From: David Craven <david@craven.ch>
To: Danny Milosavljevic <dannym@scratchpost.org>
Cc: guix-devel <guix-devel@gnu.org>
Subject: Re: [PATCH 7/7] gnu: Enable CONFIG_HOTPLUG_PCI.
Date: Thu, 2 Feb 2017 22:50:31 +0100 [thread overview]
Message-ID: <CAL1_im=2pZgmhoyvfNv1pQGooshMtbqeYN8eWYzYFZmprmDeQA@mail.gmail.com> (raw)
In-Reply-To: <20170202214159.2901d3e4@scratchpost.org>
Hi Danny,
> For example, let's say Intel had non-updateable microcode on its CPUs and it included a backdoor. If anyone *ever* found it, nobody would trust Intel ever again - and Intel couldn't sweep it under the rug because millions of physical chips that include the backdoor would be in the hands of different people. What could they do?
>
> On the other hand, if firmware is updateable by a (possibly automated) program, that program could easily check whether it's running on *your* computer specifically and then give you a special firmware. Now nobody but you has a chance to find it. Not to mention checking the date etc.
>
> With all the spying going on that's a *real* possibility. Also, many people already found backdoors in BIOS updates for example - so it's not theoretical.
But you can check the hash of the firmware. If a device doesn't have
internal flash we at least know that it's running the firmware we are
giving it. If the device has internal storage and if someone wanted to
target you and did have the resources to do so, they could reflash the
chip and you'd never know. Isn't human error just as scary as the NSA?
next prev parent reply other threads:[~2017-02-02 21:50 UTC|newest]
Thread overview: 30+ messages / expand[flat|nested] mbox.gz Atom feed top
2017-02-01 23:35 [PATCH 1/7] gnu: mutter: Update to HEAD David Craven
2017-02-01 23:35 ` [PATCH 2/7] gnu: Add git-crypt David Craven
2017-02-09 16:52 ` Ludovic Courtès
2017-02-01 23:35 ` [PATCH 3/7] gnu: Add replace-input procedure David Craven
2017-02-09 16:54 ` Ludovic Courtès
2017-02-10 11:31 ` David Craven
2017-02-01 23:35 ` [PATCH 4/7] gnu: Add appstream-glib David Craven
2017-02-09 16:55 ` Ludovic Courtès
2017-02-01 23:35 ` [PATCH 5/7] gnu: Add gnome-disk-utility David Craven
2017-02-05 5:53 ` Maxim Cournoyer
2017-02-09 16:57 ` Ludovic Courtès
2017-02-01 23:35 ` [PATCH 6/7] system: install: Add gptfdisk to installation os David Craven
2017-02-09 16:58 ` Ludovic Courtès
2017-02-01 23:35 ` [PATCH 7/7] gnu: Enable CONFIG_HOTPLUG_PCI David Craven
2017-02-02 0:39 ` David Craven
2017-02-02 15:53 ` David Craven
2017-02-02 17:07 ` David Craven
2017-02-02 19:20 ` Danny Milosavljevic
2017-02-02 20:18 ` David Craven
2017-02-02 20:41 ` Danny Milosavljevic
2017-02-02 21:50 ` David Craven [this message]
2017-02-03 2:54 ` David Craven
2017-02-03 17:45 ` Danny Milosavljevic
2017-02-09 17:02 ` Ludovic Courtès
2017-02-10 11:58 ` David Craven
2017-02-02 0:38 ` [PATCH 1/7] gnu: mutter: Update to HEAD David Craven
2017-02-09 17:00 ` Ludovic Courtès
2017-02-10 14:56 ` David Craven
2017-02-09 16:52 ` Ludovic Courtès
2017-02-09 16:57 ` David Craven
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to='CAL1_im=2pZgmhoyvfNv1pQGooshMtbqeYN8eWYzYFZmprmDeQA@mail.gmail.com' \
--to=david@craven.ch \
--cc=dannym@scratchpost.org \
--cc=guix-devel@gnu.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
Code repositories for project(s) associated with this external index
https://git.savannah.gnu.org/cgit/guix.git
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.