Someone (probably the NSA) has been hiding viruses in hard drive firmware

posted on Feb, 16 2015 @ 11:18 PM
I find myself skeptical of this article, though we are only months removed from the Snowden leaks that provided evidence that folks in such secretive agencies, have no issue in lying to our elected representatives in front of the folks who cast ballots....

If true, how much longer will we allow the degradation of our civil liberties to continue? Or have we already lost the ability to know what those liberties were to begin with?


The NSA may be hiding payloads in the firmware of consumer hard drives, according to a new report from Kaspersky Lab. The report tracks a group that researchers have dubbed "Equation," which uses previously undiscovered methods to plant targeted malware in hard drive firmware, where it is difficult to detect or remove. The report found exploits for hard drives made by many of the largest brands in the industry, including Samsung, Western Digital, Seagate, Maxtor, Toshiba and Hitachi. The group is closely tied to Stuxnet, using many overlapping vulnerabilities and techniques over the same time period, and those similarities combined with previously published NSA hard drive exploits have led many to speculate that Encounter may be part of the NSA.

posted on Feb, 16 2015 @ 11:20 PM

posted on Feb, 16 2015 @ 11:21 PM
posted on Feb, 16 2015 @ 11:27 PM
There's also some detailed coverage here:
HUGE SPY PROGRAM EXPOSED: NSA has hidden software in hard drives around the world

Concerns about access to source code flared after a series of high-profile cyberattacks on Google Inc and other U.S. companies in 2009 that were blamed onChina. Investigators have said they found evidence that the hackers gained access to source code from several big U.S. tech and defense companies.

It is not clear how the NSA may have obtained the hard drives' source code. Western Digital spokesman Steve Shattuck said the company "has not provided its source code to government agencies." The other hard drive makers would not say if they had shared their source code with the NSA.

This looks like the NSA has created a permanent, non-removeable zero-day exploit on millions of computers around the world.

This is as bad as it gets.

