"Security Breaches Plague Intel and MSI, Raising Supply Chain Attack Concerns"

1 min read
Source: Ars Technica
"Security Breaches Plague Intel and MSI, Raising Supply Chain Attack Concerns"
Photo: Ars Technica
TL;DR Summary

The leak of MSI's private encryption keys, including the signing key used to verify the authenticity of firmware updates, has raised concerns of devastating supply chain attacks. Unlike larger hardware makers, MSI doesn't have an automated patching process or key revocation capabilities, making it difficult to revoke compromised keys. The leak also included a private encryption key used in a version of Intel Boot Guard that MSI distributes to its customers, which could allow attackers to bypass security measures and gain far-reaching access to systems. MSI has yet to issue guidance to its customers.

Share this article

Reading Insights

Total Reads

0

Unique Readers

0

Time Saved

6 min

vs 6 min read

Condensed

92%

1,19594 words

Want the full story? Read the original article

Read on Ars Technica