5 ms·
Can someone else with the proper background confirm or deny the idea in theory? If it's possible, it would be a shame to loose the thread here. Whether or not
by methehack 13y ago
Can someone else with the proper background confirm or deny the idea in theory?
If it's possible, it would be a shame to loose the thread here.
Whether or not Steve Blank is qualified to make the observation seems like a Red Herring to me.
- lisper 13y agoI don't know if I have the "proper background". I never designed CPUs for a living, but I do have a B.S.E.E. and a Ph.D. in Computer Science, and I was once the co-founder of a hardware-based startup (though I did the software). IMHO this is all quite plausible. The idea of accessing the backdoor through a sequence of obscure instructions sounds particularly plausible to me.
- duaneb 13y agoI've designed some processors, albeit not at the complexity of Intel, AMD, or IBM. However, in theory it's definitely possible via any number of mechanisms. This could be (provably) undetectable by software state, though perhaps measuring e.g. deviance from average clock cycles of certain instructions to determine whether something unusual was happening. For example, this is almost certainly similar to what would be used: http://www.intel.com/content/www/us/en/architecture-and-technology/intel-active-management-technology.html http://www.intel.com/content/www/us/en/architecture-and-tech... To me, this is the boring part—I'm much more interested in a) what they would collect, b) how they would identify it from the processor (if they didn't load software into memory), and c) how they expect to retrieve it. If they even attempted to use IP to communicate they would be caught immediately.
- Canada 13y agoData could be leaked from the system by encoding it in the timing of legitimate packet transmission.
- mansr 13y agoThis encoding would have to be maintained by every router until it reaches an intercept point.
- duaneb 13y agoSure, and how many processor architectures do you think would be necessary to backdoor to get a full route to be likely possible? This might be a good place to start: http://en.wikipedia.org/wiki/List_of_Internet_exchange_points http://en.wikipedia.org/wiki/List_of_Internet_exchange_point.... I'm sure this is exposing a weakness in my graph theory-fu.
- Canada 13y agoIf Snowden showed us anything it's that the intercept point is never many hops away! The timing differences could probably survive a few hops most of the time.
- Zigurd 13y agoI'm not a CPU designer, but I did once write a microcode debugger for a printer RIP. I say it is do-able and, if done right, very very hard to detect. Privilege escalations could be done in a small amount of obfuscated code. Implementing a sequence to trigger that is also do-able since there are usually many unused opcodes.