HN user

chuckup

390 karma
Posts1
Comments42
View on HN

tl;dr version (since this blew up on Reddit and there's lots of stuff to digest)

* in Windows 8+ any PC vendor can include an .EXE in Firmware/BIOS, and Windows will look for this on each boot, and run it right before you log in. This is called "Windows Platform Binary Table". This is something Windows does, and there is no way to turn this off. To me, this is the bigger story, because vendors may now start to use this method to install anything, making a clean windows install impossible.

* Lenovo uses this method if you try to install Windows 8, but if you install Windows 7, it does the sketchy "overwrite your system file (autochk.exe)" method instead.

* Either way, Lenovo installs a service on your PC. It was found to have security bugs. I can't find the link, but they said this was placed on some laptops/PC's from late 2014 to Summer 2015. They've released a new firmware 2 weeks ago that turns this off.

I would like to know if any non-Lenovo pc's have used this "Windows Platform Binary" method to run software from the firmware, because when I searched for it, I saw people with Dell's and HP's who thought they might have a virus, posting scan logs that contained the text "wpbbin.exe" (which would only be there if Windows found it in the BIOS and put it there) For example see https://www.google.com/search?q="wpbbin.exe"+site%3Aforums.m...

Check your PC:

Windows 8 and up: Check your event log for "Microsoft-Windows-Subsys-SMSS" and if you see "A platform binary was successfully executed." your PC vendor is doing this. Or, look for a file called wpbbin.exe in windows\system32. (This file would ONLY exist if Windows found it in your firmware and ran it.)

Windows 7: Verify your autochk.exe is legit. I think you could simply do: "sfc /VERIFYONLY" in cmd.exe (as Admin) but I did not test it. My autochk.exe was signed by Lenovo in 2014 (which tipped me off it didn't come from the Windows 7 DVD I got in 2010!).

Wow, nice find!

Also, I see Microsoft has updated that document in the last two weeks, apparently due to Lenovo's use of it.

http://news.lenovo.com/article_display.cfm?article_id=2013

"a security vulnerability that was discovered ..by an independent security researcher, Roel Schouwenberg... As a result of these findings, Microsoft recently released updated security guidelines...on how to best implement this Windows BIOS feature."

I would be interested to see if any other manufacturers are doing this as well.

You can easily check: if a file called wpbbin.exe is in your windows\system32 directory, that means Windows found and executed code that was in your firmware.

Or, see if your autochk.exe hash isn't from Microsoft (paste the hash into virustotal) If OK, virustotal would say, "Trusted source! This file belongs to the Microsoft Corporation software catalogue."

I ask because last month, when I searched for "wpbbin.exe" I found lots of people who thought they had viruses, posting scan logs to various sites, and the scan logs mentioned this file as well as things that looked like Dell and HP stuff. "Wpbbin.exe" is a file that would only exist in your system32 if Windows found it in your firmware.

Very interesting, thanks for that link.

"If LSE is not enabled, it will not be shown under the “Security” tab in the system BIOS and the user is not affected"

FYI, This was not true for me - there was no option in the BIOS regarding this. So I'd say, the lack of this in your BIOS setup screen does NOT mean it is not there!

No - see my reply to the Ars thread. Windows 8 introduced an "official" way to do this called "Windows Platform Binary Table". Every time Windows boots, it checks your ACPI table for an entry called "WPBT", writes that to disk as "wpbbin.exe", and executes it. There does not seem to be any way to disable this behavior in Windows. Truecrypt would not help in this case because it happens after boot.

I just replied to the Ars thread - it's even stranger. Windows 8 and up have an officially Microsoft sanctioned way of letting manufacturers load software through Firmware, called "Windows Platform Binary Table". It means it is impossible to do a clean install of Windows now. I've seen zero mention of it anywhere - maybe Lenovo was the first to pull the trigger and make use of it recently.

Lenovo is now using rootkit-like techniques to install their software on CLEAN Windows installs, by having the BIOS overwrite windows system files on bootup. Someone detailed this here: http://arstechnica.com/civis/viewtopic.php?p=29497693&sid=dd...

I had this happen to me a few weeks ago, on a new Lenovo laptop, doing a clean install with a new SSD, Win 8 DVD + wifi turned off. I couldn't understand how a Lenovo service was installed and running! Delete the file and it reappears on reboot. I've never seen anything like this before.

Something to think about before buying Lenovo. I searched and found almost nothing about this, so it may be something they started doing in the last few months...

every civilization must regard every other civilization as an existential threat

I've wondered about this! If "the singularity" is something that really can happen, then perhaps it IS wise to fear any civilization that has developed basic computing, as it could quickly spawn an incredibly advanced, immortal being in a very short amount of time.

And if it can happen, then I'm sure at some point in history, an AI did take hold somewhere. Realizing how dangerous this whole singularity thing can be, it sought out the destruction of any biological life that could someday create their own singularity.

I've wondered if the Fermi paradox is simply that a few AI's developed long ago, and decided not to take any chances.

Stripe: Bitcoin 11 years ago

I don't think you need to buy them (unless you want to gamble on their value going up) - just be willing to accept them as payment in the future. As more people see they can easily spend bitcoin, they become more willing to accept it as payment, and the userbase grows (bringing more price stability, hopefully)

Speaking of large gaps between primes - There is a Bitcoin clone recently released called "Gapcoin" which replaces the SHA256 hash-breaking with finding large prime gaps. It seems completely unknown and has very few people mining it, yet it already broke a few hundred records, and is one spot away from breaking Donald Knuth's record in the "top 20 highest merit gaps"

http://primerecords.dk/primegaps/gaps20.htm

http://gapcoin.org/primegaps.php

I am curious if there is any scientific use for finding these high-merit gaps? Or is it the same usefulness as finding a slightly longer expansion of PI?

