20 ms·
Intel Microcode Decryptor
- LeonTheremin 4y agoBrazilian Electronic Voting Machines use Intel Atom CPUs. Any backdoor found in microcode for these is going to be a big event.
- dyingkneepad 4y agoThere are SO many easier attack vectors for the urna eletrônica that you don't need to worry about this. I'm not implying there is anybody actually attacking them, but if I were to commit election fraud I wouldn't look at low level microcode backdoors.
- hulitu 4y agoWhy not ? This would be the perfect election interference.
- sroussey 4y agoHack the tabulating machines. So much easier and they are the only ones that humans actually look at.
- walterbell 4y agoWhy not both?
- thrashh 4y agoCuz ultimately everything costs some money to do (and even your own time is money) and we’re all trying to do the most possible with the least amount of money
- walterbell 4y agoIf an attacker already has sunk costs in successfully compromising both in a different market, then both isn't a new cost, it's two new markets. As for "why both", see recent attempts to audit electronic voting systems.
- Brian_K_White 4y agoBecause you can't cause the cpu's microcode to be updated with your hacked code by magic, and what you can do with a hacked cpu directly, and without being instantly oticed, is actually pretty limited. The way you'd get use out of it would be for some tiny single bit flip or extra op change in the cpus behavior to invoke some other larger thing, like run an execurable that wouldn't otherwise have been run, or make a region of memory readable or writable that wouldn't normally, or allow an instruction that wouldn't normally etc.., and in all of those cases you need something else installed and ready to make use of the cpu hack. But if you can arrange to insert that other stuff, then the job is already done and playing with something exotic like this is just stupid. If you have the means to use this, then you already have the means to do 500 other simpler and more useful things. It's like replacing the locks on someone's car so that you can make your own key work in it too. Sure, cool, but you already stole their entire car or at least had access to it in the shop, and could just copy their normal key if you want access again later, for much cheaper, in much less time, and much less risk of detection.
- walterbell 4y agoExploitation of an existing bugdoor is statistically more likely than a backdoor, and does not require updating any microcode. Once identified and exploited, bugs may be removed in a future microcode revision, as with all other forms of firmware and software.
- hammock 4y agoTo my knowledge there is no evidence of widespread voter machine fraud. Perhaps it is unwise to spread ideas suggesting an election system could possibly be compromised
- reese_john 4y agoAbsence of evidence is not evidence of absence. Not that I believe that widespread fraud has happened before, but electronic voting is inherently flawed, there is no reason why a coordinated attack couldn't happen in the future.
- dyingkneepad 4y agoI agree with you, and that's why I didn't spread disinformation suggesting an election system may be compromised. I just stated that the attack surface for something like this is quite big. Edit: I'm also definitely not saying that paper voting is better than urna eletrônica. Both methods have big attack surfaces.
- hammock 4y agoMaybe I misunderstood you. The attack surface for American elections is quite big also, but there is no widespread election fraud that I'm aware of
- Brian_K_White 4y agoI'm not aware of that cancer that is probably killing me right now. There is no valid argument for trusting electronic voting machines. While they are still closed source like now, it is flatly impossible and not even slightly rational to trust them. If they ever become open and auditable and verifyable, well then you are no longer trusting them. Talking about "large, coordinated" is an irrelevant distraction. Maybe there have been and maybe there haven't been any such attempted to date, but you have no way to know and so your awareness means nothing, and on top of that, every minute is a new minute. There is no valid argument for trusting these things as they currently exist. Whether you think any elections have been changed doesn't even matter.
- Tozen 4y agoWhen there are no paper ballots or printing of ballot receipts, I take it that the quiet intent is not to have a paper trail so that election fraud can be more easily hidden or for plausible deniability. Often, such methods, are to be used against the votes of minority groups or minority parties.
- goombacloud 4y agoHas someone tried to write own microcode and load it? Sounds like it should be much faster to run your own code this way than having the official microcode run an interpreter for your x86 instructions.
- fulafel 4y agoIt's signed, no interesting headway has been published afaik relating to recent intel processors. edit: there was this piece interesting headway mentioned elsewhere in comments: https://news.ycombinator.com/item?id=32149210 https://news.ycombinator.com/item?id=32149210
- viraptor 4y agoThere was some research into modifying old AMD microcode when they didn't enforce signing. https://hackaday.com/2017/12/28/34c3-hacking-into-a-cpus-microcode/ https://hackaday.com/2017/12/28/34c3-hacking-into-a-cpus-mic... Nothing of that level on Intel so far.
- codedokode 4y agoI guess that the amount of SRAM for microcode is limited so you cannot write a lot of code this way. Also, microcode might be used only for slow, rarely used instructions, and it doesn't make much sense to optimize them.
- alkjlakle 4y ago
- anewpersonality 4y agoWhat have these people stated about the war?
- fxtentacle 4y agoWow that is really cool. Here's the GitHub link without Twitter tracking, BTW: https://github.com/chip-red-pill/MicrocodeDecryptor https://github.com/chip-red-pill/MicrocodeDecryptor Especially considering how they gained this knowledge: "Using vulnerabilities in Intel TXE we had activated undocumented debugging mode called red unlock and extracted dumps of microcode directly from the CPU. We found the keys and algorithm inside." And looking further down, some X86 instructions (that people would usually call low-level) actually trigger execution of an entire ELF binary inside the CPU (implemented in XuCode). Just wow.
- cowtools 4y agoI have a sinking feeling in my chest. If the suspicions are true, we may be at a pivotal moment here.
- pyinstallwoes 4y agoCan you expand on that as someone who is learning more about low-level architectures in relation to the hardware and microcode layer?
- fragmede 4y agoIt's never been publicly clear how much is done in hardware, and how much is actually done via microcode. This blows the doors open and reveals that there's actually a lot more being done in microcode than previously suspected. What's pivotal, is how much more possible this makes microcode-based attacks against Intel-based systems.
- pyinstallwoes 4y agoYeah if they can ship code that fixes "critical security" faults in a physical product, then it's probably at the software level all the way down.
- 4y ago
- RjQoLCOSwiIKfpm 4y agoWhich machine language is the microcode written in? Is it even possible to fully decode that language with publicly available information/tools? Given that microcode is an internal mechanism of CPUs, I would expect its language to be impossible to decode for regular people because there is zero knowledge on how it works? And even if there is some knowledge on it, won't Intel change the machine language around a lot among CPU generations because the lack of public usage means it can be changed constantly, thus rendering the existing knowledge useless quickly?
- fragmede 4y agoYeah but Intel's engineers aren't going to just change the machine language around for funzies. I'd expect it to be semi-stable because if it ain't broke, there's no reason to go in and change it.
- robin_reala 4y agoThey changed from ARC to a 32-bit Quark core for the ME from version 11 up.
- alophawen 4y agoThat's just the CPU arch running IME. The uOps is designed by Intel.
- genewitch 4y agoWhen you say quark, do you mean the 486 that uses 25mA? Or did intel use that name twice? I have a couple of quarks, never used them.
- robin_reala 4y agoLooks like I misunderstood the original point, but to follow up on your comment: yes. https://en.wikichip.org/wiki/intel/management_engine#Current_Mechanism https://en.wikichip.org/wiki/intel/management_engine#Current...
- fulafel 4y agoIf they are sane, Intel didn't rely on this staying secret in their threat model.
- jacquesm 4y agoIf they were truly sane this whole thing would have never existed, so all bets are off on that one.
- mjg59 4y agoDepending on how microcode is defined, it's arguably existed back to the 40s. Which modern and reasonably performant CPUs are you thinking of that don't have microcode?
- jacquesm 4y agoYou completely misunderstood my comment.
- mjg59 4y agoWhat were you referring to, other than microcode? Edit: Oh, you mention the encryption. Big companies love obfuscating everything they create, because they're afraid something commercially sensitive will exist there and someone will copy it and outcompete them. I agree that this is ridiculous, but I don't think it's evidence of any sort of nefarious activity.
- punnerud 4y agoIs there any chance to get the RSA keys to be able to make your own code?
- deleted 4y ago[deleted]
- W4ldi 4y agoFor that you'd need to hack Intels infrastructure and get access to the private keys.
- pabs3 4y agoProbably the keys are on well-guarded offline HSMs.
- 5d8767c68926 4y agoAre there rules/standards for how these top secret keys are stored? HDCP, Mediavine, keys to the Internet, etc. Sure, you could keep it locked in a Scrooge McDuck security vault, but you need to be able to burn the key into hardware/software, meaning it ultimately needs to be distributed across many machines, greatly increasing the number of people with potential access.
- shmde 4y agoAs someone who just makes Crud apps can someone please ELI5 this. Why is this a big deal and why are people freaking out about intel chips becoming obsolete overnight ?
- Akronymus 4y agoIf there is a backdoor, it could be widely exposed. And such a hypothetical backdoor may not be patchable AT ALL. As in, there may a possibility for almost every computer being vulnerable to a RCE that bypasses even the OS.
- spockz 4y agoDepending on where the vulnerability exists it can be patched by patching the microcode right?
- mjg59 4y ago> And such a hypothetical backdoor may not be patchable AT ALL. Intel microcode can be loaded at runtime. If there's a backdoor in the microcode then it can, by definition, be patched.
- pitaj 4y agoPretty sure the microcode could be changed to deny a patch, since it has the most privileged level of control on the system.
- mjg59 4y agoMicrocode isn't persistent - on reboot you'll be running whatever version was in the CPU at manufacturing time. That means there's a path to booting to a known-good environment and updating the firmware, which will then load patched microcode before any attacker-controlled code can run.
- gorgoiler 4y agoAs I understand it, you would need to have an existing RCE to exploit the microcode patching process. h0t_max’s research means that future attacks — once your local machine has been infiltrated by some other means — can do a lot more damage than simply encrypting your filesystem or sending spam. They can rewrite the way your CPU works. When your OS gets attacked by malware it is attacking the layer above the bare metal on which your OS runs. The base hardware remains untouched. You can at least clean things up by installing a new OS on the bare metal. If malware attacks the bare metal itself, then you are stuck out of luck.
- jacquesm 4y agoI would not be surprised if this will end up being the highest upvoted post of HN for all time depending on the outcome.
- kriro 4y ago
- __alexs 4y agoI think the next discovery might be really big but this is read-only and only for Atom CPUs so far.
- alophawen 4y agoWhat makes you think any part of this news would change INTC stock values, or even car recalls? It's very confusing to me how you get to these conclusions. Nothing in this news is about any scandals that would warrant any of your suspicions.
- kriro 4y agoIf taken seriously this should have implications on purchasing decisions and I'm not sure what would happen if some (government) organizations would ask Intel to take back their hardware because there's un-patachable RCE. I mention the car recalls or the old Intel chip recalls or any recalls really because that past situations that could be comparable (I'm not implying this will lead to car recalls, only that that's past events that could be looked at for predicting how this might develop).
- hulitu 4y agoPurchasing decisions are usually not made by technical people.
- ncmncm 4y agoThe world at large will utterly ignore it.
- resoluteteeth 4y agoThe microcode shouldn't even need to be secret in theory, so being able to decrypt it on celeron/atom cpu's is by no means "devastating."
- FatalLogic 4y agoOne year ago on HN, also involving Maxim Goryachy (@h0t_max), as well as Dmitry Sklyarov (of DMCA 'violation' renown) and Mark Ermolov: Two Hidden Instructions Discovered in Intel CPUs Enable Microcode Modification https://news.ycombinator.com/item?id=27427096 https://news.ycombinator.com/item?id=27427096
- deleted 4y ago[deleted]
- no_time 4y agoJudgement is nigh. I'd love to get my hands on one of the decrypted binaries but I expect there are much more capable reverse engineers are already carrying the torch :^)
- numlock86 4y agoSo after analysis from the community and experts we will finally get rid of the whole backdoor-conspiracy bandwagon? Or will they just move on to another aspect or even simply wave it off as an orchestrated and constructed fake? I mean those people come up with a lot weirder things to advocate for their beliefs.
- charcircuit 4y agoI don't think they will. They want to believe there exists a backdoor or that they are constantly being spied on and they will make up a narrative on how that happens regardless of if that explanation is true or if it is even physically possible.
- galangalalgol 4y agoWhile it really wouldn't surprise me if there was a back door, or some incompetence (real or orchestrated) that functions as one, I also don't think "they" need microcode level backdoors given the state of software security, and the amount of information we give away freely.
- pueblito 4y agoIm pretty sure it’s indisputable that we _are_ all constantly being spied upon and tracked, both by multiple nation-states as well as a ton of private companies. Believing there is an undiscovered backdoor is absolutely a reasonable position to take.
- javajosh 4y ago>the whole backdoor-conspiracy bandwagon This isn't a correct characterization of the suspicion that Intel microcode has backdoors in it. The suspicion isn't just based on distrust of authority, like flat Earth, etc, but also on the org having means, method, and opportunity to remotely modify the operation of a CPU. And it operates within the domain of the USG, who have demonstrated a keen interest in weaponizing 0-day exploits. What better way to acquire a novel 0-day than to simply write one known only to you and distribute it from the source? This is a good plan, but it comes with a substantial risk to Intel, or any company who wishes to maintain a trust relationship with its customers. That said, I don't think anyone doing this is stupid, and for safety they would not install microcode malware on everyone, just some. This means we will find nothing in general CPUs, and anecdotal reports finding "something" can easily be dismissed as malicious or noise. The truly paranoid need not worry, even if the microcode is seen to be harmless, there is always the possibility that hardware you buy is interdicted, modified, and sent onward, such that your paranoia can remain intact.
