There's even worse possibilities, I think some hardware has ~1KB of executable OTP which can be programmed in that manner - so it may just be possible to implement some kind of backdoor that resides in the physical CPU. Maybe something only a state-level attacker could do.
For example, it could prevent CPU side-channel mitigations from ever working, somehow, e.g. by repeatedly writing to a private internal register to stealthily keep the CPU vulnerable. And few would ever know about it, because it's hidden in an on-chip security processor.
Personally I utterly hate all AMD chips which have a Platform Security Processor. Locking down your own property to prevent you from accessing it should be illegal.
There is a full Trustronic Trusted Execution Environment running in there, on both GPU and CPUs, I believe. For example the TEE firmware blob for a radeon GPU on Linux is "/lib/firmware/amdgpu/psp_13_0_7_sos.bin", with "sos" meaning Secure Operating System. And some of these firmware files are encrypted, so you can't reverse engineer them.
The moment some ARM SoC company such as Rockchip comes up with a chip that's within an order of magnitude in performance, then my AMD chip (EPYC) is going in the bin. After being smashed to pieces with a hammer, live on YouTube, with an explaination why. That might get AMD marketing to pay attention.
Update: Ampere Altra CPUs have seperate power pins for blowing eFuses, you can find it in the public datasheet here[1], on page 55, the supply pins are EFUSE_MFG_VDDQ1P8 and EFUSE_PCP_VDDQ1P8. It says tie to GND if unneeded.
Also they have a public datasheet for the chip. I wonder if we can buy unfused CPUs without secure boot enabled? Or is that the default state of the chip?
Could someone design a simple and cheap open-source motherboard for one of these processors, it's only a matter of time before the chips start turning up on Ebay? We will need more documentation from Ampere than just the datasheet, of course.
1. https://uawartifacts.blob.core.windows.net/upload-files/Altr...