I-Intel iqinisekise ubuqiniso bekhodi ye-firmware eputshuziwe ye-UEFI yama-chips e-Alder Lake

I-Intel iqinisekise ubuqiniso be-firmware ye-UEFI namakhodi omthombo we-BIOS ashicilelwe ngumuntu ongaziwa ku-GitHub. Isamba esingu-5.8 GB sekhodi, izinsiza, imibhalo, ama-blobs nezilungiselelo ezihlobene nokukhiqizwa kwe-firmware yamasistimu anamaphrosesa asuselwa ku-Alder Lake microarchitecture, ekhishwe ngoNovemba 2021, yashicilelwa. Ushintsho lwakamuva kakhulu lwekhodi eshicilelwe lwangomhla zingama-30 kuSepthemba 2022.

Ngokusho kwe-Intel, ukuvuza kwenzeka ngenxa yephutha lomuntu wesithathu, hhayi ngenxa yokuphazamiseka kwengqalasizinda yenkampani. Kuphinde kuphawulwe ukuthi ikhodi eputshuziwe imbozwa wuhlelo lweProjekthi Circuit Breaker, oluhlinzeka ngemiklomelo esukela ku-$500 kuya ku-$100000 yokuhlonza izinkinga zokuphepha ku-Intel firmware nemikhiqizo (okusho ukuthi abacwaningi bangathola imivuzo yokubika ngobungozi obutholakala kusetshenziswa okuqukethwe ukuvuza).

Akucaciswanga ukuthi ubani ngempela owaba umthombo wokuvuza (abakhiqizi bemishini ye-OEM nezinkampani ezakha i-firmware yangokwezifiso babenokufinyelela kumathuluzi okuhlanganisa i-firmware). Ukuhlaziywa kokuqukethwe kwengobo yomlando eshicilelwe kwembule ezinye izivivinyo namasevisi aqondene nemikhiqizo ye-Lenovo ("I-Lenovo Feature Tag Test Information', "Lenovo String Service", "Lenovo Secure Suite", "Lenovo Cloud Service"), kodwa ukuzibandakanya kukaLenovo ukuputshuka akukaqinisekiswa. Ingobo yomlando iphinde yembula izinsiza nemitapo yolwazi yenkampani i-Insyde Software, ethuthukisa i-firmware yama-OEM, kanye nelogi ye-git iqukethe i-imeyili evela kwesinye sezisebenzi zenkampani ye-LC Future Center, ekhiqiza amalaptop ama-OEM ahlukahlukene. Zombili izinkampani zibambisana neLenovo.

Ngokusho kwe-Intel, ikhodi etholakala esidlangalaleni ayinayo idatha eyimfihlo nanoma yiziphi izingxenye ezingaba nomthelela ekudalulweni kobungozi obusha. Ngasikhathi sinye, uMark Ermolov, onguchwepheshe ekucwaningeni ukuphepha kwamapulatifomu e-Intel, okhonjwe kulwazi olugciniwe olushicilelwe mayelana namarejista we-MSR angabhalisiwe (Amarejista Akhethekile Emodeli, asetshenziswa, phakathi kwezinye izinto, ekuphathweni kwe-microcode, ukulandelela kanye nokulungisa iphutha), ulwazi mayelana okungaphansi kwesivumelwano sokungadaluli. Ngaphezu kwalokho, kutholwe ukhiye oyimfihlo kungobo yomlando, osetshenziselwa ukusayina i-firmware ngedijithali, okungenzeka isetshenziswe ukudlula ukuvikelwa kwe-Intel Boot Guard (ukusebenza kokhiye akuqinisekisiwe; kungenzeka ukuthi lona ukhiye wokuhlola).

Source: opennet.ru

Engeza amazwana