able to be contacted externally at any time and hope our network guard tells us when something goes wrong. It works wonders!_
@bryan4tw
@bryan4tw Жыл бұрын
HSM? I hardly know him!
@MitchMatrixx
@MitchMatrixx Жыл бұрын
@@bryan4tw Hardware Security Management?
@barrett-si4zq
@barrett-si4zq Жыл бұрын
@@MitchMatrixx module
@MitchMatrixx
@MitchMatrixx Жыл бұрын
@@barrett-si4zq Ah, thanks 👍🏻 So like a Sonicwall, etc?
@thehonkening1
@thehonkening1 Жыл бұрын
your own little trusted key server :)
@nwerd7584
@nwerd7584 Жыл бұрын
Sucks this happened but im happy they didnt pay at the very least. Paying is what emboldens the choice to keep doing it. MY graphics card is MSI based but I download it directly through their software.
@derfliegendehollander7636
@derfliegendehollander7636 Жыл бұрын
i don't see source code leaks through ransoms as a bad thing. if anything, stuff like BIOS source code helps people understand stuff that is currently wildly undocumented and not easy for enthusiasts to get into. also, this would expose security issues their software might have, that a malicious entity would have figured out way before any company engineer would have. and it's not like this would hurt their bottom line.
@nwerd7584
@nwerd7584 Жыл бұрын
@@derfliegendehollander7636 I dont have any fault in seeing the gilded lining, but this just makes people realize the bad sides of it, ie. greed. The sim swap kids were pretty definitive of these types of things. Once it starts hitting companies it wasnt meant to, like certain types of ransomware has its where its gotten this reputation.. Ive experienced some service failure because of these types of things. And not all of them would be targeted toward a company that even has source code as a major piece of their product.. As a citizen of the country though it is their right to make the choice as a company, if its not liked you just dont buy it. Like if this was entirely a profitless venture in terms of the malware and then the ransom I would have a far less of an issue with it, and im kinda surprised they ddnt pay tbh.. Thats kind of these companies bread and butter. Far less big companies have done so, which like I said leads to the next one.
@ctoid
@ctoid Жыл бұрын
*Linux kernel source codes got leaked* Linus: Oh no, anyway
@volundrfrey896
@volundrfrey896 Жыл бұрын
Macos kernel source code got leaked Apple: Oh no, anyway
@emmettturner9452
@emmettturner9452 Жыл бұрын
I got an “DH L” phish google ad result recently when I searched “track DHL.” The page was clearly a phish for tracking numbers. Two days later I saw a news report about thieves stealing tracking numbers and registering accounts as their victims with courier services in order to redirect packages and steal their contents. Example was a woman who’s laptop was redirected to a drug store pickup location where someone picked it up with fake credentials.
@emmettturner9452
@emmettturner9452 Жыл бұрын
Oh yeah: I couldn’t report the ad. The three dots simply wouldn’t respond when I clicked back on my phone. Repeating the search no longer returned the ad word result.
@gd44481
@gd44481 Жыл бұрын
I always wonder how can people live without adblockers
@notaboutit3565
@notaboutit3565 Жыл бұрын
@@gd44481 I haven’t seen a regular ad in nearly a decade. The only ones I see are billboards and the occasional one when using somebody else’s computer, when I get bombarded with ads like that anymore it just makes me recoil and go into a fit of rage lmao
@yunggoosbumps215
@yunggoosbumps215 Жыл бұрын
That's why I never ever ever click anything that says AD on google. It's most certainly a fake site with malware.
@emmettturner9452
@emmettturner9452 Жыл бұрын
@@notaboutit3565 Yeah, but people typically track packages on their phones these days. That’s also how they watch and comment on KZbin. ;)
@istvanbarta
@istvanbarta Жыл бұрын
I love, how your channel is a responsible "white-hat" information source. Actually, this is not the first time when I had this kind of crucial information first instead of any mainstream information source which should be served like this because it should be their main purpose. Thank you very much for your work for the community!
@memesofproduction27
@memesofproduction27 Жыл бұрын
anyone still relying on mainstream info sources in 2023 is ngmi
@istvanbarta
@istvanbarta Жыл бұрын
@@memesofproduction27 what isn't mainstream in 2023 if you aren't subscribed to thousands of specific topics? :D
@iDeparture
@iDeparture Жыл бұрын
GN mentions it in there latest upload
@itranscendencei7964
@itranscendencei7964 Жыл бұрын
This is why I almost always wait for something to break before updating. I find that firmware/BIOS updates cause more problems than they're worth, usually. Still running the same BIOS from late 2020 without issue.
@p0358
@p0358 Жыл бұрын
Nah in the Zen 4 platform (or really any new one), the early BIOSes often have various stability issues. The last one that sets the CPU on fire being the most rampant one. Though if you’re on already a well established platform, then you’re probably right. But having a board with factory installed BIOS isn’t always good
@itranscendencei7964
@itranscendencei7964 Жыл бұрын
Well it's not the BIOS that came pre installed. I installed the most recent at the time (Dec 2020 IIRC). But yeah, it's been rock solid other than some freezing issues that I had when I first built it. Figured it out after a few months. Damn C States. Lol
@lucasm20
@lucasm20 Жыл бұрын
I wonder if this can lead to open source firmware developed using clean room reverse engineering.
