Hacker News new | ask | show | jobs
by ewokone 1138 days ago
I would love to learn more about that.

How would someone use those keys? What's beneficial, what could be useful possible cases for me? And Are my workstations in my company at risk?

1 comments

If I recall correctly, at boot time CPUs retrieve the firmware along with a cryptographic signature that verifies the firmware came from the signer. Some boards choose to burn this signature into the hardware using e-fuses. If the signing key is leaked, that means someone can flash custom firmware into the chip and the CPU would be none the wiser, all while operating at Ring 0.
CPU firmware (microcode) is signed by Intel, so it would not be affected by this leak, only motherboard firmware.
Lenovo vendor locking Ryzen CPUs with AMD PSB https://news.ycombinator.com/item?id=29958247