guix-devel
[Top][All Lists]
Advanced

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: [PATCH 7/7] gnu: Enable CONFIG_HOTPLUG_PCI.


From: David Craven
Subject: Re: [PATCH 7/7] gnu: Enable CONFIG_HOTPLUG_PCI.
Date: Thu, 2 Feb 2017 22:50:31 +0100

Hi Danny,

> For example, let's say Intel had non-updateable microcode on its CPUs and it 
> included a backdoor. If anyone *ever* found it, nobody would trust Intel ever 
> again - and Intel couldn't sweep it under the rug because millions of 
> physical chips that include the backdoor would be in the hands of different 
> people. What could they do?
>
> On the other hand, if firmware is updateable by a (possibly automated) 
> program, that program could easily check whether it's running on *your* 
> computer specifically and then give you a special firmware. Now nobody but 
> you has a chance to find it. Not to mention checking the date etc.
>
> With all the spying going on that's a *real* possibility. Also, many people 
> already found backdoors in BIOS updates for example - so it's not theoretical.

But you can check the hash of the firmware. If a device doesn't have
internal flash we at least know that it's running the firmware we are
giving it. If the device has internal storage and if someone wanted to
target you and did have the resources to do so, they could reflash the
chip and you'd never know. Isn't human error just as scary as the NSA?



reply via email to

[Prev in Thread] Current Thread [Next in Thread]