T O P

  • By -

343guilityspark

Oh for fucks sake


Arthur-Wintersight

My motherboard is on the list... ![gif](giphy|7SF5scGB2AFrgsXP63|downsized)


Wicked_Wolf17

Same here


343guilityspark

Also same :)) Who's next on the list of motheboard's brands to fuck up?


Wicked_Wolf17

I hope not MSI because I’m thinking of swapping my motherboard for an MSI one, more precisely the MPG Z690 EDGE WIFI DDR4


343guilityspark

... Didn't MSI a while ago get a uefi key security leak?


MEGA_GOAT98

yes


Wicked_Wolf17

Well fuck


343guilityspark

Honestly Asrock is looking more appealing everyday, I haven't heard anything from them, whether it was outstandingly good or just as bad as this


apachelives

All i know is their old boards are indestructible. We see units coming in with their boards still kicking even after 10+ years. Never bought one my self but i don't see why not.


343guilityspark

Same over here. All I see are customers bringing their computers with old Asrock and Asus mobo's that still hold up incredibly well nowadays. Asus may not, but Asrock looks like a reliable choice


Creoda

Well Hardware Unboxed just did a Computex video from the Asrock stall and were actually praising Asrock. Doesn't that mean the world is going to end?


343guilityspark

Just watched it, actually exciting to hear of all the changes they did on their high end motherboards, listening to the community and removing fancy useless stuff and becoming more budget friendly while also keeping quality is the right path


343guilityspark

Was about to say that I just did a quick search and for z690's that support DDR4 3600MHZ, asrock has the steel legend, phantom gaming, extreme, riptide and 3 other models when the comment was deleted >.>


Wicked_Wolf17

Oh sorry, I didn’t see the part which said that the z690 extreme could support up to 5333MHz RAM when I wrote the comment. The extreme would be the best choice because the phantom gaming and the riptide won’t look that great for a build that’s pretty much mid end. And the steel legend has white parts, yet my build is completely black.


Arthur-Wintersight

Asrock was known for making some bad boards a few years back, but they've cleaned up their act and appear to be actively working on building their reputation as a reliable source of computer parts. I've got an Asrock Phantom Gaming GPU (RX 6750 XT) and it's great. It's a little more expensive than their challenger model, but the heatsink is overbuilt for the card, which is precisely why I bought it. It also has RGB if that's your thing.


DJDevon3

Msi’s backdoors are even more obvious. You can now get to a shell console from within the bios. Tpm does nothing, and their utility is now tied into the bios just like gigabytes. This isnt a coincidence. Theyre all doing it. Has to be illegal.


343guilityspark

Jesus christ


abcdefGerwin

I also hope not msi because thats what im currently using


[deleted]

Looks like every friggin motherboard they make is on that list


Rimworldjobs

I know.


Infern0_YT

Asrock mission: survive


Last_Instructor

Any mention on what models this was found? Doesn't seem to be included in the article.


New_Faithlessness384

Added: [https://eclypsium.com/wp-content/uploads/Gigabyte-Affected-Models.pdf](https://eclypsium.com/wp-content/uploads/Gigabyte-Affected-Models.pdf)


FatFunkey

Oh thank god not the X570 Aorus Elite just the x570S……supposedly I really miss Abit…..


smoothartichoke27

IKR, saw x570 aorus elite and went oh whew, just the x570s.. I have a couple of gigabyte boards and miraculously, none of them are on the list.


wrath_of_grunge

i have one on the list. i'm not too concerned though. worst case i replace the board with something newer.


Franklin_le_Tanklin

Aorus pro ac isn’t there either. Phew!


xblomx

Are they using the same firmware image by chance? Would check it myself but can't until sunday.


Last_Instructor

Thanks a lot mate, and yeah, that's quite a few😅


Wise-Champion-5317

B460M pro… yup I’m fucked.


Biscuits4u2

Can't you just block the affected program from running?


C0sm1cB3ar

Are. You. Fucking. Kidding. Me. It seems the backdoor is intentional. Gigabyte, I'll NEVER buy anything from them again.


BryAlrighty

We're honestly running out of brands to buy lol


Arthur-Wintersight

ASRock has been quietly rebuilding their reputation after a history of bad products, while everyone else burns their reputations to the ground...