@flintfrommother3gaming
@flintfrommother3gaming Жыл бұрын
If anything, any reverse engineering attempts will probably be deprecated (if there were any) due to legal issues, even if you didn't use the source code at all.
@lucasm20
@lucasm20 Жыл бұрын
@@flintfrommother3gaming probably, but that's not stopping random people from making scripts or programs that fix things.
@MentalOutlaw
@MentalOutlaw Жыл бұрын
It technically could, but since the source was stolen any projects derived from that stolen code would be illegal.
@daniellittlewood8471
@daniellittlewood8471 Жыл бұрын
Doesn't sound like anyone in the thread knows what clean room means. The point is that you go to great lengths to ensure nobody writing code has ever seen any of the leaked code. As long as the free firmware is only based on the interface defined by the hardware (which could be described in public by someone who read the leak), and not the exact implementation in the leaked code, then copyright does not apply and there are no legal issues.
@lucasm20
@lucasm20 Жыл бұрын
@@daniellittlewood8471 Yeah what I meant by clean room is you'd have someone look over the code and then write a specification that someone else would write. The only question is whether that is still legal when done using illegally obtained code (as opposed to decompiled code). Dunno if there's a legal precedent for this exact kind of situation.
@DaBlaccGhost
@DaBlaccGhost Жыл бұрын
bout to update off the FIRST item on google for my work laptop that I see thanks Mental Cat!
@C1rnobyl
@C1rnobyl Жыл бұрын
This also allows people to take more ownership of their own hardware. Too bad they didn't leak the Intel ME signing keys. Those are the holy grail for a libre BIOS. Me cheering on this hack is a result of the "you bought it but you don't own it" way most silicon root of trust implementations work.
@shinobiighost6946
@shinobiighost6946 Жыл бұрын
Well shoot, as an MSI owner i appreciate this video
@ducktape4502
@ducktape4502 Жыл бұрын
Start asking for a refund. Alot of msi owners are. Same as me.
@shinobiighost6946
@shinobiighost6946 Жыл бұрын
@@ducktape4502 it's been years now I don't think it'll be worth my time lol
@JimboJuice
@JimboJuice Жыл бұрын
@@shinobiighost6946 you've got cause for a refund, decent chance they give it to you just to save face.
@DursunX
@DursunX Жыл бұрын
@@ducktape4502 are you serious.. is this an option or actually necessary? i just checked, my system warranty expired last week 😥 do you think it's vital to swap brands now? do i hit the panic button yet?
@Akkbar21
@Akkbar21 Жыл бұрын
@@JimboJuicethey won’t give refunds. You’re trippin and have no idea what you’re talking about.
@sakamocat
@sakamocat Жыл бұрын
"it's only very illegal if you get caught" what a phrase
@unr34L-
@unr34L- Жыл бұрын
Shut up furry kid
@txorimorea3869
@txorimorea3869 Жыл бұрын
Is only illegal if you get caught and you don't have friends in DC. If you have enemies in DC it doesn't matter if you never did anything wrong, you are still fucked. Is simple as that.
@sampletext9426
@sampletext9426 Жыл бұрын
wait you mean g0vernment officials are never caught ???
@Sir_Richard_Crainum_lll
@Sir_Richard_Crainum_lll Жыл бұрын
I once farted while waiting in line at the bank & it smelt SO bad. When attention was directed at me, I acted like it was the guy behind me & they believed it....ya, I can appreciate & agree with the quote
@sakamocat
@sakamocat Жыл бұрын
@@Sir_Richard_Crainum_lll LOL
@saumyacow4435
@saumyacow4435 Жыл бұрын
Not just custom firmware but what I'd love to see is an accessible guide to what goes on inside these firmwares - for educational purposes. It may help someone write new ground-up firmware for the purpose of experimenting with a new OS. (Yes, I have pretensions).
@kanshank
@kanshank Жыл бұрын
Checking my motherboard quickly just to be sure. Oh... Not.. Good..
@88Based88
@88Based88 Жыл бұрын
It's over :(
@vincentvega3093
@vincentvega3093 Жыл бұрын
At least not an exploding A sus
@TheHighborn
@TheHighborn Жыл бұрын
i just updated bios not long ago... rip i guess.
@ВасяПетрович-ь2я
@ВасяПетрович-ь2я Жыл бұрын
Hard asrock Chad here feeling pretty good with all the news dropping recently
@oggilein1
@oggilein1 Жыл бұрын
Good thing the MSI Z-690a has coreboot ported to it so there's a way out of this proprietary hell for those willing to look
@CasualGamers
@CasualGamers Жыл бұрын
Hopefully some AMD BIOS building tools have leaked in the mix. Adding CPU support on AM4/Unlocking pcie 4.0 on non-500 series boards/swapping agesa should be possible with an inhouse tool. There's too much effort for reverse engineering these, so basically no one does it.
@noanyobiseniss7462
@noanyobiseniss7462 Жыл бұрын
Even better, we can hack bioses again instead of being locked into what they say we can do with the hardware we pay for.
@emmettturner9452
@emmettturner9452 Жыл бұрын
Speaking of buggy MSI firmware: I spent most of my time at MSI-sponsored QuakeCon 2003 (HUGE LAN party event where Doom³ and Call of Duty were previewed to the public) troubleshooting my nForce 2 system that stopped POSTing when I cleared my CMOS. That’s because MSI’s latest firmware defaulted to a higher bus speed than many supported CPUs… including mine. This was before EFI but after dedicated jumpers for setting bus speed disappeared… a trend Abit kinda started for enthusiast boards. All I had was a “Safe Mode” jumper… and even that didn’t help. It would get me into CMOS Setup with the FSB grayed out and set to “Default.” I couldn’t actually boot with the Safe Mode jumper so it was functionally no better than popping the battery or using the CMOS Reset jumper since I still couldn’t POST after using it. Once I realized it was defaulting to the wrong bus speed I had to borrow someone else’s CPU/RAM to get into CMOS Setup and manually set the correct bus speed. Only then could I switch back to my CPU or downgrade the board’s firmware… which was several more hours of frustration. The Internet connection was so overwhelmed it almost took a day to get the PDF manual that led me to Safe Mode and another day to get the old FW from MSI. Even when downloads finished they’d be corrupt. That’s just how it is with a LAN party so huge. After nVidia and AMD, MSI was a major sponsor at QuakeCon 2003 where they were pushing their new SFF systems to compete with Shuttle… so once I had it figured out I walked right over to their booth and gave them an earful. Why would they ever initialize default settings to a higher FSB than most supported CPUs?! Insane. Needless to say, I was upset. I skipped class, drove half-way across the country, and spent a fortune to stay at the Adam’s Mark hotel only to waste more than two of my three event days due to their incompetence. I didn’t even sleep. I held a grudge. When I built an HTPC for Doom³ I skipped MSI’s SFF offerings and went straight to their competitor with the Shuttle SN45G2 (“SoundStorm” MCP-T + nF2 Ultra 400). Unfortunately, that also had a disappointing issue with FSB defaults. My mobile Barton was essentially an unlocked Athlon XP 3200+, bin-sorted because it was stable even at lower voltages than other 3200+ CPUs… thus perfectly capable of 400 FSB. There was no default yet it was always unstable when you manually set 400. You had to make it look like a locked 400 FSB CPU (“L12 trick”) and then it was perfectly stable. In my case that involved a tiny wire bridging two pins in the CPU socket. It seems there was some hidden spec you couldn’t adjust which was automatically set according to the default FSB while assuming no default was the slowest. Other enthusiast boards supported mobile Bartons at 400 FSB just fine without this trick. Not as bad as MSI’s gaffe since I could still POST at the defaults but automatic settings that aren’t exposed to the user on an enthusiast board is no bueno.
@jazzy93c
@jazzy93c Жыл бұрын
Thanks for sharing
@halfpint90
@halfpint90 Жыл бұрын
Sick bro you shouted at a bunch of enployees and ruined their weekend too well done
@yellowberryHN
@yellowberryHN Жыл бұрын
Abit being mentioned just reminds me of the old "make like an Abit motherboard and stop posting" meme
@emmettturner9452
@emmettturner9452 Жыл бұрын
@@yellowberryHN Ah, yes. Early on in the “Capacitor Plague” everyone blamed Abit for using cheap Taiwanese capacitors… then you started seeing power supplies, motherboards, and more fail for IBM, Dell, and others. Turns out that the cheap capacitors were using an incomplete formula stolen from the Japanese and soon the unstable caps were coming from everywhere in SE Asia. Meanwhile, Asus kept using high-end Japanese capacitors even though they’re Taiwanese themselves… winning over most enthusiasts. I recall my own Abit BP6 dual socket 370 440BX board stopped posting with both CPUs around 2002 (removing one would still POST).
@TENNOM
@TENNOM Жыл бұрын
god damn, L
@DursunX
@DursunX Жыл бұрын
this is concerning. thank you for publishing. my entire system is Msi based and runs multiple Msi firmware (except the psu). i didn't build a $2k open-source hacker's portal intentionally, but here we are.
@futuza
@futuza Жыл бұрын
It's really only an issue if you randomly download and install firmware updates from some source other than MSI...
@DursunX
@DursunX Жыл бұрын
@@futuza yep, back to being vigilant. no 3rd party FW sites, links, or github libraries. im locking down to stock firmware and drivers for the foreseeable future. boring but safe. 🖖🏼
@YouTubeGlobalAdminstrator
@YouTubeGlobalAdminstrator Жыл бұрын
​@@futuza shhh he wanted to tell us he's a fanboi, let him have his moment. 😂
@DursunX
@DursunX Жыл бұрын
@@KZbinGlobalAdminstrator nuh, not a fanboi.. but feelin like a fool though. i was told Msi is rock solid for non-gamers (i assumed that also meant back-of-house operations at Msi).
