Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
cat_easdon
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
4 ms
·
1.
▲
by
cat_easdon
7y ago
Sorry - the presentation was never recorded. There's more information in the GitHub repo, however: https://github.com/cattius/opcodetester .
2.
▲
by
cat_easdon
7y ago
Yeah, that's right - you could prove the absence of malicious microcode, but not the absence of hardware trojans, implants, etc. There are also the embedded microcontrollers to deal with (e.g. the Management Engine, Innovation Engine,
3.
▲
by
cat_easdon
7y ago
A team from Ruhr University Bochum reverse-engineered the microcode for the AMD K8 and K10 to implement custom microcode programs, they describe how they reverse-engineered the ROM here: https://www.syssec.ruhr-uni-bochum.de/
4.
▲
by
cat_easdon
7y ago
Author here - the main reason there's no examples is because I didn't have any interesting ones to report at the time! I was trying to develop new detection methods, but found only the (thousands) of undocumented software prefetch
5.
▲
by
cat_easdon
7y ago
Author here - the aim of this project was to explore exactly why such opcodes are problematic for security. Even if they're implemented with entirely innocent intentions - e.g. for debug+verification purposes - they can lead to vulnera