Comment by linkregister
4 hours ago
I'm unaware of any actual hardware backdoors introduced by primary manufacturers in practice, especially those installed in Xiaomi hardware.
There are accounts of interdiction and post-manufacturing compromises, such as those revealed in the Snowden leaks (2013) and most recently by reporting about the Israeli security services' sabotage of Hezbollah pagers and 2-way radios. These projects didn't expose primary manufacturers to the reputational and legal risk of association.
Until there's evidence of backdoors implanted by these companies, it's better to adopt a "trust but verify" approach and use standard layered security practices to detect intrusion. Conventional network intrusion and insider threat campaigns carry less risk of failure and are simpler and cheaper to execute.
Intel management engine
“It’s not a vulnerability, it’s a feature!”
I'm only aware of some software backdoors in Chinese devices, but times when you could've reverse engineered a chip with microscope are long gone. If there are any it would be really difficult to find them.
[flagged]
Get off the short bus twin. CPU backdoors do no good unless there is cooperation with network driver code or the CPU itself has full operating system with a full network stack.
Intel's ME comes really close to that, but I don't think Intel's ME has drivers for every possible NIC and bus a NIC can appear on in its little Minix. So, just put a Broadcom NIC in a PCIe slot and leave the Intel onboard NIC empty, or LAN facing only.
Xiaomi may get Chinese 4G/5G baseband chip manufacturers to put in backdoors in Chinese phones, but they're not needed - the Chinese government pretty much already has total control of its Internet. For other countries, how are they going to make Qualcomm provide something undocumented CPU instructions can access.
You can refute their statement without personal attacks.
Not knowing a thing makes someone uninformed, not retarded.
My retardation status is unrelated to my statement. You assert there are top secret register values but without any evidence beyond your most recent psilocybin trip.
The existence of undocumented hardware behavior isn't proof of anything.
Everyone relax. This guy on the Internet is unaware of any.
And are you aware of any? If nobody can find evidence then it's probably not a widespread risk.