I-NSA iza kusebenza kwiCoreboot, indawo evulekileyo engenye kwi-BIOS kunye ne-UEFI

Kwiiveki ezidlulileyo omnye woogxa bethu apha kwibhlog Uthethe ngomsebenzi kaSlimbook wokuphumeza iCoreboot kwiikhompyuter zabo, apho ngenxa yesininzi sabasebenzisi bayo abazicelileyo, uSlimbook umamele umnxeba wabo (ungafunda inqaku elipheleleyo kule khonkco).

Kulungiselelwe abo bangaziyo ngeCoreboot, kufuneka bayazi ukuba le yindlela evulekileyo engenye kwinkqubo yesiqhelo ye-I / O yesiqhelo (BIOS) esele ikho kwii-PC ze-MS-DOS 80s kwaye iyitshintsha nge-UEFI (Unified Extensible). Firmware interface) yakhululwa ngo-2007 Ngoku i-NSA iqalile ukwabela abaphuhlisi kwiprojekthi yeCoreboot.

U-Eugene Myers we-NSA uqalile ukubonelela ngekhowudi yokuphumeza ye-SMI Transfer Monitor (STM) ejolise kwi-x86 CPUs.

U-Eugene Myers usebenzela iQela loPhando lweeNkqubo ezithembakeleyo ze-NSA, iqela, ngokwewebhusayithi ye-arhente, elijolise "ekukhokeleni nasekuxhaseni uphando kubuchwephesha kunye neendlela ezizakukhusela iinkqubo zolwazi zaseMelika."

I-STM yi-hypervisor eqala kwimowudi "yoLawulo lweNkqubo" (SMM), indawo eyodwa "yentsimbi -2" apho ukwenziwa kwesiqhelo kwenkqubo yokusebenza kuphazanyiswa ukuze ikhowudi yenkqubo (, ulawulo lwehardware, njl. ziqhutywa ngamalungelo aphezulu.

Ifemu ikhuphe imigaqo ye-STM (Uhlobo lwe-VMM olusingatha oomatshini ababonakalayo abaqulathe ikhowudi ye-SMM) kunye namaxwebhu enkalo yokhuseleko lwe-STM firmware ngo-2015.

Ekuqaleni, i-STM bekufanele ukuba isebenze ngokukhutshwa kwe-Intel TXT, kodwa imigaqo yamva nje ivumela i-STM ukuba isebenze kuphela nge-Intel Virtualization Technology (VT). I-TXT yayingonelanga ukukhusela ezi nkonzo ngokuchasene nokuhlaselwa kwaye i-STM ijonge ukwenza njalo.

Ngaba i-NSA isebenza kwiiprojekthi zomthombo ovulekileyo?

I-NSA sele isebenze kwiiprojekthi zokhuselo ezivulelekileyo kuluntu, kubandakanya ukhuseleko lweLinux, imodyuli yokhuseleko yeLinux.

Ukugxekwa kokusebenza kwe-NSA kuninzi kwaye kuhlala kunjalo. Ke ngoko, kunqabile ukuba i-Arhente yoKhuseleko yeSizwe ibulele igalelo layo eluntwini.

Nangona kunjalo, kwimeko yenye yeeprojekthi zomthombo ovulekileyo woluntu, iya kusetyenziswa ukunceda abasebenzi beCoreboot.

Ukucaciswa ngakumbi, i-NSA ikhuphe isixhobo sobunjineli esibuyela umva njengesixhobo kwaye samkelwe ngabaphuhlisi beCoreboot.

Umbono kukuba isoftware ye-NSA iyakunceda iProjekthi yeCoreboot. Ngokukodwa, kwi-firmware yeReverse Engineering.

IGhidra sisakhelo sobunjineli esingagungqiyo iphuhliswe liCandelo loPhando le-NSA yeNSA yoKhuseleko loKhuseleko. Iququzelela uhlalutyo lweekhowudi ezinobungozi kunye ne-malware, ezinjengeentsholongwane kwaye ivumela iingcali ukuba ziqonde ngcono ukuba sesichengeni kwenethiwekhi kunye neenkqubo zazo.

Yonke ikhowudi yeCoreboot, kubandakanya yonke imirhumo ye-STM evela kwi-NSA, ngumthombo ovulekileyo. Kwithiyori, wonke umntu unokuqinisekisa ukuba akukho zingcango zangasemva.

Kuba le projekthi ayiveli kwi-NSA, kodwa iprojekthi abakhethe ukufaka isandla kuyo. Ke ngoko, ngababhali beCoreboot abanoxanduva lokwamkela okanye ukungamkeli iminikelo evela kwi-NSA.

Kodwa xa kusenziwa, i-NSA ibinokubhala ikhowudi ingakhuselekanga ngobunzima bokufumana ubungozi ngaphandle kophando olunamava kwezokhuseleko. Ngenye indlela, unokuluxhaphaza olu setyenziso kwiminyaka kamva, emva kokuba ukubekwa kweliso kunciphile.

Kuba ngekhe kumangalise ukubona olu hlobo lwesenzo luvela kwiarhente efana ne-NSA.

Ukusukela ukuba i-NSA kutshanje izame ukuhambisa ii-algorithms ezimbini ze-cryptographic kwinkqubo yokumiselwa kwe-ISO, ii-algorithms zaye zaliwa kakhulu ngabavavanyi ngenxa yokunqongophala kokuthembela kunye nokusilela kwe-NSA ukuphendula imibuzo ethile yobuchwephesha.

Okokugqibela, abo banomdla wokwazi inkqubela phambili yeprojekthi, banokujonga koku Kule khonkco ilandelayo. 


Shiya uluvo lwakho

Idilesi yakho ye email aziyi kupapashwa. ezidingekayo ziphawulwe *

*

*

  1. Inoxanduva lwedatha: I-AB Internet Networks 2008 SL
  2. Injongo yedatha: Ulawulo lwe-SPAM, ulawulo lwezimvo.
  3. Umthetho: Imvume yakho
  4. Unxibelelwano lwedatha: Idatha ayizukuhanjiswa kubantu besithathu ngaphandle koxanduva lomthetho.
  5. Ukugcinwa kweenkcukacha
  6. Amalungelo: Ngalo naliphi na ixesha unganciphisa, uphinde uphinde ucime ulwazi lwakho.

  1.   ukuyeka sitsho

    Ndiyathetha, ngokwenene? kwaye baya kuyithemba?

  2.   Ingelosi kaMiguel sitsho

    Into yokugqibela anokuze ayenze kukuthemba isoftware ye-NSA kunye "neenjongo zayo ezilungileyo" Ezi arhente zeentlola kufuneka zithintelwe ekunikeni isoftware yasimahla kuba bayayonakalisa.