Boot Guard Keys From MSI Hack Posted, Endangering PCs. (Update: Intel Responds)

Intel Boot Guard keys leaked
(Image credit: MSI)

Files purloined during the substantial MSI hack last month have started to proliferate around the dark web. One of the more worrying things spotted among the digital loot is an Intel OEM private key. MSI would have used this to sign its firmware/BIOS updates to pass Intel Boot Guard verification checks. Now hackers can use the key to sign malicious BIOS, firmware and apps, which will look entirely like official MSI releases.

Update (5/8/2023): Intel has now issued a statement, nothing that the keys are generated by the OEM (MSI) not Intel itself.

Latest Videos FromTom's Hardware
Mark Tyson
News Editor

Mark Tyson is a news editor at Tom's Hardware. He enjoys covering the full breadth of PC tech; from business and semiconductor design to products approaching the edge of reason.

  • punkncat
    Is Afterburner going to have issues as a result of this breach?

    For instance, if you had already installed it, you can or cannot trust the auto-updates it wants to do from time to time?
    Reply
  • TechieTwo
    This is why hackers should go to prison for 50 years, be fined millions and lose all personal and business assets to repay those impacted by their hack.
    Reply
  • hotaru251
    punkncat said:
    Is Afterburner going to have issues as a result of this breach?
    most likely not when gotten from official site. Only risk if they can hack update server (which likely isnt gonna be easy as if they knew was risk they'd change up security)

    personally happy im running amd build not intel (so this wont effect me mainly)
    Reply
  • gregss
    Can't the keys which have been leaked be revoked?
    Reply
  • jonathan1683
    gregss said:
    Can't the keys which have been leaked be revoked?
    I was wondering the same, but it might be read only for security. I think if it was possible they would have already done it before the announcement of the breach.
    Reply
  • Alvar "Miles" Udell
    The real problem will be that since laptops are far less likely to receive BIOS updates than desktops, mostly because they're one off things, how many affected machines will never be updated to blacklist the affected keys, assuming they can be anyway? It's always possible their sites are hacked and malware programs inserted in them, like what happened with CCleaner, and even more reasonable that their forums and others are seeded with so called "beta updates" and such from imposters using the stolen keys to install malware.
    Reply
  • derekullo
    TechieTwo said:
    This is why hackers should go to prison for 50 years, be fined millions and lose all personal and business assets to repay those impacted by their hack.
    Hard to repay millions when you are locked in prison for 50 years.
    Reply
  • Kamen Rider Blade
    TechieTwo said:
    This is why hackers should go to prison for 50 years, be fined millions and lose all personal and business assets to repay those impacted by their hack.
    Life in Prison w/o parole options, strip them of all their financial & personal/business assets, be up for "Death Penalty" 'ASAP'.
    Reply
  • digitalgriffin
    Why why why do major companies NOT keep the keys to the company on air gapped systems? Why?!?

    Now they will have to invoke an update invalidating the old keys.

    But what's worse is if a virus gets past av software, it can generate and implant it's own bios and prevent future updates to fix corruption.

    Dumbasses
    Reply
  • digitalgriffin
    gregss said:
    Can't the keys which have been leaked be revoked?
    Yes. But it requires a bios update to do that. 99% of people don't.
    Reply