Precautions for safe working with used laptop

llkd
llkd Member Posts: 3 New User
I bought a laptop in a retail shop but it has signs of use (a big value of total SSD read/write bytes, a created user and activated Windows). I am concerned about  UEFI rootkit such as Lojax, MosaicREgress and MoonBounce, which can be easily injected if an adversary have direct access to the laptop.
It is important for me to evaluate the risks of using this laptop. I have the following questions:
1) Are there security protection mechanisms preventing malicious firmware upload for motherboards in modern Acer laptops?
2) Can I compare own UEFI image with the laptop reference sample?
3) Are BIOS/Firmware update executable files from (https://www.acer.com/ac/en/US/content/support-product/) fully overwrites the UEFI firmware (SPI flash)?

Answers

  • AnhEZ28
    AnhEZ28 ACE, Member Posts: 4,277 Pathfinder
    @llkd check the popularity of that retail shop. I think they created users first so that you don't really have to do many complicated setups. I don't really see many laptops that have modified BIOS. You can try updating the BIOS from the supported site and reset the BIOS setting to default for making sure.
    Please remember to include @AnhEZ28 when you want to reply back to my comment so that I can check your response.
    Thank you and have a nice day!
  • llkd
    llkd Member Posts: 3 New User
    The retail shop has a bad reputation. There are cases where some employees use devices for their own personal purposes. And they have special promotion allows change purchased devices within a month (in some cases).
    I live in a small town and I had no choice.
    Are there a documentation that explains how BIOS/Firmware update executable files (from https://www.acer.com/ac/en/US/content/support-product/) work ?

  • AnhEZ28
    AnhEZ28 ACE, Member Posts: 4,277 Pathfinder
    edited April 2022
    @llkd the BIOS update procedure is simple, just run the EXE file, confirm that you have plugged the AC adapter, and do not do anything like power off during the update.
    Please remember to include @AnhEZ28 when you want to reply back to my comment so that I can check your response.
    Thank you and have a nice day!
  • llkd
    llkd Member Posts: 3 New User

    I tried to find a technical information about which of areas of SPI flash memory will be overwritten by this tool (only BIOS location or full UEFI (firmware?) too). I would also like to know whether memory cell code will be replaced if this code does not have changes in functionality? It is strange that I didn't find any information, even user manual of BIOS/Firmware update tool.