Intel isn't alone; search "9c5a203a" for some equally interesting stuff on the AMD side.
Intel isn't alone; search "9c5a203a" for some equally interesting stuff on the AMD side.
I will say, the thing security researchers find are simply amazing to me
I've been down so many "rabbit holes" aka "levels of abstraction" aka "abstraction hierarchies" aka "turtles on top of turtles" aka "things stacked on top of other things" (compare with Monty Python's "society for putting things on top of other things") in my life as a Programmer (and in my secret life as an Philosopher! Shhh, don't tell anyone! <g>. And yes, I know... "Keep the day job"...<g>) that one more ("I'll go down this last rabbit hole, and then I'll be finished, really!") really won't make that much more difference! <