logoalt Hacker News

userbinatortoday at 8:58 AM3 repliesview on HN

It's not even a "backdoor", it's documented in the datasheet...

http://datasheets.chipdb.org/VIA/Nehemiah/VIA%20C3%20Nehemia... (page 82)

...which along with the already publicly-known microarchitecture of the C3 makes this statement sound like total nonsense:

The rosenbridge backdoor is a small, non-x86 core embedded alongside the main x86 core in the CPU

I remember laughing at this with a few others knowledgeable in x86 when it first came out; a self-proclaimed "security researcher" who somehow failed to RTFM.

There's even a Wikipedia article about it now, with a link to the alternate instruction set documentation: https://en.wikipedia.org/wiki/Alternate_Instruction_Set


Replies

inigyoutoday at 9:08 AM

Was this documentation public at the time? The pdf still does not document the instructions themselves.

show 2 replies
phiretoday at 9:38 AM

"It's documented in the datasheet" is such a weak excuse for a backdoor.

Documenting a backdoor doesn't make it not a backdoor, just means it's not a hidden backdoor.

The fact that a number of machines shipped with the backdoor accidentally enabled, and nobody noticed for over a decade shows just how dangerous even a documented backdoor can be. The oversight wasn't even detected by someone reading the manual, it was detected by a security researcher who wrote a generic tool to fuzz out such backdoors.

show 1 reply
cinntailetoday at 9:07 AM

It's not as clear cut as you describe it here. In the other old thread you linked there was no real consensus if this should be considered a backdoor or not.