Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Yes, it is. OSes protect that ability to prevent malicious microcode, too. The update mechanism is published by Intel, too. Section 9.11 (not page 9.11) https://www.intel.com/content/dam/www/public/us/en/documents...


I always assumed that the CPU itself would have an internal signature verification mechanism built in. But after searching it seems the OS or BIOS is responsible for quite a lot... I haven't found anything clearly stating if and where cryptographic signatures are verified. Once source at least suggested that it's only present on >2013 CPUs !

[edit]

This is an interesting old paper on x86 microcode security: https://www.dcddcc.com/docs/2014_paper_microcode.pdf




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: