Live data from Hacker News

Undocumented x86 instructions in Intel CPUs that can modify microcode

twitter.com

1–10 of 145 posts

Re: Undocumented x86 instructions in Intel CPUs that can modify microcode

#2
The followup tweet indicates that the CPU has to be in an unlocked state before this is possible, which on a typical system requires there to be a Management Engine vulnerability first. Given what we currently know, this is going to be interesting for people interested in researching the behaviour and security of Intel CPUs and might well lead to discovery of security issues in future, but in itself I don't think this is dangerous.

Edit to add: https://www.intel.com/content/dam/www/public/us/en/security-... is a discussion of a previous Intel security issue which includes a description (on page 6) of the different unlock levels. This apparently requires that the CPU be in the Red unlock state, which (in the absence of ME vulnerabilities) should only be accessible by Intel.

Re: Undocumented x86 instructions in Intel CPUs that can modify microcode

#3
post #2

The followup tweet indicates that the CPU has to be in an unlocked state before this is possible, which on a typical system requires there to be a Management Engine vulnerability first. Given what we currently know, this is going to be interesting for people interested in researching the behaviour and security of Intel CPUs and might well lead to discovery of security issues in future, but in itself I don't think thi…

[deleted]

Re: Undocumented x86 instructions in Intel CPUs that can modify microcode

#4
post #2

The followup tweet indicates that the CPU has to be in an unlocked state before this is possible, which on a typical system requires there to be a Management Engine vulnerability first. Given what we currently know, this is going to be interesting for people interested in researching the behaviour and security of Intel CPUs and might well lead to discovery of security issues in future, but in itself I don't think thi…

So you mean, if I am a state actor able to kidnap the child of an Intel high level employee... say I m Joe Biden, I can ask Intel to... remote unlock my CPU and read arbitrary memory block ?

Or you mean Intel had to physically handle your CPU with a debug cable or whatever ?

Cause I really dont feel it s okay that the only safety we have from a newly discovered exploit is that there needs to be another newly discovered exploit :D

Re: Undocumented x86 instructions in Intel CPUs that can modify microcode

#5
Nothing against the original post (which just says what they found), but this seems to be really overblown. Yes, of course Intel has instructions to update the micro code, since that's a thing that they do. Neither is it particularly surprising that they didn't bother to document operations that only they would ever have reason to use (in their eyes). If, as sibling comment notes, you have to be in a specific unlocked state to use this instruction, it should be perfectly safe assuming someone hasn't compromised other layers of security. So yes, this is certainly interesting, and it could be used as part of a chain of exploits to do some really nasty things, but by itself this seems like barely news?

Re: Undocumented x86 instructions in Intel CPUs that can modify microcode

#6
post #4
post #2

The followup tweet indicates that the CPU has to be in an unlocked state before this is possible, which on a typical system requires there to be a Management Engine vulnerability first. Given what we currently know, this is going to be interesting for people interested in researching the behaviour and security of Intel CPUs and might well lead to discovery of security issues in future, but in itself I don't think thi…

So you mean, if I am a state actor able to kidnap the child of an Intel high level employee... say I m Joe Biden, I can ask Intel to... remote unlock my CPU and read arbitrary memory block ? Or you mean Intel had to physically handle your CPU with a debug cable or whatever ? Cause I really dont feel it s okay that the only safety we have from a newly discovered exploit is that there needs to be another newly discover…

Don't use CPUs from companies that have employees that can be kidnapped.

Re: Undocumented x86 instructions in Intel CPUs that can modify microcode

#7
post #4
post #2

The followup tweet indicates that the CPU has to be in an unlocked state before this is possible, which on a typical system requires there to be a Management Engine vulnerability first. Given what we currently know, this is going to be interesting for people interested in researching the behaviour and security of Intel CPUs and might well lead to discovery of security issues in future, but in itself I don't think thi…

So you mean, if I am a state actor able to kidnap the child of an Intel high level employee... say I m Joe Biden, I can ask Intel to... remote unlock my CPU and read arbitrary memory block ? Or you mean Intel had to physically handle your CPU with a debug cable or whatever ? Cause I really dont feel it s okay that the only safety we have from a newly discovered exploit is that there needs to be another newly discover…

Remotely? I think Intel would need to produce a backdoored ME firmware, get the system vendor to incorporate that into a system update and then convince the target to flash that. In that sense I don't know that they'd technically need physical access, but it doesn't really meet most people's description of a remote attack.

Re: Undocumented x86 instructions in Intel CPUs that can modify microcode

#8
post #4

Earlier quoted context omitted.

So you mean, if I am a state actor able to kidnap the child of an Intel high level employee... say I m Joe Biden, I can ask Intel to... remote unlock my CPU and read arbitrary memory block ? Or you mean Intel had to physically handle your CPU with a debug cable or whatever ? Cause I really dont feel it s okay that the only safety we have from a newly discovered exploit is that there needs to be another newly discover…

Don't use CPUs from companies that have employees that can be kidnapped.

Don't use CPUs from companies that have employees.

Re: Undocumented x86 instructions in Intel CPUs that can modify microcode

#9

Nothing against the original post (which just says what they found), but this seems to be really overblown. Yes, of course Intel has instructions to update the micro code, since that's a thing that they do. Neither is it particularly surprising that they didn't bother to document operations that only they would ever have reason to use (in their eyes). If, as sibling comment notes, you have to be in a specific unlocke…

Should products be fully documented so that consumers can make an informed decision?

Re: Undocumented x86 instructions in Intel CPUs that can modify microcode

#10
post #4
post #2

The followup tweet indicates that the CPU has to be in an unlocked state before this is possible, which on a typical system requires there to be a Management Engine vulnerability first. Given what we currently know, this is going to be interesting for people interested in researching the behaviour and security of Intel CPUs and might well lead to discovery of security issues in future, but in itself I don't think thi…

So you mean, if I am a state actor able to kidnap the child of an Intel high level employee... say I m Joe Biden, I can ask Intel to... remote unlock my CPU and read arbitrary memory block ? Or you mean Intel had to physically handle your CPU with a debug cable or whatever ? Cause I really dont feel it s okay that the only safety we have from a newly discovered exploit is that there needs to be another newly discover…

It is public knowledge that US intelligence agencies actually just hijack computers and equipment on their way to the customer and install hardware backdoors there (Snowden et al., 2014).

It is also known that they have had backdoors in commercial systems as they came off the shelf, but I think usually those were CIA owned and controlled companies like the crypto AG phones.

What is unknown (pure speculation) is whether, for example, Intel CPUs come backdoored straight from the factory floor? On the one hand, that would be a powerful capability to have, but on the other hand, the risk of exposure and subsequent damage to the US economy, prestige, etc. would be non-zero. So it's hard (for a plebian like me, anyway) to estimate how those costs/benefits might be weighed up by the US government.

Post reply on HN