Live data from Hacker News

AMD PSP: Firmware TPM Remote Code Execution via Crafted EK Certificate

seclists.org

81–90 of 99 posts

Re: AMD PSP: Firmware TPM Remote Code Execution via Crafted EK Certificate

#81
post #62

Earlier quoted context omitted.

> We're going back to pen and paper. The extra safety makes the hassle worth it. I've read that, several years ago, parts of the Russian security establishment switched to mechanical typewriters.

You might be talking about the following article: https://www.theguardian.com/world/2013/jul/11/russia-reverts... Even in Germany high officials hinted at using mechanical typewriters: https://www.theguardian.com/world/2014/jul/15/germany-typewr... Luckily, the politicians in Germany and Europe wake up. They want to build up European chip and hardware facilities to have the full chain in Europe. Also they plan to dem…

Luckily, the politicians in Germany and Europe wake up. They want to build up European chip and hardware facilities to have the full chain in Europe. Also they plan to demand certification and customer visible labels. Finally!

This is the same Thomas de Maizière that backed a law that allows German law enforcement agencies to order companies to insert back doors in their products:

https://boingboing.net/2017/12/05/thomas-de-maiziere.html

Re: AMD PSP: Firmware TPM Remote Code Execution via Crafted EK Certificate

#82

Earlier quoted context omitted.

> TPMs ... Google is quietly working to remove them from their own machines Are you referring to Chromebooks or Google's cloud server hardware? Are the TPMs being replaced with a proprietary hardware enclave?

It looks like they built their own chips for their servers: https://cloudplatform.googleblog.com/2017/08/Titan-in-depth-... Notable quote: "Google designed Titan's hardware logic in-house to reduce the chances of hardware backdoors. The Titan ecosystem ensures that production infrastructure boots securely using authorized and verifiable code." This is what we need. Authorized and verifiable code, none of this opaque…

Google's code/hardware logic is an opaque binary blob to you. What difference does it make whether the binary blob is a Google chip or a TPM?

Re: AMD PSP: Firmware TPM Remote Code Execution via Crafted EK Certificate

#83

Earlier quoted context omitted.

The big differentiator is how attacks can be scaled. Most people/companies aren't individually a worthy enough target to develop an attack against a reasonably protected system. But with a lot of these types of attacks one can compromise a large number of systems in a largely automated manner, without risking ones personal physical security.

What prevents attackers from collecting photos of the papers with nearby phones, security cameras, or even a fleet of tiny drones?

Cost

Re: AMD PSP: Firmware TPM Remote Code Execution via Crafted EK Certificate

#84
post #32
post #23

Oh, god. At this point I no longer trust ANY computer for mission-critical business at my company. We're going back to pen and paper. The extra safety makes the hassle worth it.

If you stay with a system that is as open as possible from the lowest levels of the hardware to the highest level of the software, and if you airgap, and audiogap, and RF-gap the system permanently until it ceases to exist, you are pretty fine. Also, more practically, two computers with different ISA and underlying hardware that compute the exact same high level semantics, that don't know each other but transparently…

The Spectre attack (for example) is an innovation in breaking complex systems. It's not just a hardware bug that can be easily spotted with a more cleverly designed process, or prevented with good security practices. It's a new way to look at the very general and basic concept (not implementation!) that was introduced years ago and was considered pretty safe for all these years.

It's the complexity of everything that we do with computers that needs to be addressed, not just the quality of software and hardware testing and exploit mitigation. Mitigation techniques can't stop every unknown exploit, just some of them; in a sufficiently complex system there always will be a way to break the system in an unexpected and conceptually new way. Besides, they are additional layers of complexity on their own, and you can't fight complexity with complexity.

Re: AMD PSP: Firmware TPM Remote Code Execution via Crafted EK Certificate

#85
post #41

Earlier quoted context omitted.

Computer security has been ridiculous for quite some time. Your only chance is tons of layers and early detection that something's not OK. I'm really happy that everything that's happening is happening. Sad that things like Cloudbleed got so little attention outside HN-like circles. I'm happy because it's gonna have to change. Whole stack revisited. Eventually. These things speed it up. On the long run, the thing tha…

> I'm happy because it's gonna have to change. Whole stack revisited. Eventually. I used to believe this kind of thing, but now I think you greatly underestimate human indifference and interest in effort conservation (uncharitably called "laziness"). Look at Intel's response to Spectre/Meltdown. Are they going back and redesigning their microarchitecture with new hardware-enforced safety rings [that actually enforce,…

If we want to understand why users do what they do, perhaps we should ask the UX people. Alan Cooper in his book "The Inmates are Running the Asylum" says that one of the differences between programmers and ordinary people is that programmers worry a lot about what-if scenarios while ordinary people just hope for the best and then handle surprises as they arise.

