11 ms·
Chip Red Pill: Arbitrary [Micro]Code Execution Inside Intel Atom CPUs
- blopeur 5y agoChip Red Pill Repos : https://github.com/chip-red-pill https://github.com/chip-red-pill Tool : https://github.com/chip-red-pill/udbgInstr https://github.com/chip-red-pill/udbgInstr Undocumented x86 insts for uarch control : https://github.com/chip-red-pill/udbgInstr/blob/main/paper/undocumented_x86_insts_for_uarch_control.pdf https://github.com/chip-red-pill/udbgInstr/blob/main/paper/u...
- shoo 5y agothanks for linking to the paper, that contains considerably more information
- mleonhard 5y agoSummary: An Intel CPU in "Red Unlock" mode allows any user-mode code to read and write its microcode. The paper teaches security researchers how to do it. They can use it to discover undocumented Intel CPU internals and functionality. I don't know if these instructions will be useful in exploits. They require the CPU to be in Red Unlock mode. One known way to enable Red Unlock requires connecting a special cable to the motherboard's USB port and exploiting the Intel Trusted Execution Engine core [0]. There are probably remote exploits via ethernet and the Intel Management Engine. Could there be some motherboards that shipped with Red Unlock mode permanently enabled? User-mode code running on such machines could trivially root the machine and even escape a hypervisor. [0] https://github.com/ptresearch/IntelTXE-PoC https://github.com/ptresearch/IntelTXE-PoC
- gitowiec 5y ago
- alexb_ 5y agoA lot of their claims sound very scary but I don't really know what to make of this as an average user. Is there an explanation to what this stuff means for me? What security vulnerabilities does this allow for on Intel CPUs? Are they worth worrying about? On a scale of "minor bug" to "every single intel chip is easily able to run arbitrary code and is vulnerable on a hardware level" how bad is this exactly?
- southerntofu 5y ago> "every single intel chip is easily able to run arbitrary code and is vulnerable on a hardware level" It's not just Intel though. Both AMD and Apple also have their own "security processor" running its own operating system without your consent in your own hardware. Essentially this means they own the hardware, not us. I don't know if you would call it that, but to me it sure looks like the definition of a universal backdoor.
- deleted 5y ago[deleted]
- zibzab 5y agoOr, and here is a crazy idea, maybe they use a dedicated security chip to improve isolation and achieve better security? Don't know about apple, but the AMD security firmware has been reverse engineered and no backdoors have so far been found. https://github.com/PSPReverse/PSPTool https://github.com/PSPReverse/PSPTool
- dTal 5y agoSecurity from whom?
- nonrandomstring 5y agoGood to see people starting to ask the right questions; (see Snowden: "Permanent Record", Farnell: "Digital Vegan", Anderson: "Security Engineering") - Security for who? Security from whom? Security to what end? There is no such thing as "bare security". No tide that raises all ships. "Security" is now a constant sum game. Your security is my insecurity.
- OldTimeCoffee 5y agoYes, but then you can probe the pins and MITM, like you can with an external TPM chip. (See something like the TPM Genie) It's internal because it's more secure that way.
- xelxebar 5y ago> All the modern Intel CUPs have a RISC core inside.. This reminds of (yet another) mind-blowing Chris Domas video: https://invidious.snopyta.org/watch?v=jmTwlEh8L7g https://invidious.snopyta.org/watch?v=jmTwlEh8L7g
- blueflow 5y ago... which turned out to be a fraud by scientific standards because they flag he "discovered" was a thing documented in the datasheet.
- c-linkage 5y agoA) He said in the talk that he didn't have the manual for that specific processor. B) The whole talk was about a tool that automated the process of discovering hidden opcodes in a chip.
- userbinator 5y agoHe said in the talk that he didn't have the manual for that specific processor. That doesn't excuse the lack of attention to detail and doing research before spinning it as something new. Especially since this was in the publicly-available datasheet that one could find with very little searching.
