5 ms·
How many exploits/breaches in the wild due to open s3 bucket, default admin passwd to database, poorly written webshit code, plaintext password, etc. ? And how
by bubblethink 6y ago
How many exploits/breaches in the wild due to open s3 bucket, default admin passwd to database, poorly written webshit code, plaintext password, etc. ? And how many prevented by secure boot, boot guard, memory encryption, ME, PSP etc. ? Other than obvious money reasons for Dell, people seem to be vastly overestimating their threat models. And even for the secure chain of trust, there are ways to do so where the owner has the key, not the vendor. See heads for example.
- sedatk 6y agoOr, those scenarios just don't make the news as frequent as script kiddie stuff. We only learned about what NSA has been up to because Snowden happened.
- bubblethink 6y agoThis is the opposite lesson to take away from Snowden's revelations. You want more user control, not less.
- sedatk 6y agoI agree. I’m just saying that news may not be the best indicator of how common an attack vector is.
- young_unixer 6y agoIf I want to protect against the NSA I'm worried about them using Intel ME, AMD PSP and other black boxes to hack me. I don't worry that much about them sneaking into my data center or house and physically changing my hardware. The security you lose from having a black box in your CPU is much greater than the security you win by virtue of being (theoretically) protected against unsigned bootloaders and rogue hardware.
- sedatk 6y agoI merely provided NSA as an example of how advanced attack vectors might go unnoticed for decades.
- temptemptemp111 6y agoNo, everyone with half a brain knew, but was called a conspiracy theorist for years. Then Snowden was a controlled release with virtually the same information, and it was approved by the mainstream media. Plus his stamp of approval was on Signal "for whistleblowers" :P
- argb 6y agoAlthough a PSP flaw is very unlikely to harm an individual user, it puts the US and it's intellectual property at risk from foreign actors such as Russia or China. And many engineering firms do not have the resources of the NSA to protect against such threats. Additionally, a PSP or Intel ME related hack involving a SCADA system would not be discovered until it's too late, with potentially extremely severe consequences. AMD is advertising the processor as being a security device that is intended to enhance system security. If such a SCADA hack involving the PSP was to result in loss of life for example, what would AMD's liability be in such circumstances, where the 'security device' itself has enabled the system to be hacked in the first place? Taking into account that the 'security device' cannot be disabled by the SCADA operator, so they have no choice to use it. That is why I believe the PSP and ME should be removed completely. Should that not be possible it should be replaced with a processor that is transparent to its internal operation.