Hardware backdoors in some x86 CPUs
61–70 of 102 posts
Re: Hardware backdoors in some x86 CPUs
#62This backdoor only appears on decades-old VIA C3 embedded x86 processors
For example, I am building a device that records motion data, video, audio, and lidar imaging. Inside the 6 dollar IMU and the 12 dollar lidar sensor are powerful processors that load binary blobs provided by the manufacturer. The lidar could potentially gain access to any of the system data stored on the SPI bus, which includes the bulk storage and secondary RAM for the system. It could exfiltrate that data using its laser to anyone within a few hundred meters in the laser fov. It could also receive remote c&c over its optical sensor. The only thing that prevents that from being the case is that I trust the blob does not include the code to do those things, but it would be trivial to replace the blob with one that does.
Millions of devices are made that include basic wifi functionality. often, this comes in the form of a dedicated WiFi module. Those almost entirely consist of a powerful processor running a proprietary binary blobs, connected to some internal bus of the system that may give it access to some or all of the functions of the device, or at the very least could cause the device to malfunction. These WiFi phy modules are sub$1, pervasive, and often built in to devices that do not have any advertised connectivity features. A threat actor that has knowledge of an attack surface for that opaque blob can probably cause >50% of the connected devices built with that product to malfunction, in some cases in serious and dangerous ways, and sometimes to exfiltrate data that might be compromising or valuable.
That’s what this article is really about.
Re: Hardware backdoors in some x86 CPUs
#63Earlier quoted context omitted.
They should have mentioned that in the first line of the github readme, not burried deep down in the text.
Buried? Deep down? The fourth paragraph, clearly labeled "Affected Systems", a minute or two into the read.
Re: Hardware backdoors in some x86 CPUs
#64Click bait title, please change it to VIA C3 CPUs
Stupid autistic policy of "Don't editorialize the title"...
Re: Hardware backdoors in some x86 CPUs
#65Click bait title, please change it to VIA C3 CPUs
Re: Hardware backdoors in some x86 CPUs
#66Earlier quoted context omitted.
Sure but the cops aren't going to pull you over based on what you think about Chinese policy. Government do mess with people across international borders, but the capacity to do that is inherently limited.
Blackmail is still a possibility ... Plus your data can be sold on the market. To US based entities. While the Chinese still hold on to the data for future uses ...
Re: Hardware backdoors in some x86 CPUs
#67Earlier quoted context omitted.
Password resets aren't "backdoors" unless they contain a flaw the defeats any security protections. It's not just that the backdoor is less secure than the front, the backdoor has no security or is so easily defeated the security may as well not exist. I'm surprised the hidden aspect of backdoor is so forward in folks minds. In my thinking nothing in cyber security is hidden, I drop the obviously present hidden part…
No offense but I don’t think you have a clear enough definition in your head and you’re making it up as we go along and you get challenged. >> I'm probably mistaken, but I've always referred to password resets as backdoors > Password resets aren't "backdoors" unless they contain a flaw the defeats any security protections. You really have to make up your mind. It was “always” but then it wasn’t, and even as you put i…
Re: Hardware backdoors in some x86 CPUs
#68Re: Hardware backdoors in some x86 CPUs
#69Earlier quoted context omitted.
Was this documentation public at the time? The pdf still does not document the instructions themselves.
yes, AIS was known sandsifter was lots of noisy PR, but no new encoding findings
Re: Hardware backdoors in some x86 CPUs
#70this is pretty old by now but still very relevant. people dont look at this enough but with rising chip complexities for TPU units etc. and a shift towards poorly documented hardware like NVIDIA gives this problem new fuel. Domas (and maybe his team or colleagues?) has put out shit tons of very interesting materials over the past years on advanced malware, implants and things like Cantor Dust which are amazing things…