Hacker News new | ask | show | jobs
by osy 2243 days ago
Since Intel/AMD also designs the processor they can also put in backdoors beyond ME, microcode updates, etc. If you don’t trust proprietary blobs, I respect that. But you can’t trust proprietary silicon either.
2 comments

Defense in depth fails when the attacker has unrestricted access to the core of your defense infrastructure.
Yeah, microcode updates are proprietary software too. The weird result is that if you want a system with no proprietary software, you end up having to use the original microcode which is burned onto the chip and counts as hardware.

It's not a perfect solution but maybe it's a reasonable place to draw the line, until we have open source hardware processors using RISC-V or something.

Then you have to accept all the bugs with the original...
...and that a backdoor wasn't written into the original microcode, or that a state-sponsored actor didn't intercept during shipping...