Live data from Hacker News

Hardware backdoors in some x86 CPUs

github.com

71–80 of 105 posts

Re: Hardware backdoors in some x86 CPUs

#71

this is pretty old by now but still very relevant. people dont look at this enough but with rising chip complexities for TPU units etc. and a shift towards poorly documented hardware like NVIDIA gives this problem new fuel. Domas (and maybe his team or colleagues?) has put out shit tons of very interesting materials over the past years on advanced malware, implants and things like Cantor Dust which are amazing things…

I didn't know what Cantor Dust was, and had to click through a few different search results to get past all the abstract descriptions and begin to form a basic idea. In a nutshell, I understand them as a sort of "blockie" for binary data formats. Things like WAV audio files, bitmaps, ASCII text, machine code, etc. each generate their own distinct visual signature (but different examples within any of these categories…

Fascinating, thanks for sharing. A candor dust guessing game would be pretty fun to play

Re: Hardware backdoors in some x86 CPUs

#72

Earlier quoted context omitted.

They should have mentioned that in the first line of the github readme, not burried deep down in the text.

Buried? Deep down? The fourth paragraph, clearly labeled "Affected Systems", a minute or two into the read.

They knew what they were doing by not including "VIA C3 CPUs" before the fourth paragraph. Come on. It should have been in the title.

Re: Hardware backdoors in some x86 CPUs

#73
post #31

Earlier quoted context omitted.

backdoor means a secondary access point that defeats the security features of the primary. In the door analogy, the home owner spends a ton on a lock and camera for the front door but doesn't even have a deadbolt on the back.

Every definition of a “backdoor” in computing implicitly or explicitly considers it hidden/covert. In the house analogy you don’t see the backdoor when approaching the front. If it was just “an alternative everyone knows about and can be broken easier than the front door” then it probably would have been called “a window”. Most login forms have a weaker option like a SMS 2FA or password reset fallback. Nobody calls i…

The Free Software Foundation (FSF) calls the update system used in Windows 10 a "back door" [1], I think because it installs updates automatically. This sounds like nonsense to me, because it implies that I installed a back door on my own machine by enabling automatic upgrades (on Trisquel).

It's meaningful that the Windows 10 install method has no (official) way to disable it, but I don't think making something optional could make it not a back door, if it was one before.

Even when automatic updates are disabled, I'm not going to be reading every update so the effect seems mostly the same, regardless of whether updates are automatic or not.

The FSF's definition of "back door" (at the bottom of the linked page) is "any feature of a program that enables someone who is not supposed to be in control of the computer where it is installed to send it commands" which leaves a lot of ambiguity with the words "supposed to be". I am not sure how to interpret this definition.

[1] https://www.gnu.org/proprietary/proprietary-back-doors.html#...

Re: Hardware backdoors in some x86 CPUs

#74
post #6

This backdoor only appears on decades-old VIA C3 embedded x86 processors

It's not even a "backdoor", it's documented in the datasheet... http://datasheets.chipdb.org/VIA/Nehemiah/VIA%20C3%20Nehemia... (page 82) ...which along with the already publicly-known microarchitecture of the C3 makes this statement sound like total nonsense: The rosenbridge backdoor is a small, non-x86 core embedded alongside the main x86 core in the CPU I remember laughing at this with a few others knowledgeable i…

The documentation was locked away behind NDAs when the faulty BIOS leaving it reachable was discovered. Look at the publication dates.

Re: Hardware backdoors in some x86 CPUs

#75
post #62
post #6

This backdoor only appears on decades-old VIA C3 embedded x86 processors

TBF the specific backdoor isn’t the point of the article. It’s a cautionary tale. The point is that practically all systems above the MCU level, and even some of those, have lower level systems that are often undocumented or not intended for use by the hardware designers, much less the end users. Those systems often have extremely low level access to system resources. For example, I am building a device that records…

I recently got an air purifier. The touch button controls for adjusting the fan speed didn't seem to be working, so I emailed support.

They had me download their app, link the air purifier, and give them its MAC address. Then they asked me to try pressing each of the buttons a few times and email them back. I did so, and they responded that they re-calibrated the buttons using my touch samples. It worked.

Re: Hardware backdoors in some x86 CPUs

#78

this is pretty old by now but still very relevant. people dont look at this enough but with rising chip complexities for TPU units etc. and a shift towards poorly documented hardware like NVIDIA gives this problem new fuel. Domas (and maybe his team or colleagues?) has put out shit tons of very interesting materials over the past years on advanced malware, implants and things like Cantor Dust which are amazing things…

I didn't know what Cantor Dust was, and had to click through a few different search results to get past all the abstract descriptions and begin to form a basic idea. In a nutshell, I understand them as a sort of "blockie" for binary data formats. Things like WAV audio files, bitmaps, ASCII text, machine code, etc. each generate their own distinct visual signature (but different examples within any of these categories…

This is excellent!

Re: Hardware backdoors in some x86 CPUs

#79
post #57
post #55

Earlier quoted context omitted.

If many people do this then I'm sure China will find some uses for that data at some point.

Sure but the cops aren't going to pull you over based on what you think about Chinese policy. Government do mess with people across international borders, but the capacity to do that is inherently limited.

Can't Chinese government exchange the data with your government whenever they need it?

Re: Hardware backdoors in some x86 CPUs

#80
post #57
post #55

Earlier quoted context omitted.

If many people do this then I'm sure China will find some uses for that data at some point.

Sure but the cops aren't going to pull you over based on what you think about Chinese policy. Government do mess with people across international borders, but the capacity to do that is inherently limited.

> Sure but the cops aren't going to pull you over based on what you think about Chinese policy.

You might be surprised to learn that China has operated clandestine prisons in the US!

https://www.justice.gov/archives/opa/pr/two-arrested-operati...

Post reply on HN