3 ms·
So after analysis from the community and experts we will finally get rid of the whole backdoor-conspiracy bandwagon? Or will they just move on to another aspect
by numlock86 4y ago
So after analysis from the community and experts we will finally get rid of the whole backdoor-conspiracy bandwagon? Or will they just move on to another aspect or even simply wave it off as an orchestrated and constructed fake? I mean those people come up with a lot weirder things to advocate for their beliefs.
- charcircuit 4y agoI don't think they will. They want to believe there exists a backdoor or that they are constantly being spied on and they will make up a narrative on how that happens regardless of if that explanation is true or if it is even physically possible.
- galangalalgol 4y agoWhile it really wouldn't surprise me if there was a back door, or some incompetence (real or orchestrated) that functions as one, I also don't think "they" need microcode level backdoors given the state of software security, and the amount of information we give away freely.
- pueblito 4y agoIm pretty sure it’s indisputable that we _are_ all constantly being spied upon and tracked, both by multiple nation-states as well as a ton of private companies. Believing there is an undiscovered backdoor is absolutely a reasonable position to take.
- javajosh 4y ago>the whole backdoor-conspiracy bandwagon This isn't a correct characterization of the suspicion that Intel microcode has backdoors in it. The suspicion isn't just based on distrust of authority, like flat Earth, etc, but also on the org having means, method, and opportunity to remotely modify the operation of a CPU. And it operates within the domain of the USG, who have demonstrated a keen interest in weaponizing 0-day exploits. What better way to acquire a novel 0-day than to simply write one known only to you and distribute it from the source? This is a good plan, but it comes with a substantial risk to Intel, or any company who wishes to maintain a trust relationship with its customers. That said, I don't think anyone doing this is stupid, and for safety they would not install microcode malware on everyone, just some. This means we will find nothing in general CPUs, and anecdotal reports finding "something" can easily be dismissed as malicious or noise. The truly paranoid need not worry, even if the microcode is seen to be harmless, there is always the possibility that hardware you buy is interdicted, modified, and sent onward, such that your paranoia can remain intact.
- midislack 4y ago
- DSingularity 4y agoNo. Intel can sign arbitrary binaries which get executed in a more privileged mode and without leaving any traces. That’s the problem.
- trelane 4y agoOr someone with their keys
- jbm 4y agoYou're getting unfairly dismissed, so let me take some of the downvote burden. In this thread, I see implications about big media controlling microcode (which doesn't seem to be impacting piracy — if anything, it's easier than ever before), about governments imminently finding backdoors and trashing an entire generation of chips, and other extreme outcomes that seem wholly out of step with reality. (Not in the "Everyone else is dumb but we few are smart" way; in the "I have not interacted with a business or government ever" way) I'm sure the 2600 crowd will have their next "Yes but what about the *Long form* birth certificate"-style goalpost shift if there are no backdoors found.