Gigabyte mobos - Supply Chain Risk from Gigabyte App Center Backdoor

Discussion in 'other security issues & news' started by FanJ, May 31, 2023.

  1. FanJ

    FanJ Updates Team

    Joined:
    Feb 9, 2002
    Posts:
    4,660
    Supply Chain Risk from Gigabyte App Center Backdoor
    By: Eclypsium - May 31, 2023
    https://eclypsium.com/blog/supply-chain-risk-from-gigabyte-app-center-backdoor/



    Wired : Millions of PC Motherboards Were Sold With a Firmware Backdoor
    May 31, 2023 9:00 AM
    https://www.wired.com/story/gigabyte-motherboard-firmware-backdoor/

    Read more at above links!!!
     
  2. nicolaasjan

    nicolaasjan Registered Member

    Joined:
    Sep 23, 2018
    Posts:
    890
    Location:
    The Netherlands
    From the Eclypsium blog:
    So, a Windows only problem. :)
     
  3. anon

    anon Registered Member

    Joined:
    Dec 27, 2012
    Posts:
    8,010
    A list of affected Gigabyte models is available here:
    https://eclypsium.com/wp-content/uploads/Gigabyte-Affected-Models.pdf
     
  4. FanJ

    FanJ Updates Team

    Joined:
    Feb 9, 2002
    Posts:
    4,660
    Maybe a bit off topic:

    I don't understand why Eclypsium is calling this a "Supply Chain Risk".
    Maybe because it is the new "buzz word" (or whatever you want to call it)?
    As far as I understand "Supply Chain" is about:
    Company A --> Company B (etc), where A and B are not the same.
    But isn't it here all the fault of Gygabyte alone?

    Am I now wrong, do I don't understand it right? Maybe it is the way you look at it?
     
  5. Freki123

    Freki123 Registered Member

    Joined:
    Jan 20, 2015
    Posts:
    337
    Maybe you just "compromise gigabyte" and then push an infected bios update so you can do everything you want on other company's pc's that are just unlucky to own a gigabyte mainboard. That would be my guess. I mean updates over an HTTP connection seem :gack:
     
  6. FanJ

    FanJ Updates Team

    Joined:
    Feb 9, 2002
    Posts:
    4,660
    Hi,
    Yes, I understood that.

    But I still would not call this a "Supply Chain" issue.

    OK, you can look at it this way:
    PC Builder A uses components (chips, mobos, etc.) from company B (or maybe some services from company C).
    That is a Supply Chain.
    But think a little bit further:
    That PC Builder A installs Windows from Microsoft. OK, also some Supply Chain in some way.
    But now we have hundreds of security and privacy issues over the years with Windows.
    Are we calling all those security and privacy issues now also a "Supply Chain" risk?
    We could. But if we do, those words "Supply Chain" mean nothing anymore: then those words "Supply Chain" are completely empty, just some bla-bla.

    Please note that I am not criticizing the report by Eclypsium, just only that "Supply Chain".
     
  7. solitarios

    solitarios Registered Member

    Joined:
    Mar 28, 2016
    Posts:
    230
    I think it refers to the application installation center that is in the bios and if you do not disable it, it starts with the system and downloads programs, drivers, etc. for the PC. I've never tested the app but I guess it must have some user interaction to download things other than the Gigabyte bios app. By the way the motherboard I have in my computer is listed. All the best.
     
  8. solitarios

    solitarios Registered Member

    Joined:
    Mar 28, 2016
    Posts:
    230
    BIOS-2023-06-03 103029.png

    Solved.
     
  9. anon

    anon Registered Member

    Joined:
    Dec 27, 2012
    Posts:
    8,010
    Gigabyte Rolls Out Firmware Update to Mend Firmware Backdoor
    https://www.tomshardware.com/news/gigabyte-firmware-update-backdoor
     
  10. anon

    anon Registered Member

    Joined:
    Dec 27, 2012
    Posts:
    8,010
    GIGABYTE Fortifies System Security with Latest BIOS Updates and Enhanced Verification
    Jun 1, 2023
    https://www.gigabyte.com/Press/News/2091
     
  11. anon

    anon Registered Member

    Joined:
    Dec 27, 2012
    Posts:
    8,010
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.