3 ms·
Releasing the PSP source code would AFAIK not change a thing. While it might be an interesting read, the PSP (i.e. AMD) would still remain in control of the pla
by moppl 10y ago
Releasing the PSP source code would AFAIK not change a thing. While it might be an interesting read, the PSP (i.e. AMD) would still remain in control of the platform. The PSP does NOT rely on code obfuscation. It is a much deeper architectural problem with he PSP, than the fact that it holds a binary blob.
The designer of the Intel Management Engine (the mother of the PSP) Xiaoyu Ruan wrote in his book "Platform Embedded Security Technology Revealed" in chapter 4:
"By design, the firmware binary should not contain secrets, and hence it is not encrypted or obfuscated in any form. Note that lossless compression may be applied to the code. The firmware binary, in its compression form, is stored on SPI flash in cleartext. At runtime, the code segment is not encrypted when it is paged out to DRAM. Admittedly, advanced hackers have successfully reverse-engineered and disassembled the engine’s firmware binary. However, knowledge of source code is not deemed a harmful threat, because no secrets or keys are ever hardcoded in the code, and the architecture and robustness of the engine does not rely on security through obscurity."
Further in chapter 11:
"Hardware root of trust: Binary code and the data of firmware components are stored in the flash memory in the clear. Encryption is not used because the security architecture does not rely on security through obscurity. The concept of hardware root of trust contains two folds: first, the root of trust for integrity is a hardware ROM (read-only memory). Unlike the firmware in the flash memory, the binary of ROM by design is not available externally. Although, even if the code of ROM is leaked, the security of the engine should not be impacted; second, the EPID (enhanced privacy identification; see Chapter 5 for details) private key and other chipset keys are burned into the engine’s security fuse block in Intel’s factory. These keys comprise the root of trust for confidentiality and privacy for the engine."
https://link.springer.com/book/10.1007%2F978-1-4302-6572-6 https://link.springer.com/book/10.1007%2F978-1-4302-6572-6
So IMHO AMD should be asked to produce a chip without the PSP. Or offer the possibility to disable it. As long as there is a PSP on the system it cannot be fully controlled by the user, even if it's source code should be known. It is a small autonomous computer with it's own CPU, RAM, ROM, clock etc that has fully privileged access to the systems components and can load and run code anytime (so it can run other code than the firmware source code).
Nevertheless I do see that there is a good side to these kinds of petitions and requests. AMD feels that there is interest in the subject.
- bubblethink 10y ago>As long as there is a PSP on the system it cannot be fully controlled by the user, even if it's source code should be known. Why can't you have self-signed PSP/ME firmware ? Why is this not similar to the way android handles bootloaders ? i.e., You either have OEM's keys in the chain, or you have your own. If your employer owns the machine, they do whatever they want. If you own the machine, you do whatever you want.
- analognoise 10y agoIt gives you the illusion of doing whatever you want, but it is still a system with complete and total access that you can't view.
- bubblethink 10y agoWhy is it an illusion if you have the source ? You get the source, build it, sign it, and flash it. You can't verify that CPU will only accept your signed firmware and not something else under special circumstances, but you can't verify those sort of cases in hardware anyway. The CPU is a black box at the end of the day. Edit: Disabling becomes a special case of flashing in this case. Actual hardware disabling will likely never happen because of all the people who use the functionality. The best you can hope for is flashing whatever you want (including nops)
- analognoise 10y agoExactly right; the CPU is a black box. There's nothing stopping a PSP/IME from waking up on a magic packet, executing code that doesn't exists in flash (say, it is cleverly crafted into what looks like dummy transistors used to ensure an equal metallization layer), downloading new firmware from a C&C server, and re-flashing itself. If you want to actually own the hardware, you'd probably need a custom chip layout all done by hand on a planar node so it was easily verifiable by a third party with relatively inexpensive tools; things like dopant-level attacks assume access to the machine physically as far as I know. If you assume that a fab could be hostile, you'd have to zero the foundry attack surface. This hypothetical chip would be dog slow and uncompetitive, but by god, it'd be yours.