- c-linkage 5y agoWhat about the part where he developed a tool that automated the process of discovering hidden opcodes? If _I_ were going to make such a tool, I would use the data sheet to confirm the tool did what it was supposed to. Given that he lacked the data sheet at the time he developed the tool, it still seems pretty impressive that the tool worked.
- blueflow 5y agoThen he should have it presented it as tool to discover hidden opcodes. Everything else is dishonesty.
- kevincox 5y agoThat's a really asshole cookie banner. It looks like only essential cookies are checked, but the big red button accepts all cookies, ignoring the selection. You need to careful read and select the second button to only accept the selected cookies.
- bcraven 5y agoEvery day I am ever thankful for https://www.i-dont-care-about-cookies.eu/ https://www.i-dont-care-about-cookies.eu/
- tgv 5y agoAccepting all cookies is just as easy, and that's what the extension probably does (they say "sometimes", but we all know what that means). Perhaps www.i-dont-care-about-privacy.hr would be a better domain name.
- ajsnigrutin 5y agoNot if you don't save cookies after tab close, and if you have third party cookies disabled.
- chrismorgan 5y agoThe EasyList Cookie filter list (supported out of the box but disabled, in uBlock Origin) covers this too.
- jamesgeck0 5y agoI was able to remove two or three other browser extensions when I started digging into uBlock Origin's capabilities. I also use it as a replacement for NoScript; it's easier to sync my allowlist between multiple computers with uBO than it is with NoScript.
- PinguTS 5y agoJust use the 'Decline' button to the left.
- rocketChair 5y agoIt's getting increasingly difficult to trust American-designed chips and systems for me at this point... and I can't help but feeling that people paid way, way too little attention to everything we learned from the NSA and CIA leaks a few years back.
- deleted 5y ago[deleted]
- jason0597 5y agoIf you don't trust American chips, then what chips do you trust? We certainly don't have much choice when it comes to choosing chips. It's an incredibly expensive process and only a select few superpowers can successfully maintain semiconductor industries.
- rocketChair 5y agoI trust anything made by European companies, NXP, Philips, ST, Siemens etc., anything from Japan, South Korea, and most of the Taiwanese and Chinese companies. Unfortunately, with some rare exception, they're not allowed to make x86-compatible chips, because the U.S. has worked long and hard to forbid the ISA, and everything used so far to implement it, from being standardised and thus kept under an unbelievable weight of patents. Hopefully the build-up of more European fabs, and realisation that the EU has to make its own chips, will eventually remedy some of this.
- AnimalMuppet 5y agoAnd Chinese? They seem... certainly not more trustworthy than US companies.
- rocketChair 5y agoI disagree, an important difference is this: The U.S. has been proven definitely guilty of all accusations of espionage, sabotage, backdoors etc., while there have never been any clear proof presented for the Chinese counterparts -- only accusations, and overwhelmingly from the very country that has committed all the wrongs itself. Take whatever side you want, but at least keep to the truth.
- lr1970 5y agoOne of the authors of the posted article Dmitry Sklyarov of the "United States vs. ElcomSoft and Dmitry Sklyarov" fame [0] was arrested by the FBI in 2001 for giving a talk at the DEF CON exposing the weaknesses in the Adobe e-book copy protection. After spending time in federal detention Dmitry was released and returned to Russia. The charges against him were dropped. [0] https://en.wikipedia.org/wiki/United_States_v._Elcom_Ltd https://en.wikipedia.org/wiki/United_States_v._Elcom_Ltd.
- deleted 5y ago[deleted]
- mlindner 5y agoYour link doesn't actually say the same thing as your post. The charges weren't dropped. He was tried and found not guilty.
- tfvlrue 5y ago> The U.S. government agreed to drop all charges filed against Sklyarov, provided that he testify at the trial of his company. I think the confusion is that there were charges filed against both him and the company he worked for, the former of which were dropped if he testified at company's trial (which was ultimately found not guilty).