Comment by szatkus
5 hours ago
MediaTek is a Taiwanese company. Xiaomi could put any backdoor that the government tell them to install and TSMC won't be able to catch that.
5 hours ago
MediaTek is a Taiwanese company. Xiaomi could put any backdoor that the government tell them to install and TSMC won't be able to catch that.
I'm unaware of any actual hardware backdoors introduced by primary manufacturers in practice, especially those installed in Xiaomi hardware.
There are accounts of interdiction and post-manufacturing compromises, such as those revealed in the Snowden leaks (2013) and most recently by reporting about the Israeli security services' sabotage of Hezbollah pagers and 2-way radios. These projects didn't expose primary manufacturers to the reputational and legal risk of association.
Until there's evidence of backdoors implanted by these companies, it's better to adopt a "trust but verify" approach and use standard layered security practices to detect intrusion. Conventional network intrusion and insider threat campaigns carry less risk of failure and are simpler and cheaper to execute.
Intel management engine
“It’s not a vulnerability, it’s a feature!”
I'm only aware of some software backdoors in Chinese devices, but times when you could've reverse engineered a chip with microscope are long gone. If there are any it would be really difficult to find them.
[flagged]
Get off the short bus twin. CPU backdoors do no good unless there is cooperation with network driver code or the CPU itself has full operating system with a full network stack.
Intel's ME comes really close to that, but I don't think Intel's ME has drivers for every possible NIC and bus a NIC can appear on in its little Minix. So, just put a Broadcom NIC in a PCIe slot and leave the Intel onboard NIC empty, or LAN facing only.
Xiaomi may get Chinese 4G/5G baseband chip manufacturers to put in backdoors in Chinese phones, but they're not needed - the Chinese government pretty much already has total control of its Internet. For other countries, how are they going to make Qualcomm provide something undocumented CPU instructions can access.
You can refute their statement without personal attacks.
Not knowing a thing makes someone uninformed, not retarded.
My retardation status is unrelated to my statement. You assert there are top secret register values but without any evidence beyond your most recent psilocybin trip.
The existence of undocumented hardware behavior isn't proof of anything.
Everyone relax. This guy on the Internet is unaware of any.
And are you aware of any? If nobody can find evidence then it's probably not a widespread risk.
Do you say the same about Intel, Amd, etc. or is it only big bad China?
There's been 40 years of documented push back when western governments try to backdoor things - starting with clipper. Pushback is not always successful - but it's far more transparent then China.
>There's been 40 years of documented push back when western governments try to backdoor things
A bit of selective memory necessary for that take given good old Crypto AG
https://en.wikipedia.org/wiki/Crypto_AG
Are there any documented cases of backdoors being present in Chinese hardware at time of manufacturing?
3 replies →
Too many propoganda leads to expressions like yours. Sorry your story has zero foundation and is fox news quality.
1 reply →
My opinion about Trump is as bad as the next guy's, but we still have better relation with the USA than with China. And it's not like we have much choice.
There are already American backdoors on intel and AMD chips everywhere, we call them ME and PSP. Switching to chinese tech won't make it worse.
Now, if the EU would start make to make chips that have no subsystem to screw me over, that would be something.
> Now, if the EU would start make to make chips that have no subsystem to screw me over, that would be something.
Why would they not do the same? They are very pro-surveillance for a start.
Hopefully the same pushback that has so far stopped the worst of chat control would help. But even if not having more western alternatives would be very welcome. If you're in the US it may not resonate with you, but as a Canadian currently reading ongoing rhetoric about being annexed by the US I'd love to have options if things continue to go south with the status quo.
It's good to be skeptical about how we implement the idea of a "root of trust" in these machines, but matter-of-factly characterizing ME and PSP as "backdoor" is misleading and not useful.
TSMC doesn't care what you put in your CPUs. Apple could tell them they want to build a CPU where 90% of the transistor footprint is for a new CIA Engine that takes pictures of your feet every three seconds to trace where you've been from the smell and TSMC's response would be "how many wafers do you want?".