3 ms·
It's not even a "backdoor", it's documented in the datasheet... http://datasheets.chipdb.org/VIA/Nehemiah/VIA%20C3%20Nehemiah%20Datasheet%20R113.pdf http://dat
by userbinator 2mo ago
It's not even a "backdoor", it's documented in the datasheet...
http://datasheets.chipdb.org/VIA/Nehemiah/VIA%20C3%20Nehemiah%20Datasheet%20R113.pdf http://datasheets.chipdb.org/VIA/Nehemiah/VIA%20C3%20Nehemia... (page 82)
...which along with the already publicly-known microarchitecture of the C3 makes this statement sound like total nonsense:
The rosenbridge backdoor is a small, non-x86 core embedded alongside the main x86 core in the CPU
I remember laughing at this with a few others knowledgeable in x86 when it first came out; a self-proclaimed "security researcher" who somehow failed to RTFM.
There's even a Wikipedia article about it now, with a link to the alternate instruction set documentation: https://en.wikipedia.org/wiki/Alternate_Instruction_Set https://en.wikipedia.org/wiki/Alternate_Instruction_Set
- cinntaile 2mo agoIt's not as clear cut as you describe it here. In the other old thread you linked there was no real consensus if this should be considered a backdoor or not.
- inigyou 2mo agoWas this documentation public at the time? The pdf still does not document the instructions themselves.
- userbinator 2mo agoIt was public at least 4 years before he first announced his discovery: https://web.archive.org/web/20140130160743/http://datasheets.chipdb.org/VIA/Nehemiah/VIA%20C3%20Nehemiah%20Datasheet%20R113.pdf https://web.archive.org/web/20140130160743/http://datasheets...
- 23455646gg3g 2mo agoyes, AIS was known sandsifter was lots of noisy PR, but no new encoding findings
- jcranmer 2mo agoAFAIK, sandsifter did find a halt-and-catch-fire instruction on one of the CPUs, but I haven't seen anyone announce which CPU model it was.
- phire 2mo ago"It's documented in the datasheet" is such a weak excuse for a backdoor. Documenting a backdoor doesn't make it not a backdoor, just means it's not a hidden backdoor. The fact that a number of machines shipped with the backdoor accidentally enabled, and nobody noticed for over a decade shows just how dangerous even a documented backdoor can be. The oversight wasn't even detected by someone reading the manual, it was detected by a security researcher who wrote a generic tool to fuzz out such backdoors.
- brador 2mo agoDoesn’t backdoor imply hidden? If it’s clearly documented it’s just a (front)door?
- blank429384jf 2mo agobackdoor means a secondary access point that defeats the security features of the primary. In the door analogy, the home owner spends a ton on a lock and camera for the front door but doesn't even have a deadbolt on the back.
- close04 2mo agoEvery definition of a “backdoor” in computing implicitly or explicitly considers it hidden/covert. In the house analogy you don’t see the backdoor when approaching the front. If it was just “an alternative everyone knows about and can be broken easier than the front door” then it probably would have been called “a window”. Most login forms have a weaker option like a SMS 2FA or password reset fallback. Nobody calls it a backdoor. It’s just a crappy second front door, or window.
- blank429384jf 2mo agoI'm probably mistaken, but I've always referred to password resets as backdoors. Is there another term they could be classfied as?
- crest 2mo agoThe documentation was locked away behind NDAs when the faulty BIOS leaving it reachable was discovered. Look at the publication dates.