ironman9105

Q: Is it possible that EFI & SMC firmware update be malicious?

Is it possible that EFI & SMC firmware update that I installed be fake or malicious?

Any ways to reinstall (tried by system prohibited) or to check firmware's genuineness?

Remark: I have checked in "System Information" that firmware's versions are the same as those in Apple's website.

EFI and SMC firmware updates for Intel-based Macs - Apple Support

MacBook Air, OS X Mavericks (10.9.5), 11-inch Early 2014

Posted on Apr 16, 2015 2:09 AM

Close

Q: Is it possible that EFI & SMC firmware update be malicious?

  • All replies
  • Helpful answers

  • by petermac87,

    petermac87 petermac87 Apr 16, 2015 2:19 AM in response to ironman9105
    Level 5 (7,402 points)
    Apr 16, 2015 2:19 AM in response to ironman9105

    Then where did you get the updates from?

     

    Pete

  • by Kurt Lang,

    Kurt Lang Kurt Lang Apr 16, 2015 8:27 AM in response to ironman9105
    Level 8 (37,815 points)
    Mac OS X
    Apr 16, 2015 8:27 AM in response to ironman9105

    The only place to get firmware updates for any Mac are on the page you linked to. If your Mac is already up to date, it won't install, as you found out.

     

    What could possibly make you think a firmware update - that you didn't need - would be fake coming directly from Apple?

  • by ironman9105,

    ironman9105 ironman9105 Apr 16, 2015 10:04 AM in response to Kurt Lang
    Level 1 (0 points)
    Apr 16, 2015 10:04 AM in response to Kurt Lang

    I did update my firmware at the App Store. However, I worry about some advanced hacking technique such as MITM attack or fake DNS server redirecting me to malicious download site. Those techniques are commonly used by Chinese Government.

    In fact, I locate in China. And at the time of update, I did not use any antivirus or VPN software.

    Worse, I found 2 updates showing EFI firmware 2.8 appear at the update page of App Store. And every time I restart, the screen has a blue blink. Are these conditions normal?

    Are those updates from App Store are always genuine? Apple claims those installation will be checked.

    Any ways to reinstall (tried but system prohibited) or to check firmware's genuineness?

    Thank you!

  • by Kurt Lang,

    Kurt Lang Kurt Lang Apr 16, 2015 10:42 AM in response to ironman9105
    Level 8 (37,815 points)
    Mac OS X
    Apr 16, 2015 10:42 AM in response to ironman9105

    Since only the Chinese government could really tell anyone what is happening with their Internet hubs, there's no one here who can genuinely answer your question. You would just have to hope an Apple Store would have access to the real, unaltered files they use.

     

    I didn't see any way to check the firmware for authenticity. I did download the latest firmware for my Mac Pro (same level that's already installed). Double clicking the .dmg file causes the OS to do the usual verify process. But that's your only type of reassurance.

     

    No idea what the blue blink is. It isn't enough information to tell what you mean, and probably isn't easy for a person to describe.