https://www.theregister.com/2022/03/05/nvidia_stolen_certificate/ [user] [user] Sign in The Register(r) -- Biting the hand that feeds IT [magn] [burg] [burg] Topics Security Off-Prem All Off-PremEdge + IoTChannelPaaS + IaaSSaaS (X) On-Prem All On-PremSystemsStorageNetworksHPCPersonal Tech (X) Software All SoftwareAI + MLApplicationsDatabasesDevOpsOSesVirtualization (X) Offbeat All OffbeatDebatesColumnistsScienceGeek's GuideBOFHLegalBootnotesSite NewsAbout Us (X) Vendor Voice All Vendor VoiceAdobeAmazon Web Services (AWS) MigrationGoogle Cloud Google Cloud's ApigeeGoogle WorkspaceNutanixRapid7SophosVeeam (X) Resources * Whitepapers * Webinars * Newsletters Situation Publishing * The Next Platform * Devclass * Blocks and Files Get our Weekly newsletter [front] Security Leaked stolen Nvidia cert can sign Windows malware 70k staff email addresses and NTLM password hashes also dumped online Gareth Corfield Sat 5 Mar 2022 // 04:09 UTC 15 comment bubble on white --------------------------------------------------------------------- 15 comment bubble on white # reddit Twitter Facebook linkedin WhatsApp email [https://www.theregis] Copy An Nvidia code-signing certificate was among the mountain of files stolen and leaked online by criminals who ransacked the GPU giant's internal systems. At least two binaries not developed by Nvidia, but signed this week with its stolen cert, making them appear to be Nvidia programs, have appeared in malware sample database VirusTotal. This leak means sysadmins should take steps, or review their security policies and defenses, to ensure code recently signed by the rogue cert is detected and blocked as it is most likely going to be malicious. This can be done through Windows configuration, network filtering rules, or whatever you use to police your organization. [front] Computer security bod Bill Demirkapi - who we've featured before on these pages - tweeted a warning about the certificate potentially being able to be used to sign Windows kernel-level driver files: As part of the #NvidiaLeaks, two code signing certificates have been compromised. Although they have expired, Windows still allows them to be used for driver signing purposes. See the talk I gave at BH/DC for more context on leaked certificates: https:// t.co/UWu3AzHc66 pic.twitter.com/gCrol0BxHd -- Bill Demirkapi (@BillDemirkapi) March 3, 2022 In later tweets he added that Windows will accept drivers signed with certificates issued prior to July 29, 2015 without a timestamp. Microsoft's Windows driver signing policy corroborates this, stating the operating system will run drivers "signed with an end-entity certificate issued prior to July 29th 2015 that chains to a supported cross-signed CA". The leaked Nvidia certificate is just such a creature, having expired in 2014. Code signed with this cert will, in the right conditions, be accepted by Windows even though the certificate has expired. Another Nvidia cert was leaked though expired after the cut-off date. [front] [front] We asked Microsoft what steps would it be willing to take to ensure Windows blocks all code signed by the 2014 cert since its leak. A spokesperson told us: "We are looking into these new claims and we will do what is necessary to keep our customers protected." Infosec bod Kevin Beaumont spotted some folks have been signing their own driver code with Nvidia's private 2014 cert and uploading it to VirusTotal to check if antivirus scanners accepted it. He posted on Twitter: VirusTotal search if you want 'em ls:"2022-03-01T00:00:00+" signature:43BB437D609866286DD839E1D00309F5 p:1+ tag:signed .sys (drivers) load fine in Windows 10/11 still, even when signed with expired cert. Threat actors started on 1st March, a day after torrent posted. pic.twitter.com/S6pCfgV8hb -- Kevin Beaumont (@GossiTheDog) March 4, 2022 The move to allow such drivers was a backwards compatibility effort (per an MSDN post from 2015, introducing Windows 10 build 1607) to prevent a then-new Windows 10 feature from causing problems with previously unsigned drivers. We note that a good number of antivirus scanners, tested by VirusTotal on uploaded samples, are now seemingly catching code signed by the rogue Nvidia certificate, so it may be that your AV engine will automatically block it. * Data stolen from Nvidia, blueprints leak threatened * Nvidia, Apple noticeably absent from Intel-led chiplet interconnect collaboration * Conti ransomware gang leak: 60,000 messages online * Insurance giant Aon confirms it has suffered 'cyber incident' The crooks who compromised Nvidia's internal systems to steal and leak the certificate - among many other files, including credentials, secret source code, and documentation - call themselves Lapsus$, and are seemingly trying to blackmail Nvidia into removing cryptomining limit from its GPU firmware. Last year, for its RTX 30-series graphics cards, Nvidia introduced a technology into their drivers called Lite Hash Rate, or LHR for short. LHR cripples cryptocurrency mining. By nerfing the cards' cryptomining performance, Nvidia hoped to make its graphical processing units less attractive to miners, leaving more hardware available to gamers, in theory, and others who actually want graphics performance rather than pure hash rates. [front] Lapsus$, according to the group's Telegram page, are threatening Nvidia with the public release of more internal materials and details of chip blueprints unless the company promises to remove LHR. It seems wholly implausible that Nvidia would give in to such blackmail. The gang also wants Nvidia to open-source its drivers for Macs, Linux, and Windows PCs. According to Have I Been Pwned, within the leaked data are "over 70,000 employee email addresses and NTLM password hashes, many of which were subsequently cracked and circulated within the hacking community." In a statement Nvidia previously said: "We are aware that the threat actor took employee passwords and some Nvidia proprietary information from our systems and has begun leaking it online. Our team is working to analyze that information." It is maintaining an incident response page here. (r) Get our Tech Resources # Share reddit Twitter Facebook linkedin WhatsApp email [https://www.theregis] Copy 15 Comments Similar topics * Cryptocurrency * Nvidia Narrower topics * Bitcoin * Crypto.com * Ethereum Corrections Send us news --------------------------------------------------------------------- [front] Other stories you might like * Photonics startup Luminous Computing bags $105m Bill Gates among those plowing funds into AI supercomputing tech Jeff Burt Sat 5 Mar 2022 // 01:27 UTC 2 comment bubble on white Luminous Computing, a startup using photonics to drive artificial intelligence, has raised venture capital backing, pulling in $105m in Series A funding from a range of investors that includes Microsoft co-founder Bill Gates. The Bay Area upstart, founded in 2018, announced the funding round, which included such firms as Gigafund, 8090 Partners, Third Kind Venture Capital, Alumni Ventures Group and Strawberry Creek Ventures. It adds to the $1m in pre-seed money the company received in 2018 and the $9m in seed funding pulled in a year later. Luminous officials said the new cash will be used to double the size of the company's engineering team and the build-out of its custom chips and software, as it ramps toward commercial-scale production. It also is continuing to recruit photonics designers, digital and analog very large-scale integration (VSLI) engineers, packaging and system integration engineers and machine learning experts. Continue reading * Russia's invasion kicks Senate into cybersecurity law mode Critical infrastructure, federal agencies must report intrusions, ransomware payments within hours, draft rules state Jeff Burt Sat 5 Mar 2022 // 00:40 UTC 12 comment bubble on white Russia's invasion of Ukraine, and the possibility that the Kremlin may escalate its cyberespionage against the West after being heavily sanctioned, has convinced the US Senate to unanimously pass a bipartisan cybersecurity bill. This draft law would, among other steps, force critical infrastructure companies to report attacks and ransomware payments. The Strengthening American Cybersecurity Act of 2022, which now goes to the House, would put into law some of the regulations the Biden Administration and some members of Congress have been advocating for since the onslaught of high-profile ransomware attacks last year, including those on such companies as Colonial Pipeline and meat processor JBS Foods. Continue reading * Chinese rocket junk may have just smashed into Moon Details still up in the air, unlike whatever hit our natural satellite Katyanna Quach Fri 4 Mar 2022 // 23:17 UTC 26 comment bubble on white A chunk of Chinese space junk today crashed into the far side of the Moon, according to a maker of astrometry software. The trash is believed to be a spent Long March 3C rocket booster from the launch of Chang'e 5-T1, a Chinese experimental robotic spacecraft that lifted off in 2014. The leftover component was estimated to have smashed into the Moon at 1225 UTC on Friday, after hurtling through space at 5,800 miles per hour. We're not sure of the timing because debris at such altitudes isn't usually tracked by agencies, such as the US Space Force, according to Planetary Society member Bill Gray, who develops software for professional astronomers and first predicted the impact. Gray said he started tracking the debris in his spare time after an astronomer at NASA alerted him a few weeks ago to something that seemed, in Gray's words, "suspiciously large." Continue reading * Internet backbone Cogent cuts Russia connectivity Biz cites 'unwarranted and unprovoked invasion of Ukraine' ... also crippling sanctions Chris Williams, Editor in Chief Fri 4 Mar 2022 // 20:58 UTC 23 comment bubble on white Cogent Communications will pull the plug on its connectivity to customers in Russia in response to President Putin's invasion of Ukraine. The US-based biz is one of the planet's largest internet backbones - the freeways of the internet - and says it carries roughly a quarter of global 'net traffic. Its clients range from small businesses to mobile carriers and broadband ISPs. Cogent's role is to pipe hundreds of terabits of your internet data around the world every second. Russian state-owned Rostelecom is among the dozens of customers Cogent has in the country. Continue reading * GNOME, Mono, Xamarin founder Miguel de Icaza leaves Microsoft Departure follows GitHub CEO exit Liam Proven in Prague Fri 4 Mar 2022 // 18:59 UTC 6 comment bubble on white Just months after Nat Friedman quit as CEO of Microsoft-owned GitHub, his Xamarin co-founder has also ejected from the Windows giant. Miguel De Icaza joined Microsoft when it acquired Xamarin in 2016, which marked the beginning of a change in Redmond's mobile strategy. He has spoken to The Reg before about how different Microsoft is today from its notoriously FOSS-averse past. De Icaza has long been a pivotal figure in the areas of Linux and Linux-Microsoft interoperability. He was the original founder of the GNOME desktop project in 1997, along with Federico Mena. A couple of years later, he started Helix Code with Nat Friedman. Subsequently renamed Ximian, the company developed the GNOME email client Evolution and the Ximian Connector, which enabled Evolution to talk to Microsoft Exchange Server. Continue reading * Microsoft says hello again to China, goodbye to Russia Middle Kingdom gets another Azure region, Putin gets the middle finger Dan Robinson Fri 4 Mar 2022 // 17:42 UTC 20 comment bubble on white Microsoft has opened a fifth Azure region in China with one hand while putting a stop to new sales in Russia with the other. The Redmond software giant declared today that its new Azure region in North China went live with unrestricted access for customers on 1 March, with capabilities including hybrid and multi-cloud deployment, IoT, edge computing, and data intelligence. As well as the Azure region, Microsoft said it is adding a set of services that are new to the China market. Among these are support for Azure availability zones to ensure resilience of applications, with Microsoft offering a 99.99 per cent SLA for virtual machines across two or more availability zones in this case. Also new is Azure Arc, which extends Microsoft's Azure Resource Manager to other platforms such as Windows and Linux servers and virtual machines hosted outside of Azure. Continue reading * Russia scrambles to bootstrap HPC clusters with native tech Don't send a mobile chip to do a high-end CPU, GPU job. Unless you have no choice. Nicole Hemsoth Fri 4 Mar 2022 // 16:16 UTC 14 comment bubble on white With the largest data center chipmakers locking Russia out of next-generation devices, not to mention the withdrawal of mobile and software makers from that market, it is no surprise Russian researchers are on the fast track to develop ways around the new technologies that will drive the rest of the world. This is important in the Russian context now, but these efforts are likely to spur similar efforts in China, which is also no stranger to sanctions of the tech variety - as we've seen in cases like Huawei, for instance. The US government last week blocked key technology exports, including semiconductors, to Russia after the invasion of Ukraine. Chipmakers complying with the US export controls include AMD, Intel, TSMC, and GlobalFoundries, at least, with all suspending shipments of products to Russia. Dell, HP, and Lenovo have also stopped shipping products to the country, and Oracle and SAP suspended their business last night. Continue reading * BBC points Russians to the Tor version of itself Back to the future with short wave radio, plus Russia drop internet Iron Curtain Gareth Corfield Fri 4 Mar 2022 // 15:30 UTC 57 comment bubble on white Russia has reportedly blocked access to Western media outlets including the BBC to netizens within its borders, as suspicions rise that the country has begun implementing a "splinternet" plan to seal itself off from the wider internet. This morning the British state broadcaster declared it had been blocked from inside Russia, using also-blocked Twitter to spread the news among Westerners, and signposted web users to a long-forgotten Tor mirror of itself. The BBC launched two new shortwave frequencies in the region earlier this week to broadcast four hours of World Service English news a day. These frequencies can be received clearly in Kyiv and parts of Russia. The Beeb is not alone; other Western news outlets including Germany's Deutsche Welle, Voice of America, US-sponsored Radio Free Europe and others have also been blocked. Continue reading * Backblaze report finds SSDs as reliable as HDDs But warns sample size is a bit small to leap to big conclusions Dan Robinson Fri 4 Mar 2022 // 14:30 UTC 13 comment bubble on white Backblaze has published the first SSD edition of its regular drive statistics report, which appears to show that flash drives are as reliable as spinning disks, although with surprising failure rates for some models. The cloud storage and backup provider publishes quarterly and annual Drive Stat reports, which focused exclusively on rotating hard drives until last year. Backblaze said it will initially publish the SSD edition twice a year, but that this may change depending on how valuable readers find it. The 2021 Drive Stats report was published in February. In a blog post detailing the latest probing, Backblaze cloud storage evangelist Andy Klein said the SSDs are all used as boot drives in the firm's storage servers, and that Backblaze only began using SSDs this way from Q4 of 2018. He pointed out the drives do more than just boot the servers, they also store log files and temporary files produced by the servers, and so each SSD will read, write, and delete files depending on the activity of the server during the day. Continue reading * Deutsche Bank seeks options as sanctions threaten Russian dev unit No data or code stored in Moscow and St Petersburg tech operations, bank says Lindsay Clark Fri 4 Mar 2022 // 13:23 UTC 33 comment bubble on white International trade sanctions threaten to cut off Deutsche Bank from its near-shore IT support and software development unit in Russia following the invasion of Ukraine. The global bank's Russian technology centre employs around 1,500 staff, including software developers and systems maintenance experts who work on its global trading business and main corporate banking system. According to The Financial Times, the EUR25bn revenue bank is weighing up options as sanctions threaten to cut off the centre of expertise from the rest of its operations. Continue reading * NHS Digital's demise bad for 55 million patients' privacy - ex-chairman IT and data arm now part of NHS England, which could be pressured into data sharing without proper oversight Lindsay Clark Fri 4 Mar 2022 // 11:53 UTC 32 comment bubble on white Ten months after attempts first began to extract the medical information of 55 million citizens in England, NHS Digital's former chairman is warning the merger of the agency with NHS England threatens the privacy of people's personal data. Continue reading ABOUT US* * Who we are * Under the hood * Contact us * Advertise with us MORE CONTENT* * Latest News * Popular Stories * Forums * Whitepapers * Webinars SITUATION PUBLISHING* * The Next Platform * DevClass * Blocks and Files * Continuous Lifecycle London * M-cubed Situation Publishing The Register - Independent news and views for the tech community. Part of Situation Publishing SIGN UP TO OUR DAILY NEWSLETTER Subscribe Twitter Facebook LinkedIn feeds no-js Biting the hand that feeds IT (c) 1998-2022 Do not sell my personal information Cookies Privacy Ts&Cs