4 ms·
This sounds excessively paranoid to me. If you’re worried about backdoors and the threat model includes the ability to compromise the CPU, you probably need to
by KerrAvon 4y ago
This sounds excessively paranoid to me. If you’re worried about backdoors and the threat model includes the ability to compromise the CPU, you probably need to back up a few steps and figure out how the CPU got compromised? What am I missing?
- adrian_b 4y agoAny CPU can be compromised by its designers, and the owner cannot verify whether this is true or not. All Intel and AMD CPUs are compromised from a security POV by features much more dangerous than the hardware RNG, i.e. by the existence of the System Management Mode and of the extra processors included in the CPU package, which can do absolutely anything in a manner that cannot be detected by the owner of the computer. As long as Intel and AMD do not publish a complete documentation of how their remote management features work and as long as they do not allow the owners of the computers to control them, it can only be assumed that they can be backdoored. Whatever documentation exists for those features, it appears to be provided only under NDA, presumably only to the companies which write remote management applications for large corporations. Nevertheless, like for the hardware RNG, there are workarounds that can make very unlikely the exploitation of any hardware backdoor. For example, if a computer with an Intel CPU is used in a router/firewall exposed to the Internet, it is prudent to not use any Intel Ethernet interface for the Internet interface. If there are only Intel Ethernet interfaces, an USB to Ethernet adapter can be used. This will prevent the use of the remote management by an attacker. The same applies for the WiFi, for a secure router/firewall, any Intel WiFi must be disabled (e.g. by disconnecting the antennas) and replaced by a WiFi dongle.