Undocumented x86 instructions in Intel CPUs that can modify microcode
21–30 of 145 posts
Re: Undocumented x86 instructions in Intel CPUs that can modify microcode
#22Good thing Apple is moving to M1; no more of that Intel crap. and stick with AMD for Linux.
I wonder what interesting things are in Apple's completely undocumented chips? There is that famous saying about known unknowns and unknown unknowns...
Re: Undocumented x86 instructions in Intel CPUs that can modify microcode
#23Re: Undocumented x86 instructions in Intel CPUs that can modify microcode
#24Earlier quoted context omitted.
This would still break SGX/remote attestation, no? The chip can correctly say it's running some piece of assembly but if "ret" has been redefined to do whatever I want...
That would be a good thing, given what those features are usually used for (DRM and other user-hostility).
Re: Undocumented x86 instructions in Intel CPUs that can modify microcode
#25Re: Undocumented x86 instructions in Intel CPUs that can modify microcode
#26Earlier quoted context omitted.
So you mean, if I am a state actor able to kidnap the child of an Intel high level employee... say I m Joe Biden, I can ask Intel to... remote unlock my CPU and read arbitrary memory block ? Or you mean Intel had to physically handle your CPU with a debug cable or whatever ? Cause I really dont feel it s okay that the only safety we have from a newly discovered exploit is that there needs to be another newly discover…
It is public knowledge that US intelligence agencies actually just hijack computers and equipment on their way to the customer and install hardware backdoors there (Snowden et al., 2014). It is also known that they have had backdoors in commercial systems as they came off the shelf, but I think usually those were CIA owned and controlled companies like the crypto AG phones. What is unknown (pure speculation) is wheth…
There is also a third possibility, that some intelligence agency invested a ton of cash into finding abusable exploits in these systems giving them the same access a backdoor would provide.
Also from the Snowden leaks, we know that they have programs with budgets in the millions into finding similar exploits and that there were similar programs outside Snowden's clearance. And though a bug may cause the same damage to the economy, it wouldn't hurt US prestige in the same way.
Re: Undocumented x86 instructions in Intel CPUs that can modify microcode
#27Re: Undocumented x86 instructions in Intel CPUs that can modify microcode
#28Re: Undocumented x86 instructions in Intel CPUs that can modify microcode
#29Re: Undocumented x86 instructions in Intel CPUs that can modify microcode
#30The followup tweet indicates that the CPU has to be in an unlocked state before this is possible, which on a typical system requires there to be a Management Engine vulnerability first. Given what we currently know, this is going to be interesting for people interested in researching the behaviour and security of Intel CPUs and might well lead to discovery of security issues in future, but in itself I don't think thi…