Live data from Hacker News

Hardware backdoors in some x86 CPUs

github.com

111–119 of 119 posts

Re: Hardware backdoors in some x86 CPUs

#111
post #101

Earlier quoted context omitted.

I was basically going to quote your whole statement here and then point to the more than 19 US states that have had Water Treatment plants forced to disconnect much of their Operational Technology systems.

And those disconnects would be that effective gatekeeper. Maybe overkill, but "air gapping" is a often a reasonable mitigation.

it is not overkill to airgap OT tech. having it on the internet is really braindead.

most ones that are routable are hackable real easily. the only reason no one does it is because they dont need to or dont want to.

more people should do this. there should be laws to prevent such systems to be connected to others.

main problem is often billing systems and sometimes OT stuff will need things like weather info or external data which makes it harder or more expensive to effectively airgap. remote places are also a pain to maintain if u cant connect into them.

this is why most of these places rely on not being routable over most internet, so u vpn to some place and connect in from there. Sibsequently many engineers will not properly secure OT because its not routable.

then a routing mistake happen at ISP and oops all the boxes are rooted -_-.

airgapping is not overkill.

Re: Hardware backdoors in some x86 CPUs

#112

Earlier quoted context omitted.

It's not just the government. The government sneakily adds stuff they think only they can exploit, but skilled non-state actors can exploit hardware features regardless of whether it was put there by the government. And as we get widespread diffusion of increasingly capable AI, it will become easy and cheap to do for pretty much anyone, and so will defense. Assuming bio-digital integration continues (i.e., humans kee…

>bodily integrity and autonomy Which you already do not have. And what you do have, is being eroded further. You live in a world where you can be forcibly caged for a faulty manipulation of symbols you did not even consent to learning ! You can be caged for doing things for your "own" body; in turn, repairs to your body can be denied and even deemed "impossible" because your physical existence threatens someone's ill…

That's a somewhat accurate description, and you could even replace "society" with "universe". But what I'm defending is precisely the apparent feeling of autonomy, which is just called "autonomy" in colloquial terms omitting the philosophical baggage. I don't think it's fair to call this illusory, because you have no basis to define what an illusion is if you accept that all you know and all that you are is the product of universal influence. Included in that universal influence is every instance of experience from which your understanding of the concept of "illusion" was derived, so "illusion"/"real" would refer to the same thing in your worldview.

Now, taking a pragmatic materialist stance: we are obviously bound by physics and cannot move in certain ways. We can predict what action a person will take from their brain activity before the person becomes aware of their decision themselves. But what the brain does to convince you that oneself is in control is probably the exact thing that's required for life to thrive. It was the evolutionary path taken, and it's also the future I strive for, and I hope others would do the same.

Re: Hardware backdoors in some x86 CPUs

#113

This shows that large companies making closed-source CPUs cannot be trusted. No doubt they would add whatever the government asks them to add. What can be done to mitigate this? One option would be to buy a large FPGA and flash it with an open-source CPU. Another would be to emulate a CPU, working with encrypted data and commands, so that even if the backdoor in a host CPU tries to overwrite memory, it would only cra…

[dead]

Re: Hardware backdoors in some x86 CPUs

#114
post #62

Earlier quoted context omitted.

TBF the specific backdoor isn’t the point of the article. It’s a cautionary tale. The point is that practically all systems above the MCU level, and even some of those, have lower level systems that are often undocumented or not intended for use by the hardware designers, much less the end users. Those systems often have extremely low level access to system resources. For example, I am building a device that records…

I recently got an air purifier. The touch button controls for adjusting the fan speed didn't seem to be working, so I emailed support. They had me download their app, link the air purifier, and give them its MAC address. Then they asked me to try pressing each of the buttons a few times and email them back. I did so, and they responded that they re-calibrated the buttons using my touch samples. It worked.

Feels like having touch calibration procedure built into firmware and documented in the manual (remember those?) would also work.

Re: Hardware backdoors in some x86 CPUs

#115

Earlier quoted context omitted.

That’s insane. I actively avoid buying things that are pointlessly internet connected nowadays. An air purifier’s buttons should be simple electromechanical switches.

By "touch buttons" possibly he means that they are "buttons" on a touch screen. What's crazy to me is that this is now cheaper to put in a product than electromechanical switches.

It's a Mila, they're capacitive touch buttons but not a touchscreen. There's just a fan down, fan up, and mode button. Even still, I don't know how they got the calibration wrong enough at the factory that it can't detect a full-pressure thumb press.

Re: Hardware backdoors in some x86 CPUs

#116

Earlier quoted context omitted.

> Sure but the cops aren't going to pull you over based on what you think about Chinese policy. You might be surprised to learn that China has operated clandestine prisons in the US! https://www.justice.gov/archives/opa/pr/two-arrested-operati...

> "This is gaming the system, changing the post between this and https://news.ycombinator.com/item?id=49073612 edit for clarity: the submitter kept changing the title and body between this and the linked post. This was the "mistaken duplicate" before." Bruh, I am not "gaming the system", the CIA (Central Intelligence Agency) is gaming the system.

[deleted]

Re: Hardware backdoors in some x86 CPUs

#117
post #43

Earlier quoted context omitted.

We have shorter attention spans now.

Multiple things can be true at the same time. While we do have shorter attention spans, some (lots of?) developers absolutely suck at writing articles

And some intentionally write clickbait headlines even though the have the skills to do better.

Re: Hardware backdoors in some x86 CPUs

#118
post #31

Earlier quoted context omitted.

Every definition of a “backdoor” in computing implicitly or explicitly considers it hidden/covert. In the house analogy you don’t see the backdoor when approaching the front. If it was just “an alternative everyone knows about and can be broken easier than the front door” then it probably would have been called “a window”. Most login forms have a weaker option like a SMS 2FA or password reset fallback. Nobody calls i…

The Free Software Foundation (FSF) calls the update system used in Windows 10 a "back door" [1], I think because it installs updates automatically. This sounds like nonsense to me, because it implies that I installed a back door on my own machine by enabling automatic upgrades (on Trisquel). It's meaningful that the Windows 10 install method has no (official) way to disable it, but I don't think making something opti…

I agree with any automatic updates being a back door.

Doesnt really matter which platform, automatic updates are bad news.

On windows it led to clownstrike. On BMW it led to dash ads.

Theres infinite examples of auto updates being an attack vector for OEMs and other bad actors.

Always disable updates on every product. Can always reenable as needed or even sideload updates.

Re: Hardware backdoors in some x86 CPUs

#119
post #31

Earlier quoted context omitted.

backdoor means a secondary access point that defeats the security features of the primary. In the door analogy, the home owner spends a ton on a lock and camera for the front door but doesn't even have a deadbolt on the back.

Every definition of a “backdoor” in computing implicitly or explicitly considers it hidden/covert. In the house analogy you don’t see the backdoor when approaching the front. If it was just “an alternative everyone knows about and can be broken easier than the front door” then it probably would have been called “a window”. Most login forms have a weaker option like a SMS 2FA or password reset fallback. Nobody calls i…

I like where this is going.

Can we refer to user data as “the garage”?

And instead of hackers they should be “coons”.

The headlines can read: ”Buncha Coons In The Garage Again”

It’s more quaint

Post reply on HN