Earlier quoted context omitted.
Pen and paper in a good old fashioned steel cabinet (you can get those with some nice solid wood enclosing as well) require actual physical access to read. However, side channels exist. If you write classified information on a correspondence pad, then the pad itself becomes a classified item, too. Obviously.
Who gets keys to the cabinet? How do you know they haven't been duplicated? What if there is a fire? Do you keep a copy of the files somewhere? How do you control access to those?
AMD PSP: Firmware TPM Remote Code Execution via Crafted EK Certificate
71–80 of 99 posts
Re: AMD PSP: Firmware TPM Remote Code Execution via Crafted EK Certificate
#72And to make matters worse at least for Intel we have indications that those security wholes are the result of a calculated risk to afford a higher development velocity: https://danluu.com/cpu-bugs/
This year is going to be fun...
Re: AMD PSP: Firmware TPM Remote Code Execution via Crafted EK Certificate
#73Earlier quoted context omitted.
I would not at all be surprised if Spectre and Meltdown were already known at nation state level, they have a lot of resources to throw at problems like this. The fact that Google provides this service for free is an amazing counterbalance to that kind of power, the bugs don't magically disappear but at least the playing field has been leveled a bit.
It is my impression that analysis of side channels has been done and professionalized in the intelligence community for a long time before it became an important consideration in the general IT community.
So it's not unknown. But as a counterpoint I had a shocking moment in the 90's when I learned that Faraday Cages (to prevent TEMPEST attacks) were being designed with a second Faraday cage inside them to protect the light bulbs.
Seems that the interference between a CRT and a fluorescent bulb are sufficient that you can detect information on the power lines leading into the room. So they caged the bulbs to keep them magnetically isolated from the computers.
Re: AMD PSP: Firmware TPM Remote Code Execution via Crafted EK Certificate
#74Glad someone proved them wrong, and that hopefully we'll get a proper killswitch for these backdoors.
Re: AMD PSP: Firmware TPM Remote Code Execution via Crafted EK Certificate
#75Earlier quoted context omitted.
> I'm happy because it's gonna have to change. Whole stack revisited. Eventually. I used to believe this kind of thing, but now I think you greatly underestimate human indifference and interest in effort conservation (uncharitably called "laziness"). Look at Intel's response to Spectre/Meltdown. Are they going back and redesigning their microarchitecture with new hardware-enforced safety rings [that actually enforce,…
> TPMs ... Google is quietly working to remove them from their own machines Are you referring to Chromebooks or Google's cloud server hardware? Are the TPMs being replaced with a proprietary hardware enclave?
https://cloudplatform.googleblog.com/2017/08/Titan-in-depth-...
Notable quote:
"Google designed Titan's hardware logic in-house to reduce the chances of hardware backdoors. The Titan ecosystem ensures that production infrastructure boots securely using authorized and verifiable code."
This is what we need. Authorized and verifiable code, none of this opaque binary blob BS.
Re: AMD PSP: Firmware TPM Remote Code Execution via Crafted EK Certificate
#76Earlier quoted context omitted.
Computer security has been ridiculous for quite some time. Your only chance is tons of layers and early detection that something's not OK. I'm really happy that everything that's happening is happening. Sad that things like Cloudbleed got so little attention outside HN-like circles. I'm happy because it's gonna have to change. Whole stack revisited. Eventually. These things speed it up. On the long run, the thing tha…
> I'm happy because it's gonna have to change. Whole stack revisited. Eventually. I used to believe this kind of thing, but now I think you greatly underestimate human indifference and interest in effort conservation (uncharitably called "laziness"). Look at Intel's response to Spectre/Meltdown. Are they going back and redesigning their microarchitecture with new hardware-enforced safety rings [that actually enforce,…
Let me answer that for you. In the period of the last 10 years, the world has all but switched to mobile devices. Mobile devices that make windows look like a secure operating system. In theory vendors promise 2 years of "safe" operation, and I am unaware of a single case where they actually shipped phones without major security vulnerabilities (and known, to at least some of their development team).
Internationally, iPhones do not matter. They're like 10% of the market, so I'm focusing on android phones here. And it's not like iPhones don't have exploits for them, it just means a few more years, something more like 4 year, until they're exploitable.
It is regularly reported that 40% of all android phones are vulnerable to individual vulnerabilities. At least half of all active android phones do not receive security updates, even in the case of serious vulnerabilities (and that patched "half" technically is described as anyone who ever got at least a single security update). How many of the total amount of android phones are trivially hackable if you run an app on them ? I'm going to say at least 75%, and at least including all phones more than 2 years since they were released.
So no. Nobody cares. We all know how bad the wintel situation is, and android is worse.
We need a global security disaster to happen so totally that regulators intervene and hold these vendors accountable.
Re: AMD PSP: Firmware TPM Remote Code Execution via Crafted EK Certificate
#77Earlier quoted context omitted.
What makes you think pen and paper is secure?
The big differentiator is how attacks can be scaled. Most people/companies aren't individually a worthy enough target to develop an attack against a reasonably protected system. But with a lot of these types of attacks one can compromise a large number of systems in a largely automated manner, without risking ones personal physical security.
Re: AMD PSP: Firmware TPM Remote Code Execution via Crafted EK Certificate
#78Oh, god. At this point I no longer trust ANY computer for mission-critical business at my company. We're going back to pen and paper. The extra safety makes the hassle worth it.
Or we could just get ME and PSP off of our chips like people have wanted for years. They have been major security and privacy risks ever since their inception.
Re: AMD PSP: Firmware TPM Remote Code Execution via Crafted EK Certificate
#79Earlier quoted context omitted.
What makes you think pen and paper is secure?
Pen and paper in a good old fashioned steel cabinet (you can get those with some nice solid wood enclosing as well) require actual physical access to read. However, side channels exist. If you write classified information on a correspondence pad, then the pad itself becomes a classified item, too. Obviously.
On the other hand, also the bad part is that pen and paper require actual physical access to read ;)
Re: AMD PSP: Firmware TPM Remote Code Execution via Crafted EK Certificate
#80Oh, god. At this point I no longer trust ANY computer for mission-critical business at my company. We're going back to pen and paper. The extra safety makes the hassle worth it.
People computing large amounts data don't have the luxury of hand calculations and the HUGE AMOUNT of errors that method entails. I have a client that has THREE levels of human validation of the SAME numbers (that the Dynamics NAV they're using could have calculated for free). Literally 1-2 full salaried persons worth of man-hours billed every year.
Going backwards away from that, and using more humans, is even crazier. Their hours and errors would skyrocket.