Firmware is vulnerable because vendors rarely sign or authenticate the software
Why Firmware Is So Vulnerable to Hacking, and What Can Be Done About It — When Kaspersky Lab revealed last week that it had uncovered a sophisticated piece of malware designed to plant malicious code inside …
Context & Ripple Effects
When Wired flagged in early 2015 that vendors rarely sign or authenticate firmware — right as Kaspersky uncovered malware designed to implant code inside it — the warning read as theoretical. Within months it wasn't: researchers showed a BIOS hack could subvert hardened operating systems like Tails, and by June a Mac firmware flaw was letting attackers install rootkits remotely.
The pattern has since repeated across every device class the article worried about — Intel's 2017 firmware flaws forced mass patching (PC vendors scrambled to issue fixes affecting millions of chips), Kryptowire found serious vulnerabilities in the firmware tweaks Asus, LG, Essential, and ZTE ship on US-sold Android phones, and by 2020 Kaspersky was finding malware embedded in UEFI firmware itself on diplomats' machines.
First-order effects
- Device owners face attacks that survive OS reinstalls because they live below the operating system, while vendors like Apple, Intel, and the Android OEMs named in later coverage are forced into emergency firmware patch cycles their update infrastructure was never built for.
Second-order effects
- Security tooling shifts down the stack: defenders who trusted a clean OS install can no longer do so, pushing antivirus and forensics vendors toward firmware-level scanning, and giving chipmakers' signing and secure-boot capabilities new commercial weight against rivals whose firmware remains unauthenticated.
Third-order effects
- If unsigned firmware stays the norm, the lowest software layer becomes the preferred persistence point for state-grade attackers — as the UEFI implants found on diplomats' machines suggest — forcing regulators and enterprise buyers to treat firmware integrity as a procurement requirement rather than a vendor promise.
The trend: Firmware is moving from an assumed-trusted blind spot to a primary attack surface, with each confirmed implant pushing the industry toward signed, verifiable boot chains.