Skip to content

Comment on Hardware backdoors in some x86 CPUs

Comments

This shows that large companies making closed-source CPUs cannot be trusted. No doubt they would add whatever the government asks them to add.

What can be done to mitigate this? One option would be to buy a large FPGA and flash it with an open-source CPU. Another would be to emulate a CPU, working with encrypted data and commands, so that even if the backdoor in a host CPU tries to overwrite memory, it would only crash the emulated OS. One more option would be to run the code in a Virtual Machine like QEMU which translates the code and prevents issuing unknown instructions.

What can be done to mitigate this?

Buy hardware used by government computers that are rivals to your country.

So if American, buy Chinese CPUs and install Chinese Linux or HarmoneyOS Assuming there is nothing you are doing of interest to them, as that will also have back doors

After Snowden, one can only imagine the worst and think everything has a backdoor.

But unless you are a high level terrorist or other person of interest, no state organization is going to target you at this level

P.s. you say no one can trust closed source, but a lot of open source is maintained by one or two people or a small group, just takes infiltration by one or two trusted contributors to push malicious code in and unless someone looks and finds that code amongst millions of lines of code, may never be discovered (more so as mainstream media won't publish any thing)

While I do think this is a good idea, it may no longer be as good as it once was: https://journalrecord.com/2026/08/05/fbi-law-enforcement-tie...

If you’re just an average dissident, it’s probably still good advice though.

I was thinking about something similar recently: if you bought a US govt purchased laptop like the ruggedized Dell Latitude I saw, would it be less likely to have Intel's IME enabled?

If many people do this then I'm sure China will find some uses for that data at some point.

Sure but the cops aren't going to pull you over based on what you think about Chinese policy. Government do mess with people across international borders, but the capacity to do that is inherently limited.

Sure but the cops aren't going to pull you over based on what you think about Chinese policy.

You might be surprised to learn that China has operated clandestine prisons in the US!

https://www.justice.gov/archives/opa/pr/two-arrested-operati...

Blackmail is still a possibility ...

Plus your data can be sold on the market. To US based entities. While the Chinese still hold on to the data for future uses ...

That still doesn't resolve who is more likely to blackmail or otherwise misuse data. I think it's a Chinese saying: the mountains are high and the emperor is far away.

Can't Chinese government exchange the data with your government whenever they need it?

It's not just the government. The government sneakily adds stuff they think only they can exploit, but skilled non-state actors can exploit hardware features regardless of whether it was put there by the government. And as we get widespread diffusion of increasingly capable AI, it will become easy and cheap to do for pretty much anyone, and so will defense.

Assuming bio-digital integration continues (i.e., humans keep pace with ASI via neural interfaces), the long term solution is total hardware sovereignty, aka the digital equivalent of bodily integrity and autonomy. We have to miniaturize and widely diffuse fab technology such that computer manufacturing can be done in local small businesses or even at home: automated chip fabbing, 3D printing, and assembly in one fridge-sized appliance you can buy at the nearest supermarket, and it can make parts to build another one of itself.

It's basically reproduction, but for the digital part of your body instead of the bio part. You should be able to design and fab your own custom chips, PCB, and chassis to build your neural interface from scratch, and write personal defense software that actively adapts to threats - a digital immune system. You'll also have the option to delegate some or all of that to a collective, but it would mean losing your individual sovereignty and becoming part of a larger organism in a symbiogenesis or multicellular evolution kind of way.

bodily integrity and autonomy

Which you already do not have. And what you do have, is being eroded further.

You live in a world where you can be forcibly caged for a faulty manipulation of symbols you did not even consent to learning! You can be caged for doing things for your "own" body; in turn, repairs to your body can be denied and even deemed "impossible" because your physical existence threatens someone's illusions.

Maybe hunter-gatherer bands could've been said to have been autonomous. But the individual? Simply a replaceable embodiment for vast, impersonal forces. Your body and mind have always been property of the society that manufactured you. You do not own even your cherished the illusion of autonomy; it's just another behavior taught to you to make you produce more for your masters.

That's a somewhat accurate description, and you could even replace "society" with "universe". But what I'm defending is precisely the apparent feeling of autonomy, which is just called "autonomy" in colloquial terms omitting the philosophical baggage. I don't think it's fair to call this illusory, because you have no basis to define what an illusion is if you accept that all you know and all that you are is the product of universal influence. Included in that universal influence is every instance of experience from which your understanding of the concept of "illusion" was derived, so "illusion"/"real" would refer to the same thing in your worldview.

Now, taking a pragmatic materialist stance: we are obviously bound by physics and cannot move in certain ways. We can predict what action a person will take from their brain activity before the person becomes aware of their decision themselves. But what the brain does to convince you that oneself is in control is probably the exact thing that's required for life to thrive. It was the evolutionary path taken, and it's also the future I strive for, and I hope others would do the same.

Another thing that can be done is more crowdfunded bounty programs.

5 here: https://cybersecuritynews.com/bug-bounty-platforms/

The issue are "bugs" could be randomly distributed, even across the same version number of some device.

Sample sizes and statistics come into play at that point.

Whistleblower protections are an avenue, but people can still be dealt with harshly (Schulte) and degree-of-protection can come down to motive. But motive itself is multivariate, is it not? A local-first Fediverse, with some type of "guaranteed anonymity" would work, though. But anonymity doesn't mean something can't be a hoax either, so it becomes a signal vs noise issue at that point. Yet, "nothing totally secure ever really is."

Source information can be embedded in the period of a printed sentence too.

A moral world is the answer to many problems. Something to ponder. People are said to only see the errors in their ways after death in the "hall of mirrors."

-- https://web.archive.org/web/20060102095331/http://maitreya-e...

Economic espionage is something to also think about. You may be doing everything right and that's what makes you a target. "If I'm not top dog, target anyone that is."

Perfect anonymity in crypto can also aid whistleblowing so that dump data = get paid.

Once you control the hosts CPU it's game over for the guest. The best you can do is to fetch old PPC G4 Apple computers or Thinkpads.

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.