- notRobot 4y agoCan someone more educated on this than me please ELI5 the significance of this? If I'm understanding correctly, this allows us to view (previously obfuscated) code that runs on certain (recent-ish) Intel processors? What are the consequences of this?
- fulafel 4y agoThere hasn't been any obvious reason to keep this secret behind encryption, so now there's a little buzz in the air if something newsworthy will be revealed once people start analyzing the microcode and diffs between microcode updates.
- avianes 4y ago> If I'm understanding correctly, this allows us to view (previously obfuscated) code that runs on certain (recent-ish) Intel processors? Yes, but this "code" is the Intel microcode. In a modern processor, instructions are translated in a sequence of micro-operations (uOps) before execution; These uOps are small instructions that the processor can execute with more ease. Ultimately, this allows to build more performant processors. But some instructions require translation into a uOps sequence that is too complex to be handled like other instructions. Modern processors therefore feature a "microcode sequencer", and the "microcode" is the configuration of this component. And this work allows us to interpret a previously misunderstood part of the microcode. > What are the consequences of this? There are no real direct consequences for users. But this helps to better understand how modern Intel processors work; Especially security researchers will be able to better understand how some security instruction works (mainly the SGX extension). In the long term, they may find Intel errors (as has already happened previously) which will be fixed in next Intel processor generation. Although security issues may be detected in Intel processors, this will probably have no impact for normal users, but it could affect some companies.
- mfbx9da4 4y agoThis is quite literally, hacker news.
- pueblito 4y agoCool, I’m into cheap auditable hardware! This could maybe turn out like when they discovered Linksys was breaking the GPL which ended up opening up an entire class of hardware to hack on.
- O__________O 4y agoCurious, if an attacker has the key and access to the code, is there anything to stop an attacker from updating the microcode to contain an exploit?
- Jolter 4y agoThe signing key has not been compromised, afaik.
- O__________O 4y agoAgree, though your response doesn’t address if an attacker had the signing key; appears that an attacker with the microcode encryption key, knowledge of how microcode works, how it’s updated, the signing key, and how to generate a valid signed update — they would be able to deploy an exploit to the CPU; obviously this excludes the existing issues with Intel ME.
- Jolter 4y agoYes, presuming physical access as well as access to the signing key, an attacker could certainly deploy malicious microcode. It would be a very scary thing indeed. It seems a reasonable threat model if your adversary is a malicious state actor, or similarly well funded and ambitious organization. Edit: I assume this threat has existed as long as updatable microcode has.
- StillBored 4y agowell, I guess it depends on how the private key is stored in the CPU, how if any data they can inject or cause the CPU (via power rail noise/whatever) to accept an update/etc which allows the private key/or validation routine to be bypassed. Basically, the easier route is usually to just find a way to bypass the check once, and use that to install a more permanent bypass.
- aaronmdjones 4y agoThe key in your CPU would be the public key, not the private key. The public key can only be used to verify existing signatures, not create new ones. It may be possible through power fault injection to flip the bits of the public key such that you could get it to accept microcode signed with your own private key, but I would be very surprised if the public key weren't burned into the structure of the CPU itself in a manner that renders it immune to such attacks. Of course, power fault injection may still allow you to bypass the verification routine altogether instead of modifying the key it verifies with.
- Waterluvian 4y agoNaive question about getting “dumps of microcode” Getting a dump means getting access to a memory controller of sorts and asking it to read you back the contents of addresses, right? But you’re really getting what the memory controller decides to give you. There could be more indirection or sneakiness, right? Ie. I could design a memory controller with landmines, as in “if you ask for 0x1234 I will go into a mode where I send back garbage for all future reads until power is cycled.” Is this a thing?
- sabas123 4y agoThis is a thing and was used in this fantastic piece: https://www.youtube.com/watch?v=lR0nh-TdpVg https://www.youtube.com/watch?v=lR0nh-TdpVg However the way they obtained these dumps is by going deep into debugger mode of the cpu which makes me doubt anything spooky would be going on.
- tambourine_man 4y agoI’m usually not into security research but this is fascinating, thank you. Someone screwing some C code and creating a vulnerability isn’t that interesting to me, but going on such low level and fundamental stuff makes me giddily, if not a bit scared. Last time something like this caught my eye was that iMessage[1] NSO thing, not because they managed to escaped the sandbox, but because of the insanely clever way they did it. [1] https://googleprojectzero.blogspot.com/2021/12/a-deep-dive-into-nso-zero-click.html?m=1 https://googleprojectzero.blogspot.com/2021/12/a-deep-dive-i...
- sizzle 4y agoSame and also the state sponsored centrifuge destroying 0 day that was written up a while ago, super mind bending read
- tambourine_man 4y agoYes! That one too.
- memorable 4y agoAlternative front-end version: https://nitter.net/h0t_max/status/1549155542786080774 https://nitter.net/h0t_max/status/1549155542786080774
- ItsTotallyOn 4y agoCan someone ELI5 this?
- bri3d 4y agoAs we know, processors run a series of instructions, things like "move data," "add," "store data." Over time, these instructions have gotten more and more complicated. Now there are "instructions" like "Enter Virtual Machine Monitor" which actually complex manipulations of tons of different registers, memory translations, and subsystems inside of the CPU. And, even simple, primitive instructions like call, jump, and return actually need to check the state of various pieces of the processor and edit lots of internal registers, especially when we start to consider branch prediction and issues like Spectre. It wouldn't be very plausible to hard-wire all of these complex behaviors into the CPU's silicon, so instead, most instructions are implemented as meta-instructions, using "microcode." "Microcode" is just software that runs on the CPU itself and interprets instructions, breaking them down into simpler components or adding additional behaviors. Most CPUs are really emulators - microcode interprets a higher level set of instructions into a lower level set of instructions. Historically, Intel and more recently AMD have encrypted this "microcode," treating it as a trade secret. This makes people who are worried about secret hidden backdoors _very_ worried, because their CPU's behavior is depending on running code which they can't analyze or understand. This has led to all sorts of mostly unfounded speculation about secret back doors, CPUs changing the behavior of critical encryption algorithms, and so on and so forth. Decrypting this microcode will theoretically allow very skilled engineers to audit this functionality, understand the implementation of low-level CPU behaviors, and find bugs and back-doors in the CPU's interpretation of its own instructions. Replacing this microcode silently would be absolutely catastrophic security-wise, because an attacker could silently change the way the CPU worked, right out from under running software. But, there is no evidence this is possible, as the microcode is digitally signed and the digital signature implementation, so far, seems to be correct.
- ccbccccbbcccbb 4y agoIt's all cool and certainly a breakthrough, but Atoms, Pentiums and Celerons.. Wake me up when this thing decrypts mainstream Core i7 microcode!
- exikyut 4y agoFWIW the supported CPUs list does list silicon from 2017-2019...
- marcodiego 4y agoHow far are we from getting rid of IME now?
- Genbox 4y agoDiscussion here: https://news.ycombinator.com/item?id=32148318 https://news.ycombinator.com/item?id=32148318
- dang 4y agoI think we'll merge that discussion hither, because this one was posted earlier and has the more substantive source.
- jacquesm 4y agoThat's pretty weird, this article was here already earlier, had 600+ upvotes and now it is back with new upvotes but the old comments.
- faxmeyourcode 4y agoI thought I was having a stroke or dejavu reading these comments
- jsnell 4y agohttps://news.ycombinator.com/item?id=32156694 https://news.ycombinator.com/item?id=32156694
- deleted 4y ago[deleted]
- dqpb 4y agoDoes the disclaimer at the top have any legal merit? If they didn’t include that disclaimer, would they actually be liable for damage or loss caused by its use?
- colechristensen 4y agoDoubtfully legally "required" to avoid liability, but everything you can do to knock down arguments that you injured a third party by warning them of the danger really takes the air out of lawsuits. You can point to the warning to discourage from filing lawsuits, to encourage dismissal, or to make winning a case more likely.
- ngcc_hk 4y agoCan you use this to build an intel machine under say arm?
- rolph 4y agohttps://github.com/chip-red-pill/uCodeDisasm https://github.com/chip-red-pill/uCodeDisasm
- saltminer 4y ago> Also, we recovered a format of microcode updates, algorithm and the encryption key used to protect the microcode (see RC4). RC4 had already been busted wide open when the two generations of CPUs (Gemini Lake and Apollo Lake) this affects were released. Why would they use a known insecure cipher?
- Heleana 4y agoMy guess is that the next discovery will be quite significant, but for the time being, this feature is read-only and restricted to Atom processors only.