I pretty much understand computers, don't worry. As long as "whatever runs during boot time" is not able to modify the OS and software (opnsense in my case) and punch a hole into it in a way that it can be remotely attacked and taken over, there is zero risk.I think you do not understand the risk of BIOS/UEFI poses. It is run as soon as the machine is turned on so can affect everything that loads after it which is why it has been the 'holy grail' for cyber criminals.
Please show me any kind of remote attack which has been successful using this kind of attack method on a firewall router. So far I only have seen examples which simply don't fit, which makes me wonder who has issues with understanding the whole thing.
If you refer to this one here - it's also not relevant for a firewall. The target system was and is Windows, and to install the BIOS/UEFI rootkit you first have to run infected software on the target machine. Good luck with trying this attack method on FreeBSD and not Windows, where people typically only run software provided by the owner of the FW software repos (e.g. opnsense) but not anything else.
Here is the attack method of the UEFI rootkit I have linked.

Now try this with Proxmox being booted during runtime, which then launches Opnsense (stored in an lxc container on the hard drive of Proxmox), which in the end controls access to my network.
The root kit would first have to infect Linux (Proxmox) and modify it in a way, so it's also modifying the right container containing opnsense (based on FreeBSD) and compromise this system. I see a higher chance in a Chinese agent climbing through the window of the room where the box is and replacing it with a modified one than any UEFI rootkit being able to achieve this, but I am all open ears to be proven wrong.
Last edited:

