From nobody Tue Nov 15 08:03:30 2022 X-Original-To: freebsd-security@mlmmj.nyi.freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2610:1c1:1:606c::19:1]) by mlmmj.nyi.freebsd.org (Postfix) with ESMTP id 4NBJbB1VBJz4hGQ5; Tue, 15 Nov 2022 08:03:34 +0000 (UTC) (envelope-from grarpamp@gmail.com) Received: from mail-vs1-xe29.google.com (mail-vs1-xe29.google.com [IPv6:2607:f8b0:4864:20::e29]) (using TLSv1.3 with cipher TLS_AES_128_GCM_SHA256 (128/128 bits) key-exchange X25519 server-signature RSA-PSS (4096 bits) server-digest SHA256 client-signature RSA-PSS (2048 bits) client-digest SHA256) (Client CN "smtp.gmail.com", Issuer "GTS CA 1D4" (verified OK)) by mx1.freebsd.org (Postfix) with ESMTPS id 4NBJb92LWcz3rKM; Tue, 15 Nov 2022 08:03:33 +0000 (UTC) (envelope-from grarpamp@gmail.com) Authentication-Results: mx1.freebsd.org; dkim=pass header.d=gmail.com header.s=20210112 header.b=MUfwuStu; spf=pass (mx1.freebsd.org: domain of grarpamp@gmail.com designates 2607:f8b0:4864:20::e29 as permitted sender) smtp.mailfrom=grarpamp@gmail.com; dmarc=pass (policy=none) header.from=gmail.com Received: by mail-vs1-xe29.google.com with SMTP id t14so13905818vsr.9; Tue, 15 Nov 2022 00:03:33 -0800 (PST) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20210112; h=content-transfer-encoding:cc:to:subject:message-id:date:from :mime-version:from:to:cc:subject:date:message-id:reply-to; bh=VQa2CzeALC4pUXujsTEoWTLIvhgvNQGmv+0pWHtj3Tw=; b=MUfwuStu4E0TGj0nWrhhsC0bh9R+F5NiwF9Sj2a9Kl3rc9mkbRoJrkISzxBeEqkdnt dIfFbX8q80UWsUyvwtKs3dlSJ+GMgGc9Hlg8Kq1clJejJ1yWnmDhSoxdGK9d5eYBqD8O 4NjEeSBmCF3jkz9i2Dg1A+hXDeaiOwmsiCUj7gVwKxF7lZqa4Uelg1kSZqgK5jZduSXu mmjl5yZfPpeIyZbGt5EbnRpmUdB0VVoKIU+/gLmfnZvw+u72VcuPo70BTG2hTL8z4s6s TWMwoOKmaQbycCSeeFCrC9g4NaYGfkhYJbefsAnMXELYNtg7k5cJyW6PTzWCZkGrRcIz pOIA== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20210112; h=content-transfer-encoding:cc:to:subject:message-id:date:from :mime-version:x-gm-message-state:from:to:cc:subject:date:message-id :reply-to; bh=VQa2CzeALC4pUXujsTEoWTLIvhgvNQGmv+0pWHtj3Tw=; b=Jvzx7k/hyKZhuNuWY4OugbNjR6pLe3yLCRKvcw3yzqp4b9CG2FGoBidnywXp8MpSj4 8EIb0rDn2f9Y4QLvpm7vlZB+DQKGh9iacHuh0TLVJ6H8Cfp4BCBK/Wk0lWrN6TpKYt6q yq9gD8PQftwMstd0fF+CS5ILTaTPJNHrvzjd51NmtBLjXsqTAlDzgKldtQsN/IgRy7Lx ouFwHoDAOYgTrLLCQX4RNoxGWW+7EPIPZG/ueAkwXqWAznioelU15XojbQ4tjTPY1ap4 lwJehYO1Z/AgLIDSNFNJnhcK3EAc9KbptI9HqqFdvs6+aGNj0+MkCeOqVy6RNuA4FrEw MODA== X-Gm-Message-State: ANoB5pnsnQgH83PnJQY1KeLNq/qJfff01Fpt40MAmHaYmMnJftrkn2Jl 6XQHv3r/QN+2dP0iDebLWj5RPpa8VWXd4t/9w9fJY+GdW82WeItDL7o= X-Google-Smtp-Source: AA0mqf5v8J8N7+bD4HOHlhtUy4ony0JMHYsNqpiB4EkQfdi0vvfA0qJkFzkLcNecV9U5/ClSyYCKCodlqjE1CkEjtnw= X-Received: by 2002:a67:ec86:0:b0:3ad:451e:936 with SMTP id h6-20020a67ec86000000b003ad451e0936mr8360616vsp.84.1668499410984; Tue, 15 Nov 2022 00:03:30 -0800 (PST) List-Id: Security issues List-Archive: https://lists.freebsd.org/archives/freebsd-security List-Help: List-Post: List-Subscribe: List-Unsubscribe: Sender: owner-freebsd-security@freebsd.org X-BeenThere: freebsd-security@freebsd.org MIME-Version: 1.0 Received: by 2002:a59:1504:0:b0:32a:c833:f266 with HTTP; Tue, 15 Nov 2022 00:03:30 -0800 (PST) From: grarpamp Date: Tue, 15 Nov 2022 03:03:30 -0500 Message-ID: Subject: Black Box Executes Assembly ABI, Yet Which Masters Loom To: freebsd-questions@freebsd.org Cc: freebsd-security@freebsd.org Content-Type: text/plain; charset="UTF-8" Content-Transfer-Encoding: quoted-printable X-Spamd-Result: default: False [-2.00 / 15.00]; NEURAL_HAM_SHORT(-1.00)[-0.998]; DMARC_POLICY_ALLOW(-0.50)[gmail.com,none]; R_SPF_ALLOW(-0.20)[+ip6:2607:f8b0:4000::/36]; R_DKIM_ALLOW(-0.20)[gmail.com:s=20210112]; MIME_GOOD(-0.10)[text/plain]; MLMMJ_DEST(0.00)[freebsd-questions@freebsd.org,freebsd-security@freebsd.org]; FROM_EQ_ENVFROM(0.00)[]; ARC_NA(0.00)[]; FREEMAIL_ENVFROM(0.00)[gmail.com]; MIME_TRACE(0.00)[0:+]; ASN(0.00)[asn:15169, ipnet:2607:f8b0::/32, country:US]; RCVD_IN_DNSWL_NONE(0.00)[2607:f8b0:4864:20::e29:from]; DKIM_TRACE(0.00)[gmail.com:+]; RCVD_TLS_LAST(0.00)[]; FREEMAIL_FROM(0.00)[gmail.com]; FROM_HAS_DN(0.00)[]; RCPT_COUNT_TWO(0.00)[2]; TO_MATCH_ENVRCPT_ALL(0.00)[]; RCVD_COUNT_THREE(0.00)[3]; TO_DN_NONE(0.00)[]; MID_RHS_MATCH_FROMTLD(0.00)[]; DWL_DNSWL_NONE(0.00)[gmail.com:dkim] X-Rspamd-Queue-Id: 4NBJb92LWcz3rKM X-Spamd-Bar: - X-ThisMailContainsUnwantedMimeParts: N > gives ... sense of ultimate control ... we are still the masters of the c= omputer. Tens of billions of gates on modern CPU's NIC's GPU's HDD's, every single one of them a closed source hw black box, same for thousands upon thousands of lines of firmware, hundreds of undocumented opcodes some now found with fuzzers, "bugs", exploits, off by one "oops" in that ancient commit, "Will Not Fix "Errata"". A world full of agents spies moles and crypto-corrupting GovCorps, phones remotely controllable via baseband, package interception mitm, etc. The average kernel bigger than Encyclopedia= . No, it's entirely plausible that what you think is "your" black box to play master level of Tetris on, is actually someone else's just waiting for that magic packet or execution pattern, always on, backed up to the connected cloud, auto updated, AI enhanced, datamined, and oh my those alluring honeytraps... Cortana Alexa and Ring. " Communication in a world of pervasive surveillance Sources and methods: Counter-strategies against pervasive surveillance architecture ISBN: 978-90-386-5471-3 March 2022 The Adversary 4.4 - Standardization of cryptographic sabotage p.81 4.6 - ANT Catalog p.92 " Demand and participate in the creation, startup, and purchase of... #OpenFabs , #OpenHW , #OpenAudit , #FormalVerification , #CryptoCrowdFunding , #OpenTrust , #GuerrillaNets , ... Your Freedom may well depend on it. "Wer die Wahrheit nicht wei=C3=9F, der ist blo=C3=9F ein Dummkopf. Aber wer= sie wei=C3=9F und sie eine L=C3=BCge nennt, der ist ein Verbrecher." 1 -- Bertold Brecht, Das Leben des Galilei, Seite 71