Also mildly interesting, Dmitry Sklyarov was credited… appears to be the same one from Elcomsoft that got arrested at one point because Adobe complained (and DMCA).
"may allow an unauthenticated user to potentially enable escalation of privilege via physical access"
I'm sure there's cases where that's still an issue, but for me, if they have their hands on it it's probably game over via some other route.
They're not impenetrable per se, but iPhone is pretty secure, even with physical access.
Citation seriously needed for this bold statement.
Apple is not known for timely patches for their vulnerabilities, so no, you don't even need physical access to compromise iPhones, RCE vulns not acknowledged by Apple will do just fine. Just ask shady Israeli/Saudi security companies.
Also, nothing is ever impenetrable. In cybersecurity, if your opponent has physical access to your device then it's considered game over and you have to wipe or even throw it away. That's why burner devices are heavily used.
Plus, what do iPhones have to do with the Intel chips here anyway?
Ironically, given lots of early Iphone jailbreaks were due to Apple finding out that CPUs have JTAG ports too late.
The Atom C3000 series is also widely used in NAS because it supports ECC memory and can be passively cooled while still being performant enough to not be a bottleneck.
right, not so much low-end as dead-end :)
In any case, it is not like I was making some deep point, other than a cheap shot at Intel mobile/embedded effort :).
I really miss the days when Intel basically released all the documentation you needed to build a computer around their CPUs. The Pentium was when they started being secretive.
I agree that there is value in having control over your devices. But control, by its nature, must be limited. If everyone controls your device, nobody does, certainly not you.
> After a year of the coordinated disclosure process, we (+ @h0t_max and @_Dmit ) can finally share: we found a reliable, not damaging way to extract the security fuses (Chipset + EPID root keys) from the Intel platforms.
I wonder if these people really think they are heroes for effectively helping Intel further its user-hostile actions.
There are some who disagree the process is good, works well, or actually achieves its goals. However most (not all) go along with it and don't moralize about corporate strategy or try to hold their vulnerability discoveries over a company as some kind of activism.
I think it's pretty safe to say they don't think they are heroes for working with the vendor, they are probably quite rightly proud of their discovery and work though.
You comment seems unnecessarily hostile toward them.
In other words, they're mostly bootlickers.
You comment seems unnecessarily hostile toward them.
Intel is unnecessarily hostile towards us! Those who help the enemy, should also be considered enemies.
No that is not what bootlicker means.
> Intel is unnecessarily hostile towards us!
An organization like Intel has extremely complicated strategies and estimations of what they deem "necessary". Whether you personally like it or not, a company has some leeway to do their own thing with the products they sell.
> Those who help the enemy, should also be considered enemies.
And you have purchased no products that contain any parts or other companies that license Intel's IP because that benefits Intel in the form of revenue in any way. What computers, phones, etc do you use, then, that come from companies which don't act in any user hostile ways?
The latest version of what? microcode? BIOS?
https://www.theregister.com/2017/02/07/intel_atom_failures_g...
https://support.hp.com/us-en/document/ish_5031100-5031212-16...
Whats going on? These arent to Atom CPUs alone it seems.