2 ms·
I will postulate that recent consumer hardware is almost guaranteed to have a backdoor for peripherals that grant privileged introspection into the system. For
by consonants 13y ago
I will postulate that recent consumer hardware is almost guaranteed to have a backdoor for peripherals that grant privileged introspection into the system.
For example, Stuxnet relied on creating a botnet to spread and then wait for a call from home before sabotaging the target computers in an Iranian nuclear facility. It accomplished this with multiple 0-day vulnerabilities. It was incredibly well thought out, comprehensive, and opportunistic. Those factors made it expensive. It also targeted specialized industrial hardware, hardware that lacked consumer features and thus common attack vectors.
My assertion is that it is less time, resource, and opportunity necessitating if a common vector of attack is baked in.
It could be abstracted enough that it isn't an obvious 'hey guys, check out this wide open security hole we built into our hardware' to watchful eyes, but an (un)intended consequence of the system if the backdoor isn't component based.
People keep blowing me away with their willingness to be evil for a profit, so I would bet some palms were greased and some reciprocal 'tips and favors' circulate between a hardware manufacturer and a federal intelligence agency at our expense.
It could be that hardware RNG that comes with your board. CPUs also have encryption standard instruction sets.
And then we can look at the firmware that runs on our components. Then the kernel..
It's a security nightmare all the way down.
- wglb 13y agoHere is the thing. I would be willing to wager that there are backdoors (aka vulnerabilities) that NSA doesn't know about. The whole stack is sufficiently complex that there isn't much you can prove about it, with or without malicious intent included in the calculation.