4 ms·
Oh, sorry for the dead link. So I repost it here: "Hello!? Releasing the source code would NOT change the fundamental problem with the PSP! It will still remai
by moppl 10y ago
Oh, sorry for the dead link. So I repost it here:
"Hello!? Releasing the source code would NOT change the fundamental problem with the PSP! It will still remain a black box under the control of the manufacturer! The problem is not the obfuscation of the source code, it is a much deeper platform architecture issue.
The PSP is a universal computer with it's own CPU, RAM, ROM, clock etc, that can run whatever software AMD wants it to run, hidden from the user. It could load software anytime without you even noticing. AMD controls the PSP by using unique cryptographic keys which are burnt into each PSP.
As the Intel IME engineer Xiaoyu Ruan wrote in his book "Platform Embedded Security Technology Revealed", the security architecture of the IME does not rely on security through obscurity, it relies much more on the burnt in cryptographic keys and it's architecture. The designers of the IME took into account that the firmware might be unscrambled and realeased by somebody, so they designed it in a way that this would not compromise it.
Even if you have it's source code (it's OS so to speak), there is no way for the user to tell what software it has loaded into memory and what it is doing at the moment (since it is a universal computer in its own right which offers no interface to the user). It is a parallel world on the platform the user has no access to (while the PSP has fully privileged access to all the users resources).
So the only real way to support Coreboot/Libreboot would be to remove the PSP completely (which is probably not possible, since it became an integral part of the system) or to offer the option to disable it and/or feed it with one's own cryptographic keys.
IMHO it stays an uncontrollable risk as long as there is an PSP on the platform (likewise the IME on Intel platforms). The source code doesn't make a difference. The only advantage of releasing the source would be, that it could be checked for potential security risks to avoid hostile takeovers of the PSP (which would be a true disaster).
So don't be naive, don't believe this hype."
To further answer your question (as far as I am able to do that), if the PSP is _completely laid open, it would not change its fundamental design, and it would not allow you to put your own firmware. It would be necessary to know its burnt in and unique cryptographic keys, to be able to load your own firmware/software. I would say those cryptographic keys are the crown jewels of the PSP (or IME), which allow you to take control of the PSP. And those are (hopefully) only known to the manufacturer and will not be released with the source code ;)
The problem is cast in silicon so to speak.
- i336_ 10y agoThanks for the paste! I'm curious what user it was from (anything you put on the Internet, stays on the Internet...). And thanks for the explanation about the crypto keys in the PSP. That makes perfect sense, and it's really sad that this is a case of a security architecture that is literally founded upon obscurity (ie, keeping the keys secret). So the only real solution here would be for AMD to release a PSP firmware that essentially did nothing. I can only hope the people that AMD talk to will explain that this is the sort of approach that would be needed. Being able to disable enterprise security solutions for my non-enterprise desktop and know they are off would be awesome - and that's all I'd need. As an aside, I commented in this thread - https://news.ycombinator.com/item?id=13782508 https://news.ycombinator.com/item?id=13782508 - regarding the potential existence of ME keys in the wild. Really reassuring...
- Ajedi32 10y ago> a case of a security architecture that is literally founded upon obscurity (ie, keeping the keys secret) Huh? Relying on the secrecy of keys rather than secrecy of the code is the _exact opposite_ of security through obscurity.
- DigitalJack 10y agoI can see their point. One can view obscurity as "not common knowledge" or "information that can be found if you look hard enough." A secret key technically falls in the later. You have it somewhere. If someone looks hard enough, they can find it. It may take ridiculous effort to the point of being impractical, but that is still obscurity. I recognize that when people speak of "security through obscurity" they are referring to esoteric knowledge that is difficult but not impractical to find.
- moppl 10y agoRuan writes in his book in chapter 4 "The Engine: Safeguarding Itself before Safeguarding Others": "In addition, there is a basic guideline for realizing security: Never rely on security through obscurity. When designing security hardening features for the engine, it is always assumed that all firmware source code and internal architecture documentation may be obtained by attackers. The engine’s security design principle is to harden the product by applying proven cryptography and security primitives, rather than rely on hiding secrets in the code or documents." So they cast their secrets in silicon I guess, which would be incomparably harder to recover.