Is Your Computer at Risk from the Logo Fail Exploit?
- Thread starter WWGD
- Start date
Join the discussion
Registration is free. Ask a follow-up in this thread, or start your own.
6 replies · 2K views
Discussion
Physics news on Phys.org
Mentor
- 15,788
- 10,667
Didn't know this was a thing.
https://arstechnica.com/security/20...e-vulnerable-to-new-logofail-firmware-attack/
Tom's hardware has something on it:
https://www.tomshardware.com/pc-com...-and-is-nearly-impossible-to-detect-or-remove
https://arstechnica.com/security/20...e-vulnerable-to-new-logofail-firmware-attack/
Tom's hardware has something on it:
https://www.tomshardware.com/pc-com...-and-is-nearly-impossible-to-detect-or-remove
Mentor
- 15,788
- 10,667
Forgot to say YIKES!
This exploit is truly scary.
This exploit is truly scary.
Science Advisor
Homework Helper
Gold Member
- 5,020
- 3,264
- Calling LogoFAIL an 'exploit' is misleading (I know it's not your term @WWGD): it is a (series of) vulnerabilities.
- No evidence of any attempted exploit involving LogoFAIL has been published.
- The vulnerability was discovered by a benign research group sometime in 2023 and disclosed confidentially to vendors: when the discovery was made public on 6 December 2023, BIOS patches were published by all vendors (except Phoenix who in an appalling move jumped the gun on 28 November).
- In order to exploit the vulnerability an attacker requires administrator access. Once an attacker has administrator access it is 'game over' as far as security is concerned anyway.
If you follow these two rules you don't need to be afraid of any kind of technical attack on your personal Windows or Mac system*:
- Keep your system up to date with the latest patches of supported software.
- Never allow untrusted software to gain administrator access e.g. by saying 'yes' to the "Do you want to allow this app to make changes to your device" dialog unless you are sure that you can trust the relevant app.
Only in the sense that if you lend someone the keys to your house they can take a copy and then they can let themselves in whenever they want that is 'truly scary' - but if you lend someone the keys to your house they can do whatever they want while they are there anyway.jedishrfu said:This exploit is truly scary.
Much more dangerous and scary, and something you do need to be constantly cautious of because there is very little by way of automatic defence that can be put in place are social engineering attacks.
Scary headlines about technical attack surfaces distract the attention of the public from the real threat.
Last edited:
Science Advisor
Homework Helper
- 7,844
- 13,167
Isn't there
"LogoFAIL is a constellation of two dozen newly discovered vulnerabilities that have lurked for years...."
Fair-enough; I may have jumped the gun. But Jedi's articles refer to it as a vulnerability only:pbuk said:
- Calling LogoFAIL an 'exploit' is misleading (I know it's not your term @WWGD): it is a (series of) vulnerabilities.
- No evidence of any attempted exploit involving LogoFAIL has been published.
- The vulnerability was discovered by a benign research group sometime in 2023 and disclosed confidentially to vendors: when the discovery was made public on 6 December 2023, BIOS patches were published by all vendors (except Phoenix who in an appalling move jumped the gun on 28 November).
- In order to exploit the vulnerability an attacker requires administrator access. Once an attacker has administrator access it is 'game over' as far as security is concerned anyway.
If you follow these two rules you don't need to be afraid of any kind of technical attack on your personal Windows or Mac system*:
* (or Linux if you can be sure of what is 'untrusted software' in this context, and unless you are running a commercial distribution this is very difficult).
- Keep your system up to date with the latest patches of supported software.
- Never allow untrusted software to gain administrator access e.g. by saying 'yes' to the "Do you want to allow this app to make changes to your device" dialog unless you are sure that you can trust the relevant app.
Only in the sense that if you lend someone the keys to your house they can take a copy and then they can let themselves in whenever they want that is 'truly scary' - but if you lend someone the keys to your house they can do whatever they want while they are there anyway.
Much more dangerous and scary, and something you do need to be constantly cautious of because there is very little by way of automatic defence that can be put in place are social engineering attacks.
Scary headlines about technical attack surfaces distract the attention of the public from the real threat.
"LogoFAIL is a constellation of two dozen newly discovered vulnerabilities that have lurked for years...."
JamalGross
- 4
- 7
Malicious actors can embed malware code or instructions within the pixels of an image file without visibly altering the image's appearance. This technique is called steganography. The malware may be hidden within the least significant bits of the image's pixels, making it difficult to detect without specialized tools.
Similar threads
Uploading photos from your computer to instagram?
- ElliotSmith
- · Replies 1 ·
- Computing and Technology
- Replies
- 1
VB6 Simple Lock Program - Easily Secure Your Computer with a Password
- madmike159
- · Replies 6 ·
- Programming and Computer Science
- Replies
- 6