Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

"The Promontory chipset is powered by an internal microcontroller that manages the chip's various hardware peripherals. Its built-in USB controller is primarily based on ASMedia ASM1142, which in turn is based on the company's older ASM1042. In our assessment, these controllers, which are commonly found on motherboards made by Taiwanese OEMs, have sub-standard security and no mitigations against exploitation. They are plagued with security vulnerabilities in both firmware and hardware, allowing attackers to run arbitrary code inside the chip, or to re-flash the chip with persistent malware. This, in turn, could allow for firmware-based malware that has full control over the system, yet is notoriously difficult to detect or remove. Such malware could manipulate the operating system through Direct Memory Access (DMA), while remaining resilient against most endpoint security products."

So because a design was based of a design based of a design it may be vulnerable to all kinds of attacks.

Am i following these assumptions correctly?

Promontory -> ASMedia ASM1142 -> ASM1042 -> these are wrong



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: