8 ms·
Since Intel/AMD also designs the processor they can also put in backdoors beyond ME, microcode updates, etc. If you don’t trust proprietary blobs, I respect tha
by osy 6y ago
Since Intel/AMD also designs the processor they can also put in backdoors beyond ME, microcode updates, etc. If you don’t trust proprietary blobs, I respect that. But you can’t trust proprietary silicon either.
- fsflover 6y agohttps://en.wikipedia.org/wiki/Defence_in_depth https://en.wikipedia.org/wiki/Defence_in_depth
- burnte 6y agoDefense in depth fails when the attacker has unrestricted access to the core of your defense infrastructure.
- ramshorns 6y agoYeah, microcode updates are proprietary software too. The weird result is that if you want a system with no proprietary software, you end up having to use the original microcode which is burned onto the chip and counts as hardware. It's not a perfect solution but maybe it's a reasonable place to draw the line, until we have open source hardware processors using RISC-V or something.
- fakename11 6y agoThen you have to accept all the bugs with the original...
- notwedtm 6y ago...and that a backdoor wasn't written into the original microcode, or that a state-sponsored actor didn't intercept during shipping...