You Must Check Your USB Devices For Unsafe Firmware, Here's How

Dhir Acharya


It's important to know if any of your USB devices have unsigned firmware so that you can take measures to protect yourself from attacks.

The USB peripherals you’re using may make your computer vulnerable to hackers. According to data security company Eclypsium, a large part of Linux and Windows-based peripherals rely on unsigned firmware, leaving them exposed to all kinds of cyberattacks, including spyware, ransomware, as well as full-on device takeovers.

The firmware that does not use a validation key, used to verify that drivers and updates are from the manufacturer, is called “unsigned.” Due to this, users may accidentally download, install fake drivers containing malicious code.

As of now, hackers have managed to exploit unsigned firmware on USB laptop trackpads, mice, even routers. However, all Linux and Windows hardware are able to use unsigned firmware, which includes webcams, hard drives, graphics cards, etc.

The bad news is that this problem can’t be solved unless the manufacturer releases new, signed firmware. It’s noted in the Eclyspium report that acknowledging the risks of unsigned firmware, some hard drive manufacturers updated their SSD and HDDs to accept only signed firmware. While many other firms have also updated their devices, many are still at risk.

Assume a device is properly updated, users still have to download and install the update on their own. And updating the firmware of a USB hub or a wireless mouse is not as easy as updating a smartphone.

Regardless, we should all check our devices for unsigned drivers and firmware. In case you cannot update the firmware on your peripherals, it’s still important to know if you are at risk of using fake drivers. Follow these steps to check your devices for unsigned drivers and firmware, if you’re a Windows user.

Step 1: Launch the Start menu on Windows.

Step 2: Search for Device Manager and run it.

Step 3: Once you’re in Device Manager, the next thing to do is right-click on a device, then click on Properties.

Step 4: Now, open the Driver tab where you will see Digital Signer. If this is listed as Unknown or it’s blank, the firmware is unsigned.

Step 5: Click on Driver details. Then you will see a pop-up window that shows a list of the installed drivers for the device. If a driver is signed, there will be a certification icon next to it as in the image above. Besides, the Digital Signer would be listed for that driver, which should match that Digital Signer you see in the Driver tab.

For Linux users, the process for checking the firmware will be different among different Linus distros.

>>> How To Import Emails Between Your Gmail Accounts

Tags
Next Story

Read More

Features- Feb 26, 2025

Elon Musk Eyes Indian Market: Tesla’s Next Big Move?

Amid slowing global sales and political tensions, Tesla is making strategic moves to enter one of the world’s fastest-growing automotive markets - India.

ICT News- Feb 26, 2025

Elon Musk's Federal Workforce Overhaul: AI Takes the Helm

Elon Musk is shaking up the U.S. federal workforce with a drastic measure—leveraging AI to determine who's essential and who's expendable.

Review- Feb 27, 2025

Microsoft Surface: A Shift from Innovation to Stability?

ICT News- Feb 25, 2025

Not Radiation: What Is Causing the Strange Genetic Evolution of Chernobyl’s Dogs?

For years researchers believed that the dogs surviving in the highly radioactive zone of Chernobyl would exhibit strong genetic mutations, helping them adapt to the harsh environment. However, the latest studies have completely...

ICT News- Feb 25, 2025

Google to Phase Out SMS-Based Authentication Codes

Google is set to discontinue authentication and account recovery via SMS verification codes.

ICT News- Feb 26, 2025

Will AI Kill Coding Jobs? The Truth Might Surprise You

For years and now more than ever, we’ve heard that AI is coming for everyone’s jobs—from truck drivers to customer service reps. But what about programmers?