← Back to context

Comment by bflesch

2 days ago

Yes but it's much easier to tell devs "put your keys here" and then just take that.

We’re talking about a hidden CPU backdoor that would let you secretly come in and retrieve keys you’ve squirreled away somewhere. I don’t think finding the keys is the hard part.

  • Are you serious?

    The CPU firmware blobs are encrypted and nobody except Intel can see what is running there. A handful of people on the planet have the tools and skills to analyze the chip for backdoors.

    A small section of CPU cache could stay powered even though the OS is shut down, persisting the keys that were passed to the AES CPU instruction. As CPU is directly linked to wifi/bluetooth and USB chipsets, exfiltration could be possible both wirelessly and via special USB payload.

    • Compared to all of that, looking for certain patterns in the instruction stream is barely any more effort than looking for specific instructions.