@Exachad
@Exachad Жыл бұрын
​@@futuza Well, finding vulnerabilities from source code is easier than finding them from reverse engineering. Some vulnerabilities might allow ordinary viruses to escalate their privilege and modify things like CPU voltage to permanently kill your computer. This is more dangerous because it's easier for an ordinary person to download an ordinary virus than it for them to download a compromised BIOS since updating BIOS is something only tech-savvy people tend to do. Such a virus has already been found before. You can Google "Extreme Privilege Escalation on Windows 8/UEFI Systems". This vulnerability wasn't just found in a specific platform's firmware, but in Intel's UEFI as a whole, meaning it affects every single motherboard that uses UEFI, which is basically every modern motherboard, so much worse than anything that could be found in the MSI leak. The presentation by MITRE even says it can 'Permanently "brick" the victim computer'. Anyway, it wasn't a big deal in the news since it was found by security researchers and patched by Intel before it was reported.
@deadman5985
@deadman5985 Жыл бұрын
A classic case of certificate revocation - make sure your OS is up-to-date because spoofed certificates don't include certificate revocation lists (or if any spoofed ones)
@deadman5985
@deadman5985 Жыл бұрын
besides that - everything should be open source, will be the only way to fix things fast enough soon
@LutherMahoney
@LutherMahoney Жыл бұрын
I wonder if anyone at MSI is facing unemployment today?
@satouhikou1103
@satouhikou1103 Жыл бұрын
Are you joking? They likely got raises for this.
@ginx2666
@ginx2666 Жыл бұрын
MSI and other corpos from that segment of the market should get the message: Open source your drivers, or get hacked.
@nnnik3595
@nnnik3595 Жыл бұрын
No they won't. But its more likely than Windows users using that dog shit package manager.
@zhanucong4614
@zhanucong4614 Жыл бұрын
they have right to their own code not being open source,just use amd or intel
@alansmithee2012
@alansmithee2012 Жыл бұрын
"Google ads" People actually see those? It's the current year and people still don't have ublock origin or any other basic adblocker installed on their browsers?
@ferna2294
@ferna2294 Жыл бұрын
Same. Google ads is SPAM.
@friendofp.24
@friendofp.24 Жыл бұрын
I'd still double check the links of websites you visit these days.
@MH_VOID
@MH_VOID Жыл бұрын
Also, people still use google? Really?
@davideographer4410
@davideographer4410 Жыл бұрын
@@friendofp.24 Oh the memories!
@b747xx
@b747xx Жыл бұрын
The Intel Bootguard keys can't be "updated" by any mean, they are carved into the chipset (e-fuses) They serve to sign the bootloader part of the BIOS The other keys Are for MSI to sign there firmware (not the bootloader but the EFI stuff after that, like the AMI Bios protection crap). Not related to signed software and drivers AFAIK. It's a really great news, now I want a MSI board actually. Finally a recent board I can actually own instead of rent. I like hackers that make hardware ownable instead of rentable. Did they left an XMR address for tip?
@Milkman-007
@Milkman-007 Жыл бұрын
gigachad mindset
@JJFX-
@JJFX- Жыл бұрын
Glad you confirmed my suspicions because this is exactly what I was thinking. I really hate MSI but this has me quite interested.
@excess.subiefl0w
@excess.subiefl0w Жыл бұрын
Xmr address for a tip. Lol savage 😂
@platinumsun4632
@platinumsun4632 Жыл бұрын
What?
@ClickCLK
@ClickCLK Жыл бұрын
b747xx, judging by your comment you seem to know a thing or two about intel bootguard, so I want to ask you a question, if you're ok with it. I'm working at a computer repair shop, we fix pc and laptop motherboards on component level. Nowadays, more and more laptops have Platform Controller Hub integrated on a single substrate with cpu and if PCH gets damaged you can't swap it alone, only the whole CPU chip. Most of the time there's no way for us to buy new CPUs (they either aren't available or extremely expensive, making repair not economically viable), so we either using used CPUs which are available for purchase or CPUs pulled from donor boards. But if the PCH was bootguard locked on those used\donor CPUs then they can only work in another board from the same series of laptops, which is really problematic. What do you think, using keys found in this leak, ist it possible to pull donor CPUs from MSI laptops and using them in other systems after resigning firmware of those systems with MSI keys?
@X8551516
@X8551516 Жыл бұрын
My question is, is Afterburner in there somewhere and could we potentially see a bunch of open source GPU overclocking software start popping up for Windows and Linux.
@davidkamaunu7887
@davidkamaunu7887 Жыл бұрын
I like how you segued to a positive outcome from this going forward. Good job at making lemonade from lemons!
@alexdms9215
@alexdms9215 Жыл бұрын
I love your content man, really appreciate it. Thanks.
@ФеофанЭтополедолжнобытьзаполне
@ФеофанЭтополедолжнобытьзаполне Жыл бұрын
Assymmetric cryptography was never intented to protect you. Although theory behind cryptography itself is good (allegedly), _they_ went for a great length to make certificate *infrastructure* as vulnerable as possible. That's exactly what you see now. We can only guess how many private keys from our CA repos are held by agencies. My bet is *a lot*.
@barrett-si4zq
@barrett-si4zq Жыл бұрын
Is there an alternative? Despite CA potentially being compromised, PKI seems like the best option we have.
@tablettablete186
@tablettablete186 Жыл бұрын
​@@barrett-si4zq Open Source? Like, I am no joking If you can see the code, you can validate it (considering that you have a trustworthy compiler and verifier)
@barrett-si4zq
@barrett-si4zq Жыл бұрын
@@tablettablete186 making something open source and singing official code with a private key aren't mutually exclusive. The signature is to make sure the file was changed and can be validated with a public key. This is a way to verify what you have downloaded is official and has been modified after being signed.
@ФеофанЭтополедолжнобытьзаполне
@ФеофанЭтополедолжнобытьзаполне Жыл бұрын
@@dieselbaby exactly. But the thing is that we already had more than enough of such cases ten years ago. I thought that CA institute was done for good when they issued fake Microsoft certificates back in 2010 or so, but nope. Then it happened again in 2013, then in 2015. Then Indian NIC legitemately issued fake certs for Goolagol. But CAs stayed stonk. More than that, they (supposed victims of CAs) started to promote SSL like never before, even introduced Let's Encrypt to further improve CA' positions. I wonder who else might be so concerned about your GF titties to be properly encrypted for free if not the one in possession of the key?
@nicolaspiper3437
@nicolaspiper3437 Жыл бұрын
Glad i checked the old youtube, taking an ethics course for data science and this article will do great. Thanks, Mental Outlaw!
@AngryR4v3n
@AngryR4v3n Жыл бұрын
Just as a side note you showed MalwareBytes Anti-malware as random software. I used it in the XP/Vista days. It was quite good actually
@Sprinkles-r5y
@Sprinkles-r5y Жыл бұрын
Cnet was also quite good back in the day too. So sad how things have changed. Keep getting suggestions to update from xp service pack 2 , this just gives me more reasons not to.
@ViroRads
@ViroRads Жыл бұрын
So that means MalwareBytes is not trustworthy or good anymore?
@AngryR4v3n
@AngryR4v3n Жыл бұрын
@@ViroRads no, I wouldn't say that, I just hadn't have the opportunity to use it again. I don't know how's the program nowadays, but if I had any virus issues I would use it again ;)
@JACS420
@JACS420 Жыл бұрын
@@ViroRads most malware nowadays comes with a rootkit, malware bytes simply can’t detect malware stuffed in your ram, or boot partition.
@senor2930
@senor2930 Жыл бұрын
Lol!
@zakaria3663
@zakaria3663 Жыл бұрын
MSI goes brrrrrrrrrrrrrrrrrrr💀💀💀💀💀💀
@stephenkolostyak4087
@stephenkolostyak4087 Жыл бұрын
11:34 "it's only illegal if you get caught." ...it's only prosecuted if you get caught. This is a significant difference.
@BitterCynical
@BitterCynical Жыл бұрын
Imagine an open source BIOS creation tool where you pick and choose the features you want. Most of us won't run more than the one CPU we have already socketed into the board, neither do we need support for dozens of different RAM modules. Lots of things take up the limited file size in a BIOS, getting rid of the stuff you don't need would free up space for other cool features. And it just so happens many MSI boards have this cool option to flash a BIOS without even a CPU installed, just plug in a USB drive and press a BIOS flash button and wait, so it'd be easy to unbrick boards after flashing a bad custom BIOS.
@aaaaa12394
@aaaaa12394 Жыл бұрын
Hey mental outlaw, Could you do a really quick video on discord, mentioning tencent etc. How would you make it impossible to retrieve messages once they've been deleted - do they even get deleted, etc. Does china have every message you've ever been sent, also the fact that discord doesn't really delete any of your data at all when you delete your account. Sorry i don't know much so i was hoping you could do a video on it
@johanngambolputty5351
@johanngambolputty5351 Жыл бұрын
If only this meant that coreboot can be made to work on my msi motherboard now, alas probably not.
@friendofp.24
@friendofp.24 Жыл бұрын
So is this an active threat to MSI users, like will my PC be compromised just by doing nothing? Or can it only be compromised by downloading fake MSI software?
@MetalSora
@MetalSora Жыл бұрын
So no unless you download any infected files, you wont be affected now this does affect that maleware will not be detected by windows a bit, since they will need to revoke the keys so it is a limited timeline as well
@Sage-xr1on
@Sage-xr1on Жыл бұрын
yes, you'll be fine as long as you don't download anything that isn't certified as being from MSI (i.e. directly from MSI's domains)
@bettertelevision968
@bettertelevision968 Жыл бұрын
thank you for your pc xd
@oventree
@oventree Жыл бұрын
the only way it could be affected by just sitting there is if someone had physical access to it and could use a flashing device clipped to one of your motherboard chips to flash a malicious bios, but that's insanely unrealistic for most people
@Hellawacked
@Hellawacked Жыл бұрын
Get it updated when they update the keys. It’s a easy pivot if someone got in elsewhere you’ll want to close it.
@minar49ner
@minar49ner Жыл бұрын
They should have had backup keys for everything letting them dump the compromised keys for the backups that should have been kept in cold storage for just an event. People are super near sighted.
@ReligionAndMaterialismDebunked
@ReligionAndMaterialismDebunked Жыл бұрын
I didn't know of Odyssey, so thanks. Yes, links mostly don't work in KZbin comments in recent years.
@grandpagamer2020
@grandpagamer2020 Жыл бұрын
good to know. I have an old 9 year old computer with an msi motherboard and I was going to update the bios a few weeks ago because something wasn't working too good.
@xr.spedtech
@xr.spedtech Жыл бұрын
That needs to wait a little bit more
@derfliegendehollander7636
@derfliegendehollander7636 Жыл бұрын
every piece of closed source software (especially relating to hardware) that gets released from the slimy hands of security-unconscious engineers is a win in my book. if any of these groups had donation addresses, i would tip them.
@andrasbiro6604
@andrasbiro6604 Жыл бұрын
And I tought its gonna be gpl food content from now on :) I will watch that part of the Luke Smith transformation as well dont worry.
@MentalOutlaw
@MentalOutlaw Жыл бұрын
I'm gonna do a bit of both, unfortunatly my soil seems to be depleted of nutrients so the farming content might be a bit slow but I might be getting a truckload of free woodchips in the next couple of days which will help alot
@Bwalston910
@Bwalston910 Жыл бұрын
@@MentalOutlaw Also heard of growing edible mushroom in wood logs for nutrient dense fertilizer. You get delicious mushrooms and a constant source of free rich fertilizer.
@drRoflol
@drRoflol Жыл бұрын
What to say, other than congratulations! It must have hurt but it sounds like the responsible (for your company) AND the smart (for you and your family) thing to do. Do what you love and do best! Good luck and have fun.
@NorthernLaw_
@NorthernLaw_ Жыл бұрын
Glad I don’t use any MSI products. That would be nuts if someone made their own custom firmware from this leaked data. Interested to see where this goes
@Fractal_32
@Fractal_32 Жыл бұрын
I’m more interested in those Intel BootGuard keys, what issues will crop up with those?
@alfonzo7822
@alfonzo7822 Жыл бұрын
Plenty I'd imagine 😅
@yoplait3256
@yoplait3256 Жыл бұрын
Damn, just bought and installed a new msi motherboard like 1 month ago and it's the very first time I've bought anything from them.
@justwentfullchuu2
@justwentfullchuu2 Жыл бұрын
What hardware can be affected by this? I mean, there's MSI gpus but those you update through the Nvidia/Amd software. So Mobos?
@dd0669
@dd0669 Жыл бұрын
Loved the deepfake voice in this video! ALMOST got me.
@midimusicforever
@midimusicforever Жыл бұрын
First thought is, fuck, what's the brand of my motherboard again?! But no, it was on my old computer I had MSI.
@Dreakopotamus
@Dreakopotamus Жыл бұрын
Bios source code would be cool.
@Dreakopotamus
@Dreakopotamus Жыл бұрын
You can already unhide hidden bios setting but making one without the other problems would be perfect
@overcheats4518
@overcheats4518 Жыл бұрын
fr
@jackoneill76
@jackoneill76 Жыл бұрын
Please refrain from calling a criminal “our boy”.
@Soda_Bobinski
@Soda_Bobinski Жыл бұрын
fed
@hyoenmadan
@hyoenmadan Жыл бұрын
I have a question. Can those private Intel/MSI keys be used to disable Bootguard and reprovision Secure Boot root database with our own firmware keys? In any case... Instead going to make new firmware with the leaked code, would be better to just improve Coreboot/UEFI with it.
@heutemalnicht
@heutemalnicht Жыл бұрын
GamersNexus is firing up the renderfarm for a new Video. Back to you, Steve!
@Kabodanki
@Kabodanki Жыл бұрын
Smelling blood in the waters
@Blixxky
@Blixxky Жыл бұрын
Honestly the way they're handling this, they deserve it.
@mikeloeven
@mikeloeven Жыл бұрын
I am hoping some good comes from this in that the modding community can use this to unlock some of the chip set voltage and OC lockouts on the graphic cards
@叵
@叵 Жыл бұрын
why are you not verified
@aunnamedinternetuser9362
@aunnamedinternetuser9362 Жыл бұрын
Watching this video on my MSI laptop. FML.
@RoronoaZorosHaki
@RoronoaZorosHaki Жыл бұрын
Imma be so mad if they didnt include a "May the 4th be with you/Revenge of the 5th" message with this attack.
@Ayyem93
@Ayyem93 Жыл бұрын
I don'y have any MSI hardware but I do have afterburner, should I still look out?
@topleads9748
@topleads9748 Жыл бұрын
Thanks, bro...great video..u rock dude
@mysterium364
@mysterium364 Жыл бұрын
I hope the coreboot team can review the leaked code to be able to reverse engineer and recreate it with enough differences to have plausible deniability.
@arghpee
@arghpee Жыл бұрын
Oh boy! and I have an MSI Mobo.
@meem6227
@meem6227 Жыл бұрын
10:09 "You see what you did was illegal, but it could've been done better if you follow these steps" I love this guy
@33tarot
@33tarot Жыл бұрын
Gotta love electronics news during mercury retrograde.
@Low_cops
@Low_cops Жыл бұрын
can you let us know when the MSI software update comes out to fix things?
@MentalOutlaw
@MentalOutlaw Жыл бұрын
Maybe, I don't own or administer any MSI products though so it's unlikely I'll hear about it very early
@Low_cops
@Low_cops Жыл бұрын
@@MentalOutlaw would it be something they would probably e-mail users about? i would guess no based on thier "press statement" but would there be any way to find out automatically, or just wait? btw, thanks for the response :)
@friendofp.24
@friendofp.24 Жыл бұрын
Yeah. I'm concerned, my PC has an MSI motherboard.