This might sound corny, but you are my favorite gadfly. I've seen many posts from you over the years on slashdot and HN pointing out flaws with things I love such as python, and now lately bitcoin. I don't always agree with you, but I'm glad you're around.

I think even more interesting is the idea of "colored coins" that represent actual items.

I'd start playing Magic: The Gathering again if the digital cards I bought were colored coins or counterparty-style tokens that I controlled, and could trade outside of the game.

If the game itself was open source and p2p, even better - there would be no worry of the company shutting down the servers/abandoning the game. The community could take over and make improvements to the client if needed. The initial creation of the game would be funded by selling the digital cards.

Which makes it rather difficult to obtain bitcoin in the first place.

True, but now with Bitcoin a teen can do work for pay over the internet (I assume minors cannot easily get a paypal account). I've seen teens draw incredible art, make avatars, do minecraft related tasks, light programming, etc. So while it's not easy, there is a way for them to obtain it.

I remember scheming for ways to make money online when I was a teen, but my only options were to get someone to send me cash in the mail, or have my parents cash a check (after asking me a bunch of questions as to why someone was sending their 14yr old a $100 check).

Hop over to btc-e and watch thousands of teens daytrade altcoins while chatting, it's eye opening.

This is great news. I've always thought teenagers are the biggest market for bitcoin, they're less likely to have a bank/credit card. Knowing you can now exchange bitcoin for Xbox points makes accepting bitcoin a lot more attractive.

But I understand all the bitcoin evangelists don't even want to consider that another digital currency can make it to the top.

Can you explain why "Safecoin" is needed and more importantly, how it is superior to Bitcoin? It sounds like a reinvention of something that already exists, done to raise funds (they wouldn't have received millions of USD$ in funding otherwise). I've never seen a good technical explanation, it's all very hand-wavy and vague.

Secondly, Maidsafe seems to be trying to solve a problem that does not exist - backing up personal data to a p2p network. It's a flawed idea because there is no way to know if your data is sitting on a botnet that could disappear any moment. There is a financial incentive to pretend to be multiple clients and use as little hardware as possible. Maidsafe cannot know if your 10 copies of data are on 10 hard drives or 1.

I could imagine the payment protocol being very flexible. Some servers may want their money up front, some may be willing to trust you to pay afterwards, etc.

At that point, why not setup escrow processes where the sender has to provide proof to release the payment?

There is no way to prove you've sent a file to someone. In the BBS days, there was a program called Leech Zmodem that lied about getting the last chunk of data, so that you didn't have to pay file points for your download.

I can think of a way around this, sort of: you could break the transfer up and require the receiver to sign a message for each piece they've received, before you send the next piece. But, they can lie and say they never got the last piece, and that's tricky because some data is worthless without the entire thing. Maybe they're not lying, and you've disconnected - should they have to pay for 90% of a file? There's lots of little edge cases I can think of.

If this whole idea ever happened, I think large data warehouses would form (using cheap amazon/google storage) and the whole thing might become centralized anyway.

I would love to see something simpler, think Kad DHT meets Bitcoin. I could share a hash with you, and from the command line you could simply type "fetch L9ThxnotKPzthJ7hu3bnORuT6xI" just as you'd use wget.

This would be a hash of an index file that describes the data, broken into small chunks. Now your client goes back onto the network and finds the cheapest way to retrieve all these chunks. You could set a default, "5 cents per GB" that you're willing to pay.

Servers could monitor the network and see what's being requested often, and pay to download (and re-serve) these chunks themselves in the hopes of profiting. When files become rare, servers could charge a premium.

Bitcoin is not a micropayment system, so paying per chunk would be expensive. You could pre-pay, say 1GB at a time at first, and slowly build up a trusted reputation where you only pay afterwards (by reusing a bitcoin address as your "identity" that you always send from). You'd work out a "contract" (signed with your sending address), give it to the server, and if you skip out on paying they could use it as proof of nonpayment which they would share with other servers. (Maybe all servers have a blacklist file they share for free). They could try to send you bogus data, but since you can verify by-the-chunk you wouldn't request more chunks from them once you've received a piece that fails a hash.

Once you've got this network in place, you could build any of the things the author in this link is describing. My hope, a Usenet 2.0 style protocol. The whole thing is very exciting. But first you need a simple, generic, data-for-bitcoin network.

Everything I've seen so far in the bitcoin/storage area (maidsafe, storj) sounds overly complicated and downright scammy. I don't want to back up my data to a p2p network. I don't want to have to purchase a new altcoin to use your network. I just want to, for starters, type "serve [file]" or "fetch [hash]" on the CLI and have it all magically work behind the scenes. First place I'd see this taking off is sharing porn - yay! From there, after time, it could become the backbone of "web 3.0".

I've always heard the line, Aliens would never travel many light years to destroy/enslave humanity, because we're no threat, and they'd be enlightened enough not to.

But the idea that we could stumble upon AI, and it could become hyper intelligent at an astronomical rate ("the singularity") - doesn't this make us a huge potential threat to non-AI life everywhere?

We'd have to be quarantined. For our own good, and theirs.

(also, it sounds like Hawking recently found lesswrong)

Also, can someone in the know care to tell me why that is that those additions for what is the end rather basic functionality is coming so late to the language?

I would think Internet Explorer being the dominant browser had something to do with it.

Bitstamped 12 years ago

What's with the terrible names in Bitcoin land?

When deciding what to name your Bitcoin site, anything with the word "bit" or "coin" in it should be avoided. Please! Otherwise, you just join the list of other unmemorable bit/coin sites.

And, this goes without saying, pick something that, when you google it, google does not say "Showing results for Bitstamp".