Live data from Hacker News

AMD PSP: Firmware TPM Remote Code Execution via Crafted EK Certificate

seclists.org

51–60 of 99 posts

Re: AMD PSP: Firmware TPM Remote Code Execution via Crafted EK Certificate

#51
post #49

Earlier quoted context omitted.

It does, DASH is also arguably much less secure than Intel's RMT.

Is there a documentation of what its capabilities are? I can't find anything specific about it.

Of the remote management? Only this https://developer.amd.com/tools-for-dmtf-dash/

AMD hasn't really had any hardware for the enterprise for a long time so they are quite behind on many things.

This is their free remote admin tool : https://community.amd.com/community/devgurus/dmtf-dash/blog/...

It can basically do quite a few things, change firmware, boot an image, redirect USB input and likely quite a few of other undocumented things.

With Ryzen Pro launching soon I guess AMD would release a new suite of remote management software.

Re: AMD PSP: Firmware TPM Remote Code Execution via Crafted EK Certificate

#52
post #31
post #28

Earlier quoted context omitted.

Do you? Can a business that runs on pen and paper compete in 2018? Have you included lost revenue due to inefficiency?

Yes. Want my job?

I can't answer that without knowing what you do for a living.

Re: AMD PSP: Firmware TPM Remote Code Execution via Crafted EK Certificate

#53
post #41

Earlier quoted context omitted.

Computer security has been ridiculous for quite some time. Your only chance is tons of layers and early detection that something's not OK. I'm really happy that everything that's happening is happening. Sad that things like Cloudbleed got so little attention outside HN-like circles. I'm happy because it's gonna have to change. Whole stack revisited. Eventually. These things speed it up. On the long run, the thing tha…

> I'm happy because it's gonna have to change. Whole stack revisited. Eventually. I used to believe this kind of thing, but now I think you greatly underestimate human indifference and interest in effort conservation (uncharitably called "laziness"). Look at Intel's response to Spectre/Meltdown. Are they going back and redesigning their microarchitecture with new hardware-enforced safety rings [that actually enforce,…

[deleted]

Re: AMD PSP: Firmware TPM Remote Code Execution via Crafted EK Certificate

#54
post #32
post #23

Oh, god. At this point I no longer trust ANY computer for mission-critical business at my company. We're going back to pen and paper. The extra safety makes the hassle worth it.

If you stay with a system that is as open as possible from the lowest levels of the hardware to the highest level of the software, and if you airgap, and audiogap, and RF-gap the system permanently until it ceases to exist, you are pretty fine. Also, more practically, two computers with different ISA and underlying hardware that compute the exact same high level semantics, that don't know each other but transparently…

> JavaScript and WebAssembly

Isn't WebAssembly a huge step forward in the ability to distribute portable, high-performance, sandboxed code?

Re: AMD PSP: Firmware TPM Remote Code Execution via Crafted EK Certificate

#55
post #49

Earlier quoted context omitted.

Is there a documentation of what its capabilities are? I can't find anything specific about it.

Of the remote management? Only this https://developer.amd.com/tools-for-dmtf-dash/ AMD hasn't really had any hardware for the enterprise for a long time so they are quite behind on many things. This is their free remote admin tool : https://community.amd.com/community/devgurus/dmtf-dash/blog/... It can basically do quite a few things, change firmware, boot an image, redirect USB input and likely quite a few of other…

Thank you.

Re: AMD PSP: Firmware TPM Remote Code Execution via Crafted EK Certificate

#56
post #23

Oh, god. At this point I no longer trust ANY computer for mission-critical business at my company. We're going back to pen and paper. The extra safety makes the hassle worth it.

> We're going back to pen and paper. The extra safety makes the hassle worth it.

I've read that, several years ago, parts of the Russian security establishment switched to mechanical typewriters.

Re: AMD PSP: Firmware TPM Remote Code Execution via Crafted EK Certificate

#57
post #32

Earlier quoted context omitted.

If you stay with a system that is as open as possible from the lowest levels of the hardware to the highest level of the software, and if you airgap, and audiogap, and RF-gap the system permanently until it ceases to exist, you are pretty fine. Also, more practically, two computers with different ISA and underlying hardware that compute the exact same high level semantics, that don't know each other but transparently…

> JavaScript and WebAssembly Isn't WebAssembly a huge step forward in the ability to distribute portable, high-performance, sandboxed code?

[deleted]

Re: AMD PSP: Firmware TPM Remote Code Execution via Crafted EK Certificate

#58
post #23

Oh, god. At this point I no longer trust ANY computer for mission-critical business at my company. We're going back to pen and paper. The extra safety makes the hassle worth it.

Or we could just get ME and PSP off of our chips like people have wanted for years. They have been major security and privacy risks ever since their inception.

Re: AMD PSP: Firmware TPM Remote Code Execution via Crafted EK Certificate

#59
post #32

Earlier quoted context omitted.

If you stay with a system that is as open as possible from the lowest levels of the hardware to the highest level of the software, and if you airgap, and audiogap, and RF-gap the system permanently until it ceases to exist, you are pretty fine. Also, more practically, two computers with different ISA and underlying hardware that compute the exact same high level semantics, that don't know each other but transparently…

> JavaScript and WebAssembly Isn't WebAssembly a huge step forward in the ability to distribute portable, high-performance, sandboxed code?

Code, that is unreviewed, unaccounted and executed automatically. Now it shall be high-performance, too? Does the sandbox work? Does it really work? Are there no side channels? Are you sure? How do you make sure you don't take part in a DDoS attack or mine cryptocurrencies for somebody else? These are just points I can come up with spontaneously.

Besides that, the appification of the web is bad because it leads ultimately to dependency on software that is outside of the users control.

Re: AMD PSP: Firmware TPM Remote Code Execution via Crafted EK Certificate

#60
post #23

Oh, god. At this point I no longer trust ANY computer for mission-critical business at my company. We're going back to pen and paper. The extra safety makes the hassle worth it.

Or we could just get ME and PSP off of our chips like people have wanted for years. They have been major security and privacy risks ever since their inception.

Somehow this doesn't seem to be up for discussion.
Post reply on HN