In many ways that is why the idea behind the bluray AACS system is briliant (as much as i detest DRM). Its based on the idea of instead of a master key, give each client a different key, which can be revoked (at least for new bluray disks) so that a breach can be mitigated.
How Stuff Gets eXposed
21–30 of 47 posts
Re: How Stuff Gets eXposed
#22I like to draw parallels with the '90s and all of the Pentium bugs. These events really really lit a fire under Intel's ass to get their crap working. Cue decades worth of research and $$$ into formal verif, EDA tooling, and perhaps most importantly, organizational ownership.
Software models, where many security paradigms have been explored decently, don't map too well or don't have a great solution, like fuzzing or linters. So it's kinda hard to provide various security guarantees if you don't have tooling to verify them. Plus, the tools that do exist require domain expertise from the engineer, so the thought to look for some MMIO exploit will never occur to a cache designer.
This kinda turned into a ramble, but ultimately, while I agree I wish Intel would do better, I can't fully fault them since I feel like the whole industry is ill-equipped to provide these security guarantees. Spectre has started some efforts, but it's slow to pickup, which is why it's rather patchwork-y still. Frankly, it kinda feels like the only thing that'll kick asses into gear is some lawsuits, F00F and FDIV style.
P.S. A couple questions--
1) Would you happen to have the "EGX" framework you wrote in Appendix A? That seems massively useful.
2) Can I just screenshot the rubber duck NFT? :)
Re: How Stuff Gets eXposed
#23Earlier quoted context omitted.
AMD has the PSP too.
The PSP is not the same as SGX. That's more like the management engine, and while I agree that both Intel and AMD are shipping that antiuser "feautue" and that AMD had its own implementation of a trusted execution environment like SGX, the current AMD chips do not ship with it. AMD is not perfect, but it's sad that people can choose one or the other and still prefer to hand Intel their money when Intel goes out of th…
As far as I can tell, AMD does currently ship a trusted execution environment supporting remote attestation, namely SEV. However, it’s only supported on server-class processors, so it’s unlikely to be used for DRM.
Re: How Stuff Gets eXposed
#24Earlier quoted context omitted.
AMD has the PSP too.
The PSP is not the same as SGX. That's more like the management engine, and while I agree that both Intel and AMD are shipping that antiuser "feautue" and that AMD had its own implementation of a trusted execution environment like SGX, the current AMD chips do not ship with it. AMD is not perfect, but it's sad that people can choose one or the other and still prefer to hand Intel their money when Intel goes out of th…
Re: How Stuff Gets eXposed
#25Earlier quoted context omitted.
> everyone should be ashamed for using Intel hardware when AMD chips do not abuse the user AMD has their own analog to Intel's Management Engine. Maybe they don't have SGX or something like it, but AMD is no saint either. In theory, SGX can be used for good: see Signal's use to avoid seeing users' contact lists. Granted, their scheme is pretty broken given how broken SGX is (and probably for other reasons), but I thi…
You say we can't force companies to not use tech in anti user ways, but then you'll give them your money becuase you can't find a laptop with an AMD chip. And I assume you just haven't shopped for a laptop long enough or you'd find one that matches your needs without Intel taking a dump on your chest while pretending to care about anything more than your money.
Ultimately we have limited choices in the market, and we have to make compromises. I'm fine running an Intel chip (which doesn't even have SGX, as they don't ship SGX in non-server SKUs anymore), and don't run anything that uses SGX... not sure there's anything written for desktop Linux that I'd use that even tries to use it anyway.
In another post downthread you acknowledge that AMD has their own trusted execution engine (which they don't ship... but neither does Intel, at least in consumer hardware), so for some reason you seem to love AMD and hate Intel when they essentially do the same things.
You also list a bunch of bad stuff Intel has done -- and yes, agreed, they were bad -- but I'm sure AMD has done just as much similar bad stuff. And if not, I'm sure it's not because they're saints, but because they hadn't had the clout of a dominant-enough market position (like Intel has had) that would allow them to get away with things like that. I have no doubt they would have done similar things if they found themselves in similar circumstances. ::shrug::
Either way, this whole "Intel vs. AMD" thing is not really a hill I care do die on... much more important stuff going on in my life.
Re: How Stuff Gets eXposed
#26It's no secret that every time Intel tries to add a Trusted Execution Environment like TrustZone, they somehow manage to screw up. For better or worse, "successful" TEE implementations on other platforms are why we don't have Google Pay or (for many services) 4K streaming on PC. (If everybody was falling apart like SGX, companies may have had to lighten up.) PowerDVD is a bit irrelevant though. PowerDVD no longer sup…
These attacks on SGX are some of the most advanced attacks on any TEE ever. The crappy ARM smartphone vendor TEEs regularly fall apart from mere C bounds issues.
Re: How Stuff Gets eXposed
#27I think the moral of the story is: there will always be bugs. Any application that will catastrophically fail if even a single user experiences a single security relavent bug is doomed to failure. In many ways that is why the idea behind the bluray AACS system is briliant (as much as i detest DRM). Its based on the idea of instead of a master key, give each client a different key, which can be revoked (at least for n…
Sure, DRM has been a huge pain for lots of people, and I don't want to think of the billions of dollars wasted on it that could have gone to more productive things... but ultimately people will find ways around DRM, technical and legal measures be damned.
Re: How Stuff Gets eXposed
#28SGX, the technology which Signal Messenger built a lot of their secure? stuff upon. Like: Technology Preview for secure value recovery https://signal.org/blog/secure-value-recovery/ > Technology preview: Private contact discovery for Signal https://signal.org/blog/private-contact-discovery/ >
Re: How Stuff Gets eXposed
#29> The extraction of these keys would then allow anyone to play UHD Blu-Rays outside of Intel SGX. AS IT SHOULD BE. UHD Blu-Rays are not cheap [1]. If I am going to buy one, I damn sure should able to play it using whatever program I want. Its quite sad how many people have just accepted this reality without a fight. If you buy an apple (the fruit), does the grocery store get to choose what knife you use to cut it, or…
Is all of this DRM actually stopping pirates? No. Is it harming your paying customers? Yes. Not always, but often enough that it discourages people from buying the media.
Re: How Stuff Gets eXposed
#30It's no secret that every time Intel tries to add a Trusted Execution Environment like TrustZone, they somehow manage to screw up. For better or worse, "successful" TEE implementations on other platforms are why we don't have Google Pay or (for many services) 4K streaming on PC. (If everybody was falling apart like SGX, companies may have had to lighten up.) PowerDVD is a bit irrelevant though. PowerDVD no longer sup…
Sure you have to play each movie in full in real time (although maybe you could get around this by spoofing the clock on the playing device somehow?), but you still only need a few people setting up a little movie ripping farm to get retail quality lossless video of everything regardless of how much money anyone puts into DRM nonsense.
The analogue hole makes all of this effort entirely pointless. All reasonably popular non interactive media is going to be available on pirate sites within hours of release no matter what you do, all this does is make life harder for legitimate consumers.