If we are to change behavior of consumers, we have to work with their natural motivation. I think the most realistic plan is to subsidize core infrastructure with enough high-quality opensource software and hardware to drive commercial interest out of all security-sensitive components.

It's like when Wikipedia is subsidized by its editors to provide the common good of education. Opensource can be similarly subsidized by developers to provide the common good of security.

Re: AMD PSP: Firmware TPM Remote Code Execution via Crafted EK Certificate

#86
post #32

Earlier quoted context omitted.

If you stay with a system that is as open as possible from the lowest levels of the hardware to the highest level of the software, and if you airgap, and audiogap, and RF-gap the system permanently until it ceases to exist, you are pretty fine. Also, more practically, two computers with different ISA and underlying hardware that compute the exact same high level semantics, that don't know each other but transparently…

The Spectre attack (for example) is an innovation in breaking complex systems. It's not just a hardware bug that can be easily spotted with a more cleverly designed process, or prevented with good security practices. It's a new way to look at the very general and basic concept (not implementation!) that was introduced years ago and was considered pretty safe for all these years. It's the complexity of everything that…

Not really novel in concept, but in implementation.

See also the responses: https://news.ycombinator.com/item?id=16083256

Especially "613.pdf" linked by NickPSecurity.

Re: AMD PSP: Firmware TPM Remote Code Execution via Crafted EK Certificate

#87
post #62

Earlier quoted context omitted.

> We're going back to pen and paper. The extra safety makes the hassle worth it. I've read that, several years ago, parts of the Russian security establishment switched to mechanical typewriters.

You might be talking about the following article: https://www.theguardian.com/world/2013/jul/11/russia-reverts... Even in Germany high officials hinted at using mechanical typewriters: https://www.theguardian.com/world/2014/jul/15/germany-typewr... Luckily, the politicians in Germany and Europe wake up. They want to build up European chip and hardware facilities to have the full chain in Europe. Also they plan to dem…

"Luckily, the politicians in Germany and Europe wake up. They want to build up European chip and hardware facilities to have the full chain in Europe. Also they plan to demand certification and customer visible labels. Finally!"

So far similar efforts by EU were rather underwhelming - but this one is probably the most important. I believe EU is the only global actor that can achieve the goal of creating reliable hardware and software. The still decentralized nature of EU means that no partner can afford any unilateral action (like backdoors) - and a conspiracy on the level of whole EU is impossible.

And of course it needs to be Open Source.

Re: AMD PSP: Firmware TPM Remote Code Execution via Crafted EK Certificate

#88
post #41
post #23

Oh, god. At this point I no longer trust ANY computer for mission-critical business at my company. We're going back to pen and paper. The extra safety makes the hassle worth it.

Computer security has been ridiculous for quite some time. Your only chance is tons of layers and early detection that something's not OK. I'm really happy that everything that's happening is happening. Sad that things like Cloudbleed got so little attention outside HN-like circles. I'm happy because it's gonna have to change. Whole stack revisited. Eventually. These things speed it up. On the long run, the thing tha…

Does Azure's composable FPGA design offer potential for assemblage of a higher level of abstraction, my poor analogy is the web assembly reduced to instructions/ primitives but you control the gate logic that's run, and isn't that logic then totally isolated from any other design side effects?

If you by some circumstances had a terrific clean and tidy system in a functional language, wouldn't that offer a higher level of possible "primitive" operations?

Re: AMD PSP: Firmware TPM Remote Code Execution via Crafted EK Certificate

#89
post #62

Earlier quoted context omitted.

> We're going back to pen and paper. The extra safety makes the hassle worth it. I've read that, several years ago, parts of the Russian security establishment switched to mechanical typewriters.

You might be talking about the following article: https://www.theguardian.com/world/2013/jul/11/russia-reverts... Even in Germany high officials hinted at using mechanical typewriters: https://www.theguardian.com/world/2014/jul/15/germany-typewr... Luckily, the politicians in Germany and Europe wake up. They want to build up European chip and hardware facilities to have the full chain in Europe. Also they plan to dem…

How does geopolitical location make hardware and software secure? Hint: it does not. It is clear there is demand at some level for secure computation and patching current hardware and software is not going to get the job done. Certification and labels imply we know how to do something we'll enough to say this is the right way. It is clear that we do not, so certification of hardware is most likely to just ensure every chip has the same exact problems.
Post reply on HN