Saturday, February 21, 2015

Foreign Policy

PC Magazine says Equipment Group malware is impossible to remove from computers. I doubt this is true. As more people look at it, they'll find a way. I don't know why re-flashing the hard drive firmware wouldn't remove it. Still, this illustrates how badly NSA has broken the internet. This malware isn't just deployed against foreigners, though it mainly is. It's also deployed in the US.
"The report said Equation has knowledge of the drives that goes way beyond public documentation released by vendors. Equation knows sets of unique ATA commands used by hard drive vendors to format their products. Most ATA commands are public, as they comprise a standard that ensures a hard drive is compatible with just about any kind of computer.
But there are undocumented ATA commands used by vendors for functions such as internal storage and error correction, Raiu said. “In essence, they are a closed operating system,” he said.
Obtaining such specific ATA codes would likely require access to that documentation, which could cost a lot of money, Raiu said.
The ability to reprogram the firmware of just one kind of drive would be “incredibly complex,” Raiu. Being able to do that for many kinds of drives from many brands is “close to impossible,” he said.
“To be honest, I don’t think there’s any other group in the world that has this capability,” Raiu said."

So hard disk drive vendors are complicit.
"Reflashing the drive, or replacing its firmware, is also not foolproof, since some types of modules in some types of firmware are persistent and can’t be reformatted, he said. "
Darn. This better spark a new hard drive architecture to prevent this activity.

No comments:

Post a Comment