@burnttoast26
@burnttoast26 Жыл бұрын
Throwing my hat in for update notifications
@Brian2
@Brian2 Жыл бұрын
Heyyy the Farming Outlaw is back in the shed working hard on that security.
@cohort6159
@cohort6159 Жыл бұрын
One "problem" is that many makers (Sony for example) remove drivers from their website for unsupported hardware. If it came with Windows 7 for example, it's no longer available for download. So people have to search online to find it. I shouldn't do this but I but old hardware and get it going again and I sometimes do this.
@pontiacg445
@pontiacg445 Жыл бұрын
Even intel does this. I have an old atom motherboard/cpu combo, won't boot latest version of debian. I find I don't have the latest bios version, so I go looking. Intel intentionally deleted it, and left a little note saying they did as much. I found it on some seedy site and updated the bios, it boots now but I can't ever trust it again. I guess Intel would like for me to just throw it away? I bet I can find some hogwash about them being sooo green somewhere on their website... So thanks, Intel and any other manufacturer that's apparently on the brink of bankruptcy from having to host a few kilobytes per product they made. How can they ever deal with that? Inconceivable!! Some third party jank parallel port adapter manufacturer still manages to host their driver files, but not one of the world's largest CPU manufacturers...
@mdioxd9200
@mdioxd9200 Жыл бұрын
Oh no ! I can't source my beloved software updates from my beloved big shiny bright *DOWNLOAD NOW* button... We truly can't have anything anymore these days :(
@TheOtherDylanArts
@TheOtherDylanArts Жыл бұрын
I have received a total of 4 broken motherboards from MSI and there customer support was utterly useless. The basically stole my money. I swore to never use MSI products ever again... Looks like that is serving me well.
@AnarchoTak
@AnarchoTak Жыл бұрын
i just got rid of my old msi graphics card a few weeks ago😅 good timing
@publicguy1664
@publicguy1664 Жыл бұрын
I hate bloat ware, but MSI's Dragon w/e is now a must. I use it to control my RGB settings, but it's clunky and probably is more of a resource hog than it should be, but at least you can trust the updates from it.
@Sidicas
@Sidicas Жыл бұрын
The keys can be revoked at the certificate authority. Seems kind of blown out of proportion.
@tissuepaper9962
@tissuepaper9962 Жыл бұрын
AFAICT at least one of the keys' public key is burnt into hardware with e-fuses.
@nyny
@nyny Жыл бұрын
Kind of dig it, I had an old MSI device with a locked bios and the only guy that put out updates was charging a ton. Maybe now anyone can roll a new bios
@czerskip
@czerskip Жыл бұрын
MSI software is absolutely abysmal. I made a mistake of buying an MSI motherboard years ago, and whether it comes from terrible management or incompetent programmers, they've never been able to produce a remotely reliable piece of software.
@4urawrkr2
@4urawrkr2 Жыл бұрын
L for MSI but I feel bad for end users.
@joshuamaserow
@joshuamaserow Жыл бұрын
If this results in MSI open source BIOS's I will sell my other hardware and just own MSI motherboards. Fingers crossed for core boot on MSI
@Kittingiittung
@Kittingiittung Жыл бұрын
I like how at the end outlaw giving tips to them cause he wants to get it out
@RapturesDelight
@RapturesDelight Жыл бұрын
HeLP! So are MSI motherboards at risk from this hack or only the known laptop product list?
@macktheripper7454
@macktheripper7454 Жыл бұрын
Hey MO did you know mullvad was raided? Not connected with this but thought you’d have put out a video about it
@anonanon3066
@anonanon3066 Жыл бұрын
Congratulations. You are being open sourced. Please do not resist.
@funguy398
@funguy398 Жыл бұрын
But we still get our drivers from official sites and but other programs
@tigey2003
@tigey2003 Жыл бұрын
If Kenny has million number of fans i am one of them . if Kenny has ten fans i am one of them. if Kenny have only one fan and that is me . if Kenny has no fans, that means i am no more on the earth . if world against the Kenny, i am against the world. i love #Kenny till my last breath.. .. Die Hard fan of Kenny . Hit Like If you Think Kenny Best player & Smart In the world
@nelsoncorreia7293
@nelsoncorreia7293 Жыл бұрын
Go Kenny
@highrider9168
@highrider9168 Жыл бұрын
>be google >>Make your own search engine >>>Prioritize SCAMS and SPAM for revenue >>>>"Woah, where did all these scams come from?" 😮
@YuriPetrovich
@YuriPetrovich Жыл бұрын
Another good video. Do one about Nostr
@Prismo2328
@Prismo2328 Жыл бұрын
I believe my pc updated about a week ago, however, idk when the false updates started to surface. Are we for sure certain that only manual BIOS updates are the only concern. As for the firmware updates is it through the update page in the system settings? If so how concern should i be?
@bsdims
@bsdims Жыл бұрын
the mic quality improvement is giving me an internal existential crisis lmao
@sneakycactus8815
@sneakycactus8815 Жыл бұрын
man no motherboard company is safe to go with these days
@Fractal_32
@Fractal_32 Жыл бұрын
Has ASRock been hacked? I don’t believe they have been but I could be wrong.
