Comment on Local charity shop rejects pre-spychip PCs. Then they get destroyed.
rockSlayer@lemmy.blahaj.zone 18 hours ago
By spychip are you referring to IME and PSP? Chips that old are going to have security holes larger than a CEO’s ego. Those chips will be vulnerable to Spectre and Meltdown. Iirc from the fallout of those CVEs, only AMD bothered to patch chips that went back to 2011
evenwicht@lemmy.sdf.org 18 hours ago
“Meltdown affects Intel x86 microprocessors, IBM Power microprocessors,[1] and some ARM-based microprocessors”
I don’t see AMD on that list. Do you?
“At the time of disclosure (2018), this included all devices running any but the most recent and patched versions of iOS,[5] Linux,[6][7] macOS,[5] or Windows.”
So this vuln can be fixed by patching OS kernels, and your reaction is to switch to a CPU that runs embedded closed-source software controlled by a corporate third party who decides what is authorized to execute on your own system? You can fix the problem with or without being nannied.
Spectre affected “All pre-2019 microprocessors”. So no, the spy chip did not protect you. Intel injected the spychip from 2008 forward and AMD did it from 2013 forward.
More generally, it’s not smart infosec to introduce complexity. It’s profoundly naive to stick a big attack surface in the core of your CPU. I think it’s quite well established that vulns exploit defects, and defects are proportional to complexity. Signing up for a closed source blob in the core of your processor is far from wise.
The /chase the shiny/ mentality neglects the fact that you sign up for the worst kind of vulns – the unknown variety. With old gear the vulns are more of the known variety, which you have a fighting chance of controlling for.
rockSlayer@lemmy.blahaj.zone 17 hours ago
Lashing out at me was unnecessary. I was pointing out that there are 2 catastrophic vulnerabilities that are going to be present in every chip that meets your criteria.
I’m not defending the IME or the PSP. The most generous thing I can say about them is that they are unnecessary. I’m pointing out that the chips that you want to use have been unsupported for so long that they have catastrophic vulnerabilities that have never even been attempted to be patched. There are more catastrophic vulnerabilities than just Spectre and Meltdown.
evenwicht@lemmy.sdf.org 7 hours ago
It was an attack on your bullshit. Not on you personally.
And I was pointing out that you are wrong.
You are advocating for chips that are /more/ vulnerable, not less. You are advocating for chips with a much larger attack surface and unknown vulns. Overall, you are giving poor advice from an infosec standpoint.
I’m waiting.
rockSlayer@lemmy.blahaj.zone 1 hour ago
No, you weren’t. You were being pedantic. AMD will have Spectre. Intel will have Spectre and Meltdown. 2 vulnerabilities.
No, I wasn’t. Stop putting words in my mouth. Unless you know how to write microcode, I have serious doubts that you are capable of successfully patching the vulnerabilities on those chips.
Do whatever you want. I don’t care.