Important Security disscussion about Intel-ME and AMD-PSP

Unless there’s audited (blueprint + fabrication) Open Source hardware that we can use to run our Open Source operating systems… I don’t think it matters much… Reasons:

Open-source Hardware - Kicksecure chapter Open Source BIOS and Firmware Security Impact in Kicksecure wiki

Interesting link with the exact quote that I very much agree with. Quote security researcher Christian Werlingarchive.org in Question, regarding psparchive.org:

From my personal perspective, in terms of threats customers already need to trust AMD with manufacturing something as complex as a CPU without introducing bugs (let alone backdoors). “Cleaning” one small piece of this complex system (i.e. the PSP’s firmware) would be a drop in the ocean.



No idea if this is related:

https://www.amd.com/en/technologies/manageability-tools


new wiki chapter written just now:
Open-source Hardware - Kicksecure chapter Requirements for Trustworthy Hardware in Kicksecure wiki

I would guess because:

  • Broken / non-existing / difficult business model. See: Open Source Business Models
  • Extremely difficult. There are no people working on this under these conditions.

General security question. Unspecific to Whonix.

Can be resolved as per: