Earlier quoted context omitted.
A poorly documented or undocumented (debugging) backdoor in a chip marketed for ATMs and medical hardware, enabled by default, at the very least qualifies as reckless endangerment.
Not really. A properly designed network should take account for such things as unknown/irreparable flaws. An irreparable backdoor in a device can be mitigated with a gatekeeper, something akin to a firewall that will not allow a threat actor to have access to a faulty device. The real recklessness would be allowing an ATM unfettered access to the internet on the assumption that the manufacturer has already protected…
Hardware backdoors in some x86 CPUs
101–110 of 117 posts
Re: Hardware backdoors in some x86 CPUs
#102Earlier quoted context omitted.
Sure but the cops aren't going to pull you over based on what you think about Chinese policy. Government do mess with people across international borders, but the capacity to do that is inherently limited.
> Sure but the cops aren't going to pull you over based on what you think about Chinese policy. You might be surprised to learn that China has operated clandestine prisons in the US! https://www.justice.gov/archives/opa/pr/two-arrested-operati...
Bruh, I am not "gaming the system", the CIA (Central Intelligence Agency) is gaming the system.
Re: Hardware backdoors in some x86 CPUs
#103Earlier quoted context omitted.
Not really. A properly designed network should take account for such things as unknown/irreparable flaws. An irreparable backdoor in a device can be mitigated with a gatekeeper, something akin to a firewall that will not allow a threat actor to have access to a faulty device. The real recklessness would be allowing an ATM unfettered access to the internet on the assumption that the manufacturer has already protected…
I was basically going to quote your whole statement here and then point to the more than 19 US states that have had Water Treatment plants forced to disconnect much of their Operational Technology systems.
Re: Hardware backdoors in some x86 CPUs
#104(2018) And "x86" sort of gives the wrong impression -- this isn't an AMD or Intel chip; it's a 2001-era VIA chip.
Intel chips also have a hardware backdoor in the form of a separate core that the neither the user nor the installed operating system control. Intel Management Engine: https://www.wikipedia.org/wiki/Intel_Management_Engine As do AMD chips: AMD Platform Security Processor: https://www.wikipedia.org/wiki/AMD_Platform_Security_Process...
Re: Hardware backdoors in some x86 CPUs
#105Earlier quoted context omitted.
Every definition of a “backdoor” in computing implicitly or explicitly considers it hidden/covert. In the house analogy you don’t see the backdoor when approaching the front. If it was just “an alternative everyone knows about and can be broken easier than the front door” then it probably would have been called “a window”. Most login forms have a weaker option like a SMS 2FA or password reset fallback. Nobody calls i…
The Free Software Foundation (FSF) calls the update system used in Windows 10 a "back door" [1], I think because it installs updates automatically. This sounds like nonsense to me, because it implies that I installed a back door on my own machine by enabling automatic upgrades (on Trisquel). It's meaningful that the Windows 10 install method has no (official) way to disable it, but I don't think making something opti…
Re: Hardware backdoors in some x86 CPUs
#106This shows that large companies making closed-source CPUs cannot be trusted. No doubt they would add whatever the government asks them to add. What can be done to mitigate this? One option would be to buy a large FPGA and flash it with an open-source CPU. Another would be to emulate a CPU, working with encrypted data and commands, so that even if the backdoor in a host CPU tries to overwrite memory, it would only cra…
5 here: https://cybersecuritynews.com/bug-bounty-platforms/
The issue are "bugs" could be randomly distributed, even across the same version number of some device.
Sample sizes and statistics come into play at that point.
Whistleblower protections are an avenue, but people can still be dealt with harshly (Schulte) and degree-of-protection can come down to motive. But motive itself is multivariate, is it not? A local-first Fediverse, with some type of "guaranteed anonymity" would work, though. But anonymity doesn't mean something can't be a hoax either, so it becomes a signal vs noise issue at that point. Yet, "nothing totally secure ever really is."
Source information can be embedded in the period of a printed sentence too.
A moral world is the answer to many problems. Something to ponder. People are said to only see the errors in their ways after death in the "hall of mirrors."
-- https://web.archive.org/web/20060102095331/http://maitreya-e...
Economic espionage is something to also think about. You may be doing everything right and that's what makes you a target. "If I'm not top dog, target anyone that is."
Perfect anonymity in crypto can also aid whistleblowing so that dump data = get paid.
Re: Hardware backdoors in some x86 CPUs
#107Earlier quoted context omitted.
I recently got an air purifier. The touch button controls for adjusting the fan speed didn't seem to be working, so I emailed support. They had me download their app, link the air purifier, and give them its MAC address. Then they asked me to try pressing each of the buttons a few times and email them back. I did so, and they responded that they re-calibrated the buttons using my touch samples. It worked.
That’s insane. I actively avoid buying things that are pointlessly internet connected nowadays. An air purifier’s buttons should be simple electromechanical switches.
Re: Hardware backdoors in some x86 CPUs
#108this is pretty old by now but still very relevant. people dont look at this enough but with rising chip complexities for TPU units etc. and a shift towards poorly documented hardware like NVIDIA gives this problem new fuel. Domas (and maybe his team or colleagues?) has put out shit tons of very interesting materials over the past years on advanced malware, implants and things like Cantor Dust which are amazing things…
I didn't know what Cantor Dust was, and had to click through a few different search results to get past all the abstract descriptions and begin to form a basic idea. In a nutshell, I understand them as a sort of "blockie" for binary data formats. Things like WAV audio files, bitmaps, ASCII text, machine code, etc. each generate their own distinct visual signature (but different examples within any of these categories…
See also ECB penguin [1]
Re: Hardware backdoors in some x86 CPUs
#109This shows that large companies making closed-source CPUs cannot be trusted. No doubt they would add whatever the government asks them to add. What can be done to mitigate this? One option would be to buy a large FPGA and flash it with an open-source CPU. Another would be to emulate a CPU, working with encrypted data and commands, so that even if the backdoor in a host CPU tries to overwrite memory, it would only cra…
It's not just the government. The government sneakily adds stuff they think only they can exploit, but skilled non-state actors can exploit hardware features regardless of whether it was put there by the government. And as we get widespread diffusion of increasingly capable AI, it will become easy and cheap to do for pretty much anyone, and so will defense. Assuming bio-digital integration continues (i.e., humans kee…
Which you already do not have. And what you do have, is being eroded further.
You live in a world where you can be forcibly caged for a faulty manipulation of symbols you did not even consent to learning! You can be caged for doing things for your "own" body; in turn, repairs to your body can be denied and even deemed "impossible" because your physical existence threatens someone's illusions.
Maybe hunter-gatherer bands could've been said to have been autonomous. But the individual? Simply a replaceable embodiment for vast, impersonal forces. Your body and mind have always been property of the society that manufactured you. You do not own even your cherished the illusion of autonomy; it's just another behavior taught to you to make you produce more for your masters.
Re: Hardware backdoors in some x86 CPUs
#110this is pretty old by now but still very relevant. people dont look at this enough but with rising chip complexities for TPU units etc. and a shift towards poorly documented hardware like NVIDIA gives this problem new fuel. Domas (and maybe his team or colleagues?) has put out shit tons of very interesting materials over the past years on advanced malware, implants and things like Cantor Dust which are amazing things…
A poorly documented or undocumented (debugging) backdoor in a chip marketed for ATMs and medical hardware, enabled by default, at the very least qualifies as reckless endangerment.