Live data from Hacker News

AMD PSP: Firmware TPM Remote Code Execution via Crafted EK Certificate

seclists.org

41–50 of 99 posts

Re: AMD PSP: Firmware TPM Remote Code Execution via Crafted EK Certificate

#41
post #23

Oh, god. At this point I no longer trust ANY computer for mission-critical business at my company. We're going back to pen and paper. The extra safety makes the hassle worth it.

Computer security has been ridiculous for quite some time. Your only chance is tons of layers and early detection that something's not OK. I'm really happy that everything that's happening is happening. Sad that things like Cloudbleed got so little attention outside HN-like circles.

I'm happy because it's gonna have to change. Whole stack revisited. Eventually. These things speed it up. On the long run, the thing that holds most value, in my opinion, is information. Not physical things, not energy, information. Bitcoin is a big step in that direction but I don't just mean cryptocurrencies. If you can't keep your information secret the value is destroyed.

I see two paths. One, we do a huge refactoring of how do we do computations. Super clear assumptions and provably building simple layers on top of that. I'd like that. The other one is that we keep this whole messy legacy. And security will become based on more and more layers and heuristics. Which would eventually become AIs competition. Brr.

Just some random ponderings, I'm not a security expert.

Re: AMD PSP: Firmware TPM Remote Code Execution via Crafted EK Certificate

#42
post #27

Earlier quoted context omitted.

Who gets keys to the cabinet? How do you know they haven't been duplicated? What if there is a fire? Do you keep a copy of the files somewhere? How do you control access to those?

You get literally the exact same set of problems with computers, plus all problems computers bring to the table for free.

You're pretending pen and paper doesn't bring another set of problems of its own.

Re: AMD PSP: Firmware TPM Remote Code Execution via Crafted EK Certificate

#43
post #4

Earlier quoted context omitted.

I think Intel's ME is much more complex than AMD's PSP. Does anyone know if AMD's PSP has a full network stack and the ability to interact with network hardware independent of the main CPU's OS?

Yes, AMD's PSP runs a full OS which was made by Trustonic.

It must feel weird to create an operating system that runs on a CPU inside a bigger CPU.

Re: AMD PSP: Firmware TPM Remote Code Execution via Crafted EK Certificate

#44
post #42

Earlier quoted context omitted.

You get literally the exact same set of problems with computers, plus all problems computers bring to the table for free.

You're pretending pen and paper doesn't bring another set of problems of its own.

No, I'm just not exhaustively listing the advantages of computers, because (i) not what this thread is about (ii) by and large we're aware of them.

Re: AMD PSP: Firmware TPM Remote Code Execution via Crafted EK Certificate

#45

Earlier quoted context omitted.

Physical security is not necessarily automatic, but it's much more straightforward than computer security. You don't have to worry about someone in Russia getting a hold of your pen and paper while you're sitting there with it in your room. I think that anyone who has worked professionally understands that it's a miracle we make it through life with the relatively limited quantity of exposures and accidents that we h…

I would not at all be surprised if Spectre and Meltdown were already known at nation state level, they have a lot of resources to throw at problems like this. The fact that Google provides this service for free is an amazing counterbalance to that kind of power, the bugs don't magically disappear but at least the playing field has been leveled a bit.

It is my impression that analysis of side channels has been done and professionalized in the intelligence community for a long time before it became an important consideration in the general IT community.

Re: AMD PSP: Firmware TPM Remote Code Execution via Crafted EK Certificate

#46
post #24

Earlier quoted context omitted.

What makes you think pen and paper is secure?

Physical security is not necessarily automatic, but it's much more straightforward than computer security. You don't have to worry about someone in Russia getting a hold of your pen and paper while you're sitting there with it in your room. I think that anyone who has worked professionally understands that it's a miracle we make it through life with the relatively limited quantity of exposures and accidents that we h…

[deleted]

Re: AMD PSP: Firmware TPM Remote Code Execution via Crafted EK Certificate

#47
post #41
post #23

Oh, god. At this point I no longer trust ANY computer for mission-critical business at my company. We're going back to pen and paper. The extra safety makes the hassle worth it.

Computer security has been ridiculous for quite some time. Your only chance is tons of layers and early detection that something's not OK. I'm really happy that everything that's happening is happening. Sad that things like Cloudbleed got so little attention outside HN-like circles. I'm happy because it's gonna have to change. Whole stack revisited. Eventually. These things speed it up. On the long run, the thing tha…

> I'm happy because it's gonna have to change. Whole stack revisited. Eventually.

I used to believe this kind of thing, but now I think you greatly underestimate human indifference and interest in effort conservation (uncharitably called "laziness").

Look at Intel's response to Spectre/Meltdown. Are they going back and redesigning their microarchitecture with new hardware-enforced safety rings [that actually enforce, lol] and new ways to block timing attacks without sacrificing performance? Seriously doubt it. From LKML it sounds like they're just going to hardware-accelerate IBRS/IBPB to make it faster to shut down branch prediction in risky situations and leave the rest of the shebang as-is.

Even when the forecasted apocalyptic events occur, it's amazing how little anyone cares, or how little gets recognized. Surely there are people who've speculated (ha!) attacks like Spectre/Meltdown, given the knife's edge nature of hardware virtualization on x86, and advised against multi-tenancy. Surely there are people who have paid attention over the last ten years to the dozens of sandbox escape attacks that already exist without exploiting the microarchitecture! Are they getting their due? Is anyone asking why people didn't consider these possibilities or listen to the people who warned them? Nope, because they just don't want to hear that. It's all "Oh gee how could Intel have done this to us?!" when "How could you have acted like this was safe" is an at least equally valid question.

TPMs, again, are another example of exactly the same thing. Major exploits in them are 100% routine by now. Does anyone care? Google is quietly working to remove them from their own machines but it doesn't seem like anyone is going to get any real headway outside of that. Do freedom advocates like RMS get their due? Nope, they just get told "Bugger off with your 'I told you so'."

Have you ever spent months or years warning your bosses about something, only to have that thing happen, and watch them hand-wave it away and get extremely irritable after you mention that they had fair warning? Most semi-aware engineers probably have, because this happens constantly.

Admitting, realizing, and honestly correcting our mistakes is just not a thing that people do, unless they feel substantial direct and personal pain that the brain decides greatly exceeds the forecasted effort expenditure to correct the issue. Such negative force cannot be applied over an industry at large unless there is a very specific and coordinated demand from the handful of people at the tippy-top, as in the case of Spectre/Meltdown, since in the age of cloud computing, those exploits fundamentally jeopardize the profitability of every major tech company.

Re: AMD PSP: Firmware TPM Remote Code Execution via Crafted EK Certificate

#49

Earlier quoted context omitted.

I had read somewhere that AMD PSP does not have Internet access.

It does, DASH is also arguably much less secure than Intel's RMT.

Is there a documentation of what its capabilities are? I can't find anything specific about it.

Re: AMD PSP: Firmware TPM Remote Code Execution via Crafted EK Certificate

#50
post #16

Earlier quoted context omitted.

Trustonic is about as trustworthy a name as "Safecorp" or something similar. The name itself is just one big red flag.

They are probably the largest TEE* supplier AFIK even bigger than Intel; they are pretty much the Java of the TEE world. It’s a joint venture between ARM, Gemalto and a few other companies iirc. *Trusted Execution Environment

Ahhh, okay. Thanks for the clarification!
Post reply on HN