5 ms·
Does the 7000 series have Pluton? Can't find specifics anywhere.
by dschuetz 4y ago
Does the 7000 series have Pluton? Can't find specifics anywhere.
- nicolaslem 4y agoI don't know but for what it's worth my main machine is a 6000 series laptop (with Pluton) running Linux and I did not have any compatibility issues. Sure, it sucks to have some Microsoft designed hardware in my CPU but at least it not causing issues (for now).
- anonym29 4y agoYou have two ring -3 coprocessors with unrestricted DMA, unrestricted disk I/O, and unrestricted access to your network interface. One belongs to the NSA, the other to Microsoft. Do some traffic analysis on the upstream end of an ethernet cable plugged into that computer while it is hibernating or sleeping some time, you might not like what you what you find.
- YakBizzarro 4y agoany reference to that? I would like to read more
- anonym29 4y agoReference: I've done it on my own system. I'd encourage you to do it on your own system if you're curious.
- bruce343434 4y agoI don't have the hardware for it; what did you find?
- anonym29 4y agoWithout divulging too much information about the specifics, a LOT more traffic than I was expecting or willing to tolerate.
- bruce343434 4y agoSuch as?
- anonym29 4y agoSuch as outbound traffic that should not have been taking place. Like I said, not divulging more info. If you're skeptical, just try it.
- bruce343434 4y agoAre you willing to give up the reason for your secrecy? I'm not sure what you stand to lose if you just say "I saw some traffic to NSA headquarters every 10 minutes that coincide with access entries on my SSD"
- anonym29 4y agoYes. Divulging the destination on a public platform is providing more identifying information than I am comfortable sharing. It's funny that you'd think real-world espionage by intelligence agencies would be sending that data to headquarters rather than some random commercial VPS set up as collection infrastructure that is deliberately unattributable to the organization behind the espionage.
- gruez 4y ago>Do some traffic analysis on the upstream end of an ethernet cable plugged into that computer while it is hibernating or sleeping some time, you might not like what you what you find. Is this something you know for a fact, or are you extrapolating from intel ME?
- anonym29 4y agoIt's behavior I've witnessed on my own system w/ AMD PSP. I can't definitively attribute it to PSP, but I can't attribute it definitively to anything else either.
- kyriakos 4y agoIs this something that can be blocked at router/firewall level?
- anonym29 4y agoAllowlisting, yes. Keep in mind that even fairly unsophisticated malware has been observed using channels like pastebin and Twitter for exfil/c2. Blocklisting, that's a cat and mouse game. Go look at how many different URLs and IPs are utilized for commercial telemetry in the likes of Adobe and Microsoft software if you aren't familiar.
- anonym29 4y agoZen 4 (Raphael) desktop CPUs will have it. Right now, Zen 3 (Chagall) and Zen 4 Threadripper (Storm Peak) don't currently have plans for integrating it, but that may be subject to change. I cannot provide proof, but I sure as hell am never buying Zen 4 or later AMD Desktop CPUs ever again for a system that will be connected to the internet.
- dschuetz 4y agoI would not go that far saying I won't buy AMD ever again, but if Microsoft has a foot in the door inside my systems in form of creepware like Pluton it is there for keeping the door open.
- anonym29 4y agoI edited to clarify. I would consider using them on a system that never gets connected to the internet.
- adrian_b 4y agoI am also paranoiac about such things, but the part with avoiding the connection to the Internet is easy for a desktop computer, if it also does not run Windows, where you never know what services might be active and with which external servers they might try to communicate. I have a small computer that is used as the router for the Internet connection and on which I have complete control over the firewall and over the proxies used for connecting to the Internet, so there are no chances for an unwanted connection to the Internet. For additional protection, one could run the Internet browsers in a Virtual Machine, to be absolutely certain that there is no way for a script run by the browser to access the physical hardware, assuming that you do not trust the sandboxing capabilities of the browser.
- anonym29 4y agoVMs are an imperfect solution to preventing programs running in the guest OS from affecting the host OS (imperfect, as VM escapes are a thing). VMs do not provide protection to the guest OS (or it's processes) from inspection and snooping by the host OS, or from inspection / snooping by the hardware the host OS is running on. If using a bare metal hypervisor, sed 's/host OS/hypervisor/g'