@friendofp.24
@friendofp.24 Жыл бұрын
​@@Fractal_32 ASRock is notoriously a shit company anyway.
@sneakycactus8815
@sneakycactus8815 Жыл бұрын
@@Fractal_32 not to my knowledge. but what i meant by "no mobo company is safe these days" is everyone seems to have problems with every mobo manufacturer. There is no "go-to" brand for quality assurance like you might find in the PSU space (seasonic being one of the safe choices PSU wise). Gigabyte seems to be the most ragged on (with more than just mobos), ASUS has had quality control issues (now and in the past), ASRock QC issues as well (mainly with low-mid end products), MSI has had a lot of bios issues in the past and several controversies around factories burning down and such. Biostar kinda just exists and i've not seen anything positive or negative about them. EVGA and NZXT also kinda just exist but they are much less prolific in the market.
@Fractal_32
@Fractal_32 Жыл бұрын
@@sneakycactus8815 I personally haven’t had any issues with my ASRock boards. (On socket AM4 and socket AM5) I also don’t do any overclocking since I want stability without having to worry about a 2% gain or something minuscule like that. Motherboard quality has dramatically increased in the many years I have been in the pc building space, now only if postcodes would go on low and mid range boards.
@MyzIcyBeatz
@MyzIcyBeatz Жыл бұрын
ChatGPT refactoring plugin would be insane for turning 'illegal' code into 'legal' code
@blisphul8084
@blisphul8084 Жыл бұрын
What if chatGPT reads the code and outputs how it works, then another ChatGPT writes the code based on that description?
@j2simpso
@j2simpso Жыл бұрын
Thank goodness hackers haven't leaked the KSI source code and keys. Otherwise kiddos would be getting a prime high!
@violatorut2003
@violatorut2003 Жыл бұрын
Great! I just received a $1300 computer from them yesterday!
@KtotheL
@KtotheL Жыл бұрын
Laffable... These companies have all been hacked for years. It's only being acknowledged now because it's being used in other areas. (That exposes the trails back) I've done this a long time and I can honestly say I have never hacked anybody. Can you ?
@Marty_YouTuber
@Marty_YouTuber Жыл бұрын
could the hacker host the files on IPFS peer-to-peer hypermedia protocol? and i don't know how to use i2P so hackers probably should host the files on IPFS or a Torrent Link.
@ScoldAudits
@ScoldAudits Жыл бұрын
I don't know, man, I'm no pc geek by any means, but i consider myself far more tech savvy than your average person, especially for my age (I'm 50), and this is the first time I'm hearing of winget. Will definitely be using it from now on, though, and trying to spread awareness.
@GornubiusFlux
@GornubiusFlux Жыл бұрын
5:35 I am honoured to have made the cut
@cfbmoo1
@cfbmoo1 Жыл бұрын
The more stuff goes online the more easier it is to break in to. Computers went from individual islands of general computing to dumb terminals that provide these companies a SaaS platform to make money off of at the expense of the product (at home users). No you aren't a user of the software that's online, you're a product sold to advertisers. That's why advertisements are starting to show up in Windows 11 and even 10 to some extent.
@casualguydaniel
@casualguydaniel Жыл бұрын
My msi hardware isnt even officially supported anymore, so no worries for me 😅
The EARN IT Act Will Not Protect Children (But Will Destroy Privacy)
19:56
Hackers Bypass Google Two-Factor Authentication (2FA) SMS
12:47
John Hammond
Рет қаралды 1,1 МЛН
规则,在门里生存,出来~死亡
00:33
落魄的王子
Рет қаралды 32 МЛН
Я сделала самое маленькое в мире мороженое!
00:43
Кушать Хочу
Рет қаралды 4,5 МЛН
MY HEIGHT vs MrBEAST CREW 🙈📏
00:22
Celine Dept
Рет қаралды 42 МЛН
Synyptas 4 | Арамызда бір сатқын бар ! | 4 Bolim
17:24
Microsoft Is Decrypting Your Files in The Cloud
8:14
Mental Outlaw
Рет қаралды 233 М.
Darknet OPSEC Bible 2022 Edition
22:13
Mental Outlaw
Рет қаралды 625 М.
Critical IPv6 Bug Found in Windows
9:02
Mental Outlaw
Рет қаралды 130 М.
Microsoft is Turning Windows Into an Advertising Platform
9:21
Mental Outlaw
Рет қаралды 199 М.
How to Get a Private Phone, Number, and Cellular Data
10:00
Mental Outlaw
Рет қаралды 1 МЛН
Feds Couldn't Crack Signal, So They Banned It
8:50
Mental Outlaw
Рет қаралды 582 М.
Mullvad and Tor Linked Up to Make a Web Browser
12:23
Mental Outlaw
Рет қаралды 235 М.
30 Windows Commands you CAN’T live without
14:35
NetworkChuck
Рет қаралды 2,3 МЛН
Is your PC hacked? RAM Forensics with Volatility
14:29
The PC Security Channel
Рет қаралды 915 М.
规则,在门里生存,出来~死亡
00:33
落魄的王子
Рет қаралды 32 МЛН