6 ms·
PSPTool author here. Since all PSP firmware must be signed by AMD, something like a psp_cleaner would be possible given that a bug in the firmware allows to inj
by cwerling 7y ago
PSPTool author here. Since all PSP firmware must be signed by AMD, something like a psp_cleaner would be possible given that a bug in the firmware allows to inject arbitrary code. This was shown by CTS-Labs earlier. [1]
[1] https://msrnd-cdn-stor.azureedge.net/bluehat/bluehatil/2019/assets/doc/The%20AMDFlaws%20Story%20Technical%20Deep%20Dive.pdf https://msrnd-cdn-stor.azureedge.net/bluehat/bluehatil/2019/...
- ebcode 7y agothanks for posting the link. looking forward to the day when we can run post-2012 cpus knowing we'll be able to lock the backdoor.
- StudentStuff 7y agoWow, only the header is signed (for the Ryzenfall-1 bug)? That is a pretty big oversight, did AMD attempt to patch these bugs?
- zanny 7y agoIf there is anything these secret proprietary built in hardware backdoors are its that they are very poorly thought out.
- fwip 7y agoIt does seem to be a pattern. I can think of a few reasons off the top of my head: 1. Incompetence - The engineers try to get it right, but fail due to skill, budget or time constraints. 2. Malice - This allows bad actors to compromise the PSP for evil 3. Benevolence - This allows hardware owners to alter the PSP for their own protection. I think the smart money is on #1, but they're all interesting to think about.
- StudentStuff 7y agoARM is the designer of the PSP, if its incompetence then they're the ones at fault. AMD states that the PSP is "ARM TrustZone ... Industry standard" https://www.amd.com/en/technologies/security https://www.amd.com/en/technologies/security
- rurban 7y agoThat's supposed for data-only modules, so they can patch in live data later, without the need to fetch it from some flash or bios. I think no-one should call code from it.
- ilikenwf 7y agoWould this be something you would be interested in implementing? I still use Intel stuff only because no psp_cleaner exists yet. I think the coreboot guys would also be interested in something like this, too.