Tuesday, 9 April 2013

AMI Firmware Source Code, Private Key Leaked

Source code and a private signing key for firmware manufactured by a popular PC hardware maker American Megatrends Inc. (AMI) have been found on an open FTP server hosted in Taiwan.
Researcher Brandan Wilson found the company’s data hosted on an unnamed vendor’s FTP server. Among the vendor’s internal emails, system images, high-resolution PCB images and private Excel spreadsheets was the source code for different versions of AMI firmware, code that was current as of February 2012, along with the private signing key for the Ivy Bridge firmware architecture.
AMI builds the AMIBIOS BIOS firmware based on the UEFI specification for PC and server motherboards built by AMI and other manufacturers. The company started out as a motherboard maker, and also built storage controllers and remote management cards found in many Dell and HP computers.

“By leaking this key and the firmware source, it is possible (and simple) for others to create malicious UEFI updates that will be validated and installed for the vendor’s products that use this Ivy Bridge firmware,” wrote Wilson’s research partner Adam Caudill in a blogpost. “If the vendor used this same key for other products, the impact could be even worse.”
Caudill told Threatpost in an email that there are some components missing that would be needed to build an UEFI image, though for someone familiar with the technology, it’s likely a simple process, he said.
“The worst case is the creation of a persistent, Trojanized update that would allow remote access to the system at the lowest possible level,” Caudill said. “Another possibility would be the creation of an update that would render the system unbootable, requiring replacement of the mainboard.”
Firmware updates are tricky and require downtime; updates aren’t usually done unless there are performance or security issues that warrant an upgrade. In short, the impact of this leak could be longstanding.
“This kind of leak is a dream-come-true for advanced corporate espionage or intelligence operations,” Caudill wrote. “The ability to create a nearly undetectable, permanent hole in a system’s security is an ideal scenario for covert information collection.”
The researchers won’t name the vendor, FTP address or release any code, and said they have informed AMI and the vendor involved. Caudill said neither he nor Wilson have received a response.
“This vendor’s lax (non-existent?) security could have much broader repercussions though. For AMI, they now have a major piece of intellectual property freely available for download by competitors,” Caudill wrote. “For users, this code could now be subject to new scrutiny - if a security issue is found in the firmware, it could potentially impact all users whose firmware is based on the leaked code.”
This is the type of situation that has spurred a lot of discussion about supply chain security, in particular, questions about pre-installed hardware manufactured abroad. The 2013 Congressional Appropriations Act signed into law March 26 mandates that NASA, the U.S. Justice and Commerce departments, and the National Science Foundation must formally evaluate the risks associated with purchasing hardware built or put together by companies owned or operating in China.
These agencies are prohibited from buying IT equipment built or assembled in China unless a top official of the Chinese vendor sits down with the FBI or another federal agency and potential cyberespionage risks are assessed, the act said. The head of the assessing agency must then report his findings to the House and Senate Committees on Appropriations and decide whether the acquisition is in the “national interest” of the U.S.
The thinking is that it would be simple for hardware built and installed along the supply chain to contain malicious code that is difficult to detect without a comprehensive and expensive inspection. A report released last year cast suspicion on Chinese network gear manufacturers Huawei and ZTE because of the companies’ close ties with the Chinese government and allegations of security risks with their equipment present inside U.S. telecommunications companies and corporations.
As for AMI, the leak has not only security implications, but could impact the manufacturer’s viability in the market.
“I have no idea why [the unnamed vendor] made this available to the public; it's something that really shouldn't have happened,” Caudill said. In OEM relationships, source code is provided under a strict license to enable optimization for specific systems.  “This is a great example of carelessness that can have significant repercussions. I'm not sure if they didn't realize anonymous access was enabled or if they just didn't realize the implications of making this publicly available.”

Air Force Classifies Some Cybersecurity Tools as Weapons

The United States government for years has been developing and deploying offensive cyber capabilities, most of it done without much in the way of public notice.  That's been changing of late, as government and military officials have become more open in discussing these capabilities and under what circumstances they might be used. Now, the U.S. Air Force has said that it has classified six unnamed tools as weapons, mainly as a way to improve the chances of those tools receiving the funding they need.
The Air Force has emerged as one of the key military branches for offensive and defensive cyber capabilities. The U.S. Cyber Command is the overarching strategic command that's responsible for cybersecurity operations, and it comprises groups from the Army, Navy and Air Force. But it's the Air Force that has become the most vocal and public about its capabilities and intentions when it comes to cybersecurity.
At a conference in Colorado Springs on Monday, an Air Force general said that the branch has now classified six of its cyber capabilities as weapons. The move is an effort to make it easier for the Air Force, and presumably other branches as well, to get funding for these tools.
"It's very, very hard to compete for resources ... You have to be able to make that case," Lt. Gen. John Hyten said during the National Space Symposium, according to Reuters.
The budget process in Washington--always a convoluted and difficult one--has become even more problematic in the last couple of years as the economic environment has deteriorated and financial resources have become scarcer. Classifying offensive cybersecurity tools as weapons opens up a larger pool of money for their development. It is a semantic move that has little, if anything, to do with the tools themselves or how they're used.
The U.S. government has been speaking more openly about its development and use of offensive capabilities, and one aspect of that strategy is the need to secure funding, a constant worry for government officials. Intelligence officials said recently that cybersecurity threats have moved to the top of the heap in terms of dangers to U.S. national security. Constant attacks from state-sponsored groups from a number of countries have targeted U.S. military, government and private-sector networks, looking for valuable data to steal. These attacks have been going on for years, but only recently have they become a major talking point in Washington. The increased rhetoric on this topic from U.S. politicians has angered foreign governments, especially China's, but that hasn't seemed to change the message coming from Washington.
The U.S. and other countries have been using custom tools for offensive operations for many years now, and calling them weapons only changes the conversation in Washington, not the reality of their use.