Welcome to DU! The truly grassroots left-of-center political community where regular people, not algorithms, drive the discussions and set the standards. Join the community: Create a free account Support DU (and get rid of ads!): Become a Star Member Latest Breaking News General Discussion The DU Lounge All Forums Issue Forums Culture Forums Alliance Forums Region Forums Support Forums Help & Search

IDemo

(16,926 posts)
Tue Feb 17, 2015, 01:40 AM Feb 2015

Someone (Probably The NSA) Has Been Hiding Viruses In Hard Drive Firmware

The NSA may be hiding payloads in the firmware of consumer hard drives, according to a new report from Kaspersky Lab.

The report tracks a group that researchers have dubbed "Equation," which uses previously undiscovered methods to plant targeted malware in hard drive firmware, where it is difficult to detect or remove. The report found exploits for hard drives made by many of the largest brands in the industry, including Samsung, Western Digital, Seagate, Maxtor, Toshiba and Hitachi. The group is closely tied to Stuxnet, using many overlapping vulnerabilities and techniques over the same time period, and those similarities combined with previously published NSA hard drive exploits have led many to speculate that Encounter may be part of the NSA.

If true, the program would give the NSA unprecedented access to the world's computers, even when disconnected from the larger web. Viruses stored on a hard drive's firmware are typically activated as soon as a device is plugged in, with no further action required. They're also usually undetectable and survive reformatting, making them difficult to detect and remove. In July, independent researchers discovered a similar exploit targeting USB firmware — dubbed BadUSB — but there was no indication of the bugs being developed and deployed at this scale.

It also raises real questions about device manufacturer's complicity in the program. It would take extensive and sustained reverse engineering to successfully rewrite a device's firmware. The NSA would certainly be capable of it, but it's also possible the NSA compelled companies to hand over the firmware code or intercepted it through other means. Reached by Reuters, only Western Digital actively denied sharing source code with the NSA; the other companies declined to comment.

http://www.malaysiandigest.com/technology/542226-someone-probably-the-nsa-has-been-hiding-viruses-in-hard-drive-firmware.html

4 replies = new reply since forum marked as read
Highlight: NoneDon't highlight anything 5 newestHighlight 5 most recent replies
Someone (Probably The NSA) Has Been Hiding Viruses In Hard Drive Firmware (Original Post) IDemo Feb 2015 OP
More here/Reuters Tierra_y_Libertad Feb 2015 #1
Oh, lucky me. dgibby Feb 2015 #3
We are ruled by criminals. woo me with science Feb 2015 #2
I'm supposed to believe Kaspersky got no help from Snowden whatsoever? Blue_Tires Feb 2015 #4
 

Tierra_y_Libertad

(50,414 posts)
1. More here/Reuters
Tue Feb 17, 2015, 02:31 AM
Feb 2015
http://in.reuters.com/article/2015/02/17/usa-cyberspying-idINL1N0VQ0NG20150217

Feb 16 (Reuters) - The U.S. National Security Agency has figured out how to hide spying software deep within hard drives made by Western Digital, Seagate, Toshiba and other top manufacturers, giving the agency the means to eavesdrop on the majority of the world's computers, according to cyber researchers and former operatives.

That long-sought and closely guarded ability was part of a cluster of spying programs discovered by Kaspersky Lab, the Moscow-based security software maker that has exposed a series of Western cyberespionage operations.

Kaspersky said it found personal computers in 30 countries infected with one or more of the spying programs, with the most infections seen in Iran, followed by Russia, Pakistan, Afghanistan, China, Mali, Syria, Yemen and Algeria. The targets included government and military institutions, telecommunication companies, banks, energy companies, nuclear researchers, media, and Islamic activists, Kaspersky said. (reut.rs/1L5knm0)

The firm declined to publicly name the country behind the spying campaign, but said it was closely linked to Stuxnet, the NSA-led cyberweapon that was used to attack Iran's uranium enrichment facility. The NSA is the U.S. agency responsible for gathering electronic intelligence.

A former NSA employee told Reuters that Kaspersky's analysis was correct, and that people still in the spy agency valued these espionage programs as highly as Stuxnet. Another former intelligence operative confirmed that the NSA had developed the prized technique of concealing spyware in hard drives, but said he did not know which spy efforts relied on it.

dgibby

(9,474 posts)
3. Oh, lucky me.
Tue Feb 17, 2015, 09:52 AM
Feb 2015

I just ordered a Western Digital external hardrive for my genealogy programs. On a positive note, whoever's spying on that is going to be bored to tears (except for all the black sheep in the family).

Blue_Tires

(55,445 posts)
4. I'm supposed to believe Kaspersky got no help from Snowden whatsoever?
Tue Feb 17, 2015, 02:04 PM
Feb 2015

And a these coincidences are unconnected?

I'll just leave this here: http://www.wired.com/2012/07/ff_kaspersky/all/

Latest Discussions»General Discussion»Someone (Probably The NSA...