3 ms·
>The issue is really complicated. As a counter-example, consider the Precursor[1] who's CPU is "... an SoC on an FPGA, which means you can compile your CPU fro
by simpaticoder 3y ago
>The issue is really complicated.
As a counter-example, consider the Precursor[1] who's CPU is "... an SoC on an FPGA, which means you can compile your CPU from design source and verify for yourself that Precursor contains no hidden instructions or other backdoors."
Device manufacturers could ship firmware as FPGA images, such that end-users can start with a "blank slate" and then install arbitrary firmware upon delivery. They choose not to.
1 - https://www.crowdsupply.com/sutajio-kosagi/precursor https://www.crowdsupply.com/sutajio-kosagi/precursor
- chongli 3y agoThat’s not going to work for a SotA phone like an iPhone. FPGAs are not even close to as fast and efficient as a purpose-built, SotA CPU.
- simpaticoder 3y agoOf course there will always be objections to any change. Everything is a trade-off. But if you wanted a truly secure device, you have to start with idea that every customer gets the same thing - a truly blank slate. It's only recently, and with incredible device density, that this assumption has changed. The fact that manufacturers CAN put extra CPUs and CAN put unique hidden, immutable data in your computer does mean it MUST be so. This is simply the path we've been going down for about the last 20 years or so. It doesn't mean we have to keep going down that path. I'd also add that computers have multiple CPUs, and an FPGA and an M1, for example, could coexist, with the FPGA serving as the BIOS and firmware repository. I think there are real and frankly chilling reasons why manufacturers will not take this approach, and it's not because of economics. A truly free device is a threat to the establishment.
- deleted 3y ago[deleted]
- LoganDark 3y ago> They choose not to. For very good reason. Last I checked, FPGAs capable of running any sort of fast, modern core are typically more expensive than a new iPhone.
- SV_BubbleTime 3y agoI was at my assembler and picked up a 30 layer PCB with two $5000 Xilinx FPGAs on it. Military application, really cool. They were t even special or rad hardened for space. But “it’s FPGA and you can see the code”… ok, fucking lol though. HeartBleed OpenSSL was an issue for how many years and the code was open to a hundred million people who could read it in some language. I know FPGA developers they couldn’t even remotely follow a softcore CPU configuration. You are talking about less than 100,000 people in the world, and even that is probably way generous, maybe 30k?
- simpaticoder 3y agoYou've obfuscated a good point. Open-source is a necessary, but not sufficient condition for openness. Actual human beings must also understand the source well enough to audit it and modify it. If heartbleed occurred in closed source, it would still be an active problem. The vendor would be reluctant to even admit the flaw, because it makes them look bad. And the whole world realized that one guy was maintaining OpenSSL, and he was on the edge of poverty. It was a wake-up call. Thousands of devs looked at the code, and understood it well enough to patch and fork. It's also true that, because of historical accidents, we have several more examples of https://xkcd.com/2347/ https://xkcd.com/2347/. However, that's not an argument against open source. It's an argument that we all should take ownership of what we ship, all the way down, without exception. An open CPU definition is a necessary, but not sufficient, requirement for this level of ownership.
- AshamedCaptain 3y agoIf you are really afraid of backdoors at the processor level, then the idea of an FPGA onboard should make you run like hell, if anything.