TE
科技回声
首页24小时热榜最新最佳问答展示工作
GitHubTwitter
首页

科技回声

基于 Next.js 构建的科技新闻平台,提供全球科技新闻和讨论内容。

GitHubTwitter

首页

首页最新最佳问答展示工作

资源链接

HackerNews API原版 HackerNewsNext.js

© 2025 科技回声. 版权所有。

Intel In Bed with NSA?

185 点作者 lifeguard将近 12 年前

15 条评论

comex将近 12 年前
It is really, really hard for me to see this as anything other than utter paranoia. As one of the messages in the thread stated:<p>&gt; Right. How exactly would you backdoor an RNG so (a) it could be effectively used by the NSA when they needed it (e.g. to recover Tor keys), (b) not affect the security of massive amounts of infrastructure, and (c) be so totally undetectable that there&#x27;d be no risk of it causing a s<i></i>tstorm that makes the $0.5B FDIV bug seem like small change (not to mention the legal issues, since this one would have been inserted deliberately, so we&#x27;re probably talking bet-the-company amounts of liability there).
评论 #6040499 未加载
评论 #6038409 未加载
评论 #6039616 未加载
评论 #6040396 未加载
评论 #6039657 未加载
评论 #6040600 未加载
评论 #6039199 未加载
__alexs将近 12 年前
The comments about RdRand being impossible to verify because it&#x27;s on-chip seem quite reasonable. (Although Intel have tried to be quite open about how it works. <a href="https://sites.google.com/site/intelrdrand/references" rel="nofollow">https:&#x2F;&#x2F;sites.google.com&#x2F;site&#x2F;intelrdrand&#x2F;references</a>)<p>I have no idea if RdRand is the <i>only</i> source of entropy for &#x2F;dev&#x2F;urandom in the kernel these days but that does seem quite silly. Especially as RdRand is documented as having two error conditions, not enough entropy, and that the hardware appears to be broken.<p>In any case, here&#x27;s the LKML thread where it was merged too <a href="http://thread.gmane.org/gmane.linux.kernel/1173350" rel="nofollow">http:&#x2F;&#x2F;thread.gmane.org&#x2F;gmane.linux.kernel&#x2F;1173350</a>
评论 #6039264 未加载
adr_将近 12 年前
If the NSA is working with Intel, they&#x27;re not going to bother with an RNG... The processor is the most trusted part of the computer security model - why would you choose bad random numbers as your attack vector?<p>Relevant talk: Hardware Backdooring is Practical - Jonathan Brossard <a href="https://www.youtube.com/watch?v=j9Fw8jwG07g" rel="nofollow">https:&#x2F;&#x2F;www.youtube.com&#x2F;watch?v=j9Fw8jwG07g</a>
starmole将近 12 年前
This issue just does not pass the rubber hose test. If the NSA wanted and got a backdoor in intel chips there are so many better ways to do it than introducing a bad hw rng. If you wanted one exploit in the chip, why would you pick a hard to exploit one and user controlled one on top of that? It&#x27;s classic paranoid thinking: People have a choice to use the hw rng or not. So it becomes a big deal. All the while not addressing the non-choice issue like having a potential backdoor triggered by a specific instruction sequence.
评论 #6040057 未加载
adventured将近 12 年前
It&#x27;s safe to assume every core technology company has been compelled to be in bed with the NSA in <i>some</i> form or another. Intel has been anti-trust managed by the government for nearly two decades. Getting access to the monopoly desktop &#x2F; laptop processor maker would be far too rich a target to ignore.
评论 #6039615 未加载
stfu将近 12 年前
Would appreciate some sort of a summary. Reading some mile long email exchange just to figure out what the headline is really about makes it kinda tricky.
评论 #6039779 未加载
spindritf将近 12 年前
I upvoted but the current title (&quot;Is Linus Tovalds &#x27;evil&#x27;?&quot;) is downright horrible and I hope a mod will revert it to the original one soon.
评论 #6038420 未加载
lucb1e将近 12 年前
Submitted a question here: <a href="http://crypto.stackexchange.com/q/9210/2512" rel="nofollow">http:&#x2F;&#x2F;crypto.stackexchange.com&#x2F;q&#x2F;9210&#x2F;2512</a><p>Feel free to edit the question if you have anything to add!
gmuslera将近 12 年前
Hanlon&#x27;s razor help in this kind of discussions. Maybe when Linus took that option didn&#x27;t saw Intel as something that would intentionally make predictable its RNG for following government orders, and just choose to not reimplement the wheel where it was already available.<p>Would he take another option since last month? Maybe in the light of this he could take back that choice.
评论 #6039501 未加载
VMG将近 12 年前
Intersting discussion, but incredibly bad title.
评论 #6038423 未加载
3327将近 12 年前
This is nothing more than speculative emails.
mr_spothawk将近 12 年前
Did anybody look @ <a href="http://leitl.org/" rel="nofollow">http:&#x2F;&#x2F;leitl.org&#x2F;</a><p>This email could just as easily be the musings of an insane person, which is what&#x27;s suggested by the contents of the website.
tomphoolery将近 12 年前
The thing that the thread about is kinda interesting, too. <a href="https://heml.is/" rel="nofollow">https:&#x2F;&#x2F;heml.is&#x2F;</a>
rooster8将近 12 年前
One reason it would be a poor decision for the NSA to recommend Intel backdoor the RNG: Intel would be in a position to sell&#x2F;leak the backdoor secret to other governments.<p>The NSA would have no way of blocking it from being used to attack the US. And you can&#x27;t roll out a hotfix for billions of CPUs worldwide.
jvreeland将近 12 年前
Doesn&#x27;t the NSA end up using these machines as well? It seems like a lot of work to introduce a flaw that you have work around for you own use later. And if it&#x27;s a hardware flawu, I doubt even the NSA could demand intel or amd manyfacture seperate batches for their own use.