4 ms·
One of the interesting points raised in the original Trusting Trust paper was exactly this - that next level of trust can again be subverted via microcode modif
by drvdevd 10y ago
One of the interesting points raised in the original Trusting Trust paper was exactly this - that next level of trust can again be subverted via microcode modification, and so on and so forth. I really don't view Trusting Trust (in the original paper) as an attack so much as a philosophical question being asked about trust in general and the way it propagates through supply chains. It's almost a paper more on economics than anything else..
- Manishearth 10y ago> I really don't view Trusting Trust (in the original paper) as an attack so much as a philosophical question being asked about trust in general Yep. This was the original intention of the talk/paper; it was about _trust_, not attacking compilers. Attacking compilers is just a super cool example that was used.
- rudolf0 10y agoOnce intelligence agencies start backdooring microcode (especially in a way that chip manufacturers can't detect), I'm throwing out my computer and living in the woods.
- oldsj 10y agoHow would you know if they did?
- rudolf0 10y agoI suspect someone somewhere would eventually find out.
- SomeStupidPoint 10y agoIf you're in a situation where it matters, the safe assumption would be Intel chips have been backdoored a while, and others likely are too.
- bluejekyll 10y agoAgreed. If it matters this much to you, better move now. I'm not even sure that the open source RISC-V initiative might prevent this, as theoretically the NSA could gain access to the manufacturing plant and insert their own core. The only way to catch that at that point would be to X-ray the chip and look for their mod, or something. Anyway, assume the NSA has access to your shit, focus on preventing the random from grabbing your bank account access and stealing your money.