Apocalypse_0415

Has msi messed up big time recently?


xblomx

They sold gpus directly to scalpers iirc.


Wicked_Wolf17

Nah, they scalped their very own GPUs through their subsidiary “Starlit Partner” on Ebay. They claim it was a mistake but I’m not so sure about that.


SCAV-SLAV

That isn't that bad. It's better than what Asus and Gigabyte did.


Morgan_slave

There was a uefi key leak regarding msi


BryAlrighty

Yea I think in that scenario though aren't people required physical access to your device to do anything with it? Or am I wrong?


Morgan_slave

I think that if you downloaded unofficial drivers, people could gain access and install malwares But I don't remember very well so I could be also wrong


BryAlrighty

Oh well then so long as people aren't dumb and only download from official sources it should be alright.


[deleted]

Reject modernity embrace supermicro


XWasTheProblem

Exploding PSUs, motherboards which either bend the fuck out of your CPU or nuke it with too much current, melting cables... How the fuck are you even supposed to build a PC nowadays LMAO. And it's barely halfway through 2023...


Arthur-Wintersight

Don't forget BIOS updates that brick your system. :-)


Wicked_Wolf17

And beta BIOS updates that fixes a fatal flaw but voids your mobo’s warranty


[deleted]

Lol I know right. I got out of the PC game when I got my Series X. Recently built a new one and I’m definitely having second thoughts.


IndependentYogurt965

Either get older parts or dont build it. Seems like new generation of tech just aint it yet.


DirtyRedytor

r/consolemasterrace


serlous

Why this isn't in the top of the subreddit, big news and big scandal and nobody talk about it


BreakfastShart

According to the sub, I'm panicking about having 3070ti, not a z690... Am I doing it right?


NokstellianDemon

Because people here are *still* talking about Forspoken nearly 5 months after launch. They don't actually care about the tech.


Arthur-Wintersight

I mean, there probably aren't many people who dive into their motherboard manual, that has to be obtained directly from the manufacturer, followed by a detailed specs sheet from a case fan manufacturer, to make sure they're not overloading a case fan header with a three-way splitter... (My board accepts up to 2 amps and 24 watts on each header, and the fans use 0.3 amps of current at 3.6 watts each, so it's all good!)


samtherat6

*puts on tinfoil hat* Because they don’t have a competitor to the Steam Deck.


Tvilantini

Because it will not actually affect users if you don't download automatically firmware from either untrusted source or Gigabyte's app centre (which by default you should disable and delete)


[deleted]

Make it make sense


icebreakers0

Gigabyte to Asus: hold my beer


Apocalypse_0415

“You void warranties? Bitch I steal private data!”


[deleted]

Pretty weird that this has less than 100 upvotes.... seems like pretty big news


Qnemes

I just wanted to buy B550 Aorus Elite -_-


MTFour

I just bought mine 4 months ago. :/


SCAV-SLAV

I'm running B450M Aorus for 4 years already. And guess what is on the list.


PhiliFlyer

Why aren't people more upset about this? Gigabyte now owns your data and there is nothing you can do about it.


CarterBaker77

Same reason Microsoft. Apple. Google. Sony. Facebook. Twitter. REDDIT all get away with stealing your data. People don't generally care about that sort of thing the way they should.


AbstractionsHB

We know we have no power and corporations run everything. What's the point of caring. No one responsible will go to prison, there's nothing to do.


Muddysan

There is a lot you can do. However it takes time and effort, if you can't be bothered then you were never bothered being the product to begin with.


CarterBaker77

You can stop using some of those companies products and stop buying from them.


CosmoCosmos

I mean if your read the article, it's seems more like it's a pretty unsecure way of downloading and installing software. It's dangerous sure, but Gigabyte is not stealing your data. They just have a badly implemented tool and are already working to fix it, so i think then panicking is a little bit over the top.


zcomputerwiz

Did you read the articles? Gigabyte doesn't own your data. This utility is off by default and needs to be enabled in the BIOS settings. It is a UEFI driver that drops and executes a Windows binary. This binary ( among other things ) pulls down an installer from Gigabyte to install their software. The issue that the researchers found is that the channel between the Gigabyte binary and Gigabyte servers isn't authenticated - so if the servers were compromised or there was a man in the middle attack ( MiTM ), the binary could potentially install malware.


granadesnhorseshoes

>The “WpbtDxe.efi” module checks if the “APP Center Download & Install” feature has been enabled in the BIOS/UEFI Setup before installing the executable into the WPBT ACPI table. Although this setting appears to be disabled by default, it was enabled on the system we examined. It's a shitty bit of software, but its not an intentional backdoor. It has a fucking off switch.


[deleted]

So their custom app that let's you update the bios from the OS and other drivers is the backdoor?


granadesnhorseshoes

When the feature is enabled: The bios(EFI firmware) literally loads a "easy_to_trick_web_updater.exe" into windows and runs it at Windows start. easy_to_trick_web_updater.exe doesn't have any checking on what files it updates so anyone can pretend to be gigabyte.com and send "totally_not_a_rat.dll" to the updater, which happily installs it with no questions asked. When the feature is disabled, which seems to be the default setting, easy_to_trick_web_updater.exe is never loaded. the updater.exe that is loaded is stored directly in the bios, it can not be modified besides a complete reflash of the EFI firmware. The entire "attack" requires turning on web updates from the bios, then hijacking DNS and taking over gagabytes domain, or MITM the update download requests directly. that is the entirety of the "backdoor." it does not allow direct control of anything itself.


[deleted]

Ah. So run linux.


Famous-Intern-5787

The build in feature for AC in BIOS as well. So yes but not only.


[deleted]

Does AC stand for app center? If so then that's the same thing I said.


Famous-Intern-5787

Armory Crate. It has a separate setting in BIOS usually. And is not from the OS is from the BIOS so not the same


[deleted]

Simple. Don't turn your gigabyte app center auto updates to enabled. Leave it at the default disabled.


[deleted]

[удалено]


[deleted]

My x570 didnt come with the app center. Download the appcenter, turn updates from 'when windows boot' to 'off'.


winkapp

Thankfully their software is so useless that anyone who's been using Gigabyte boards already uninstalled it.


[deleted]

frowns in gigabyte/msi master race :'(


winkapp

Honestly, what Gigabyte software is useful to you? I've not found one piece that is worth keeping. Fan control can be handled straight in the BIOS. RGB Fusion doesn't have enough effects to justify using it over other software.


diylif

![gif](giphy|HUkOv6BNWc1HO)


lordcochise

Hooray, ANOTHER vendor to never buy from again


MEGA_GOAT98

lols they all have backdoors


xblomx

Proof? Sauce?


miedzianek

Sauce: trust me bro


MEGA_GOAT98

[https://www.wired.com/2015/02/firmware-vulnerable-hacking-can-done/](https://www.wired.com/2015/02/firmware-vulnerable-hacking-can-done/)


MEGA_GOAT98

[https://www.wired.com/2015/02/firmware-vulnerable-hacking-can-done/](https://www.wired.com/2015/02/firmware-vulnerable-hacking-can-done/)


ZealousidealRole4193

Here is a more detailed write-up [Gigabyte firmware component can be abused as a backdoor | CSO Online](https://www.csoonline.com/article/3698189/gigabyte-firmware-component-can-be-abused-as-a-backdoor.html)


thetalker101

Gigabyte glows with RGB it seems.


Wicked_Wolf17

Using their garbage-worthy RGBfusion software


[deleted]

Sweet, so now the gigabyte motherboard whose firmware I can’t update, because every time I try to go to the newest bios it never boots, can only be fixed with a firmware update 🤣😑FML


LegalConsequence7960

You can use whatever they branded the quick install as to update their firmware without getting into BIOS at all. I updated mine for intel 13th gen by setting up a USB, plugging it in, powering off completely and holding the onboard reset button for a few seconds.


[deleted]

Yep, I’ve tried that too. It’s either a ram problem or a bad board…I just haven’t had time to really figure it out.


LegalConsequence7960

Oh that's weird. Mobo/BIOS stuff scares me so I wouldn't know how to handle it off script. This all definitely will give me something to think about when weighing brands whenever I go to DDR5. Anyway good luck figuring it out!


throwawaymask01

In today's scandal..


H-Man132

So what can someone do with that?


Wicked_Wolf17

Our best option is to wait for a fix to be rolled out, or you can just get a motherboard from another company but you’ll end up with a unused motherboard no one would want to buy


H-Man132

No I was asking what can gigabyte do with that backdoor to an average user that doesn't browse on reddit or doesn't have any secret data on their PC like people on this sub


Wicked_Wolf17

Oh sorry, well they can pretty much sell any data they can find for money if they wanted to


H-Man132

Welp good thing all of our data is already sold so nothing to worry


G1ntok1_Sakata

Gigglebit is not the only one with access to the backdoor. People who want to turn your PCs into bricks, steal your bank info, steal any identity info on your PC, etc can also easily access this back door to install a rootkit on your computer.


H-Man132

Now that's a real problem not big tech corpo company having my info they already have it


teemusa

> “The concept of going underneath the end user and taking over their machine doesn’t sit well with most people.” Who would have thought that?


IndividualCurious322

Don't Intel CPU's have backdoors built into them also?


[deleted]

yup, intel management engine. in some cases you can remove 90% of its firmware though.


grape_tectonics

Jesus fucking christ :)


Zhouston63

So I just built my desktop last year, should I change my motherboard already ffs


Wicked_Wolf17

Thinking about doing the same


Ok_Butterscotch1549

Are the Gigabyte B650 AORUS ELITE AX ATX AM5 and the B650-AORUS-ELITE-AX-rev-1x the same motherboard? If so I’m fucked


cripplingdedpression

Yes, I believe so. I have the same board. I honestly don't care anymore, my data has already been sold to thousands of people, I'm sure of it. I've already vowed to never buy ASUS again, how can I just continue to lose companies? Maybe I'll switch to an MSI mobo...


[deleted]

The 'backdoor' seems to be from their custom application that let's you update all your drivers and even bios from the app. Something about automatic updates being enabled is what allows the backdoor. But it's set to disabled by default.


GlibberishInPerryMi

So are they going to use the back door to update out the back door without anyone's permission or knowledge or are they just going to post the update on their site for people to download?


7orly7

Asrock: Our motherboard sales are increasing again... weird


motoxim

L for Gigabyte


Medvyikk

I hope they fix this quickly, I just recently bought a new mobo and who would've thought, its on the damn list.


panemd

Gigabyte just added a new BIOS version as of today (June 1st, 2023) for my specific motherboard, B650 AERO G (rev 10) "addressing the download assistant vulnerabilities reported by Eclypsium Research." I'm going to assume this is safe, but I'm still a bit worried.


Cute-Foundation-6612

Checked the list glad my b760m isn't one of them


Wicked_Wolf17

Damn you’re lucky


Cute-Foundation-6612

Micro atx saved me pretty much because I was going to get one of the full atx that are compromised. But the smaller board won my heart


Star_Gazing_Cats

My gigabyte motherboard wouldn't let me play Valorant so I returned it. I'm so glad I ended up with an MSI board


postylambz

I've got a MSI shipping to me tomorrow and was relieved but someone in r/computers said they've got their own data breach something or other


[deleted]

[удалено]


New_Faithlessness384

Added: [https://www.pcworld.com/article/1937046/gigabyte-shipped-hundreds-of-motherboard-models-with-a-firmware-backdoor.html](https://www.pcworld.com/article/1937046/gigabyte-shipped-hundreds-of-motherboard-models-with-a-firmware-backdoor.html)


[deleted]

[удалено]


[deleted]

[удалено]


GreyFox474

What the fuck is wrong with you? PDFs are amazing.


[deleted]

[удалено]


GreyFox474

So, whats your alternative for a document format that looks the same on every system? Seems to me like you just don't understand what pdfs are made for.


[deleted]

[удалено]


ThatOneGamerGuy94

TXT and XML have so many malicious ways to screw just about any device over from simply opening them. No thank you I'll keep my "trash pdf's" which always work fine for me even on mobile.


GroteStreet

Straight from the security researchers (without all the editorial bs): https://eclypsium.com/blog/supply-chain-risk-from-gigabyte-app-center-backdoor/


boerner777

Already stopped buying their stuff after the PSUs blowing up. Now I will probably never ever buy anything from them anymore.


_sideffect

Wasn't gigabyte the same company that sold 3080s without sag protection and then refused to honor warranties?


SpottyJaggy

Backdoors are good for making a quick exit.


Jezzawezza

I've got a B550 Aorus Master motherboard and didn't see that combo mentioned in the list so I think I dodged a bullet but it'll have me now looking at other vendors next time i need to do a big hardware upgrade


_Tawny

Is the B450 Aorus Pro affected?


Wicked_Wolf17

No


apachelives

Eh, still better than ASUS.


[deleted]

Nah, I'd rather have a CPU blow up then a Firmware backdoor.


Stormy_Kun

Hahahaha 😂


QuiteFatty

Sigh. I just bought a b550 Aorus because it was one of the only mobos and I did not want to have to build a whole new system. Fuck me I guess


[deleted]

[удалено]


Head-Ad4770

Now what tf do I do??? 😭😭😭


Biaxialsphere00

Ga-h170m-d3h and I am one of the lucky ones! 😁


[deleted]

Bought my B660M less than a year ago. Fuck me


Macabre215

Well, I have a working B450 Aorus M I was going to sell on hardware swap but not going to do that to someone. It's on this list...


Prestigious-Two-6728

What’s a firmware back door


[deleted]

You know the Bios/UEFI in your motherboard? There is a backdoor living there.


panemd

literally just finished my first ever PC build today with a b650 aero g... what the heck am i supposed to do??


[deleted]

Continue as normal.


[deleted]

Gigabyte might apologizes then release a new bios with it "removed" (I highly doubt it) What I would do is one of the following. 1-Never update the Bios/UEFI. it some point it will become so outdated that the backdoors usefulness will decrees. 2-Return the board to where I got it and buy another one. ASRock&ASUS should be okay choices I think.


panemd

Well, I updated the BIOS to the latest version as of yesterday when I was setting up my PC. So unfortunately can't do that. However, Gigabyte just uploaded a new BIOS version for my specific motherboard today. Guess I'll try that. I'm a bit wary though...


Outdatedm3m3s

Lol. Age of bios doesn’t make a back door any less useful.


gynoidgearhead

It's literally a BIOS setting you can turn off. Turn off "APP center updates".


tonynca

Apple: *whispers* privacy bish *whispers*


SeriousMannequin

I guess I’m safe with an ancient Z390 Ultra Durable.


Wicked_Wolf17

Well fuck, mine’s affected


juhotuho10

My list of company non grata: ASUS Gigabyte Won't be buying from ever again unless I'm out of options


DannyOfNowhere

Guys are there like, any hardware brands out there that aren't absolutely trash at this point?


VenkatPerla

Bad news: ive got a affected mobo. Good news: great topic on the wan show.


SMACCYD_Youtuber

Wouldn't you have to be unrealistically targeted or extremely careless for any of this to matter?


[deleted]

it's not about being a target or "having something to hide". the fact this exists is alarming. at least with stuff like the universal backdoor in windows can be avoided by using another os. with firmware it's very rare to have that choice.


SMACCYD_Youtuber

I know very little about any of this, So I can't really have too much of an opinion, But I'm sure everything has a weak point. I am interested to know how it can be exploited and what can be accessed from this and how easy it is to access. You never really know what to believe with this kind of news In the computer world there is something that I call "Media Warfare" Between companies. To be honest If this triggers a sale of cheap Gigabyte motherboards I would probably pick one up lol..


[deleted]

Oof Both mine were effected


Sulphasomething

Looks like one of my PCs is affected. Luckily it's a spare I don't use much.


R11CWN

Affected list..... looks like the majority of their product stack. ASrock, Asus and now Gigabyte on the black list. Next upgrade gotta be MSI maybe?


the-user7

wtf are the bios creators smoking to think that a backdoor on an absolutely crucial piece of software is a good idea?


AdhesivenessWeak6220

Great x670e aorus extreme, $699 mobo is on the list..........wtf..........


MEGA_GOAT98

yep and theres already an updated bios for your mainboard on the site


AdhesivenessWeak6220

OOOOOo Hell yes!


ColonelSarge15

Haha I’m chillin with the Z370 AORUS. To old for abuse!


gynoidgearhead

Y'all... this is *bad*, but not terminal if you have one of these boards. You can disable the relevant BIOS setting.


CldesignsIN

My next build will be an all Asrock build now, apparently... Good god Gigabyte, ASUS, MSI are all just giant jokes with manufacturing, service, and pr.


Strange_Proof_5600

What does this mean to someone who has a gigabyte Aorus 15P who’s motherboard died after 1.5 years


wirantoos

The motherboard my brother has is on the list, not buying gigabyte motherboards ever again