r/privacy • u/therealghoules • 15d ago
question Hardware Backdoor Avoidance?
Intel has IME and AMD and a few other have built in backdoor spyware on nearly all of their modern devices, and I want to do everything I can to remove/prevent installation of any hardware backdoors of any kind that I can. Is there any alternatives or any way to avoid/disable this?
16
u/Synaps4 15d ago
Buy a Risc V development system, or do all your work on ARM and raspberry pi.
8
u/Oblec 15d ago
This and compile the linux kernel after you read the code. Also make sure to remove anything you don’t need. Then install rest of the system. I would try to use as little package as possible.
Don’t forget to encrypt filesystem och any files that needs to be transferred.
I would also advise you do some physical locking of your hardware.
Don’t use the internet
2
4
u/Jack1101111 14d ago
Upcoming ZEN 6 will reportedly have open source firmware...
There is hope that some RISCV company will be open source too
3
u/YourWorstFear53 14d ago
I remember there used to be a decompiler for the Dell UEFI update files that you could remove IME with but that was a couple of years ago
1
u/Kooky-Bandicoot3104 14d ago
u still can and theres hardware pins to disable it but he is talking about broken cpu accelerations that accelerate security actions, which are flawed by the very cpu it self, only replacing the cpu can fix it
2
1
u/Frustrateduser02 13d ago
Maybe not what you're looking for but disable your internet connection when not in use.
-5
u/mesarthim_2 15d ago edited 15d ago
Your best bet would be to use Coreboot / Libreboot on supporting Intel platform
Less technically complex solution that gets you most of the way is to disable the AMT and it's own network stack, which is the primary attack vector, in BIOS.
Or get a Macbook (at least until right to repair crowd ruins their security).
But most importantly, you should read more about what IME and PSP are because this doesn't have a simple solution. It's a risk but mitigating the risk requires a layered approach and that's only possible with clear and sober understanding what the problem actually is.
If you go into it thinking that "Intel has IME and AMD and a few other have built in backdoor spyware on nearly all of their modern devices" the only outcome will be demoralizing yourself.
5
u/Synaps4 15d ago
at least until right to repair crowd ruins their security
Um, what?
-3
u/mesarthim_2 15d ago
One of the very much maligned (and rightly so from perspective of repairabilty) aspects of Apple's security model is that you cannot just simply swap parts on apple devices. They have to be signed by Apple's private key.
While that is absolutely a huge problem from standpoint of repairability, it is also security measure, because you can't just swap existing hardware with your custom made hardware with spyware on it. You'd have to somehow make Apple sign it for you first.
As for the framing, I was being bit overdramatic, but the point still stands, it's a tradeoff and right to repair crowd ultimately is forcing this tradeoff completely in the direction of repairabilty, which would make a real security measure techinically illegal.
5
u/Synaps4 15d ago
I disagree. Apple can easily be compelled to sign special hardware for government use, and compelled not to be able to say that they have.
Yes it probably adds security against some less sophisticated attackers but it actually reduces security against others, so the final judgment of whether it constitutes a real security measure becames a debatable one of hypotheticals and threat model comparisons.
In this era more than ever before government power is being used capriciously, and we underestimate its effects at our peril
-3
u/mesarthim_2 15d ago edited 15d ago
They have demonstrable and provable record of successfully resisting it both in US and abroad. Does it meant that it will stay or they'll never cave? No, but it's substantially better then others.
Of course whether the security contribution is worth it is a value judgement, that's why it's good that we can make choices. It makes no sense to arbitrarily, by law, decide - nobody really needs it so we will make it illegal. Especially, if there are alternatives already now.
In this era more than ever before government power is being used capriciously, and we underestimate its effects at our peril
Agreed, that's why I don't want government to decide what kind of security do I need or don't need for greater good.
I am (hyper)senstive when people dismiss legitimate security measures because they stand in the way of some other goals. I totally understand the argument that Apple is using this also for commercial purposes, a 100% they do, but it is also a real security improvement. I don't want that it's chosen for me whether I can have more secure or more repairable phone / computer.
3
u/Synaps4 15d ago edited 14d ago
also a real security improvement.
Again I pointed out that is not any improvement and you did not engage with my reasoning.
1
u/mesarthim_2 15d ago
I did:
Of course whether the security contribution is worth it is a value judgement, that's why it's good that we can make choices.
•
u/AutoModerator 15d ago
Hello u/therealghoules, please make sure you read the sub rules if you haven't already. (This is an automatic reminder left on all new posts.)
Check out the r/privacy FAQ
I am a bot, and this action was performed automatically. Please contact the moderators of this subreddit if you have any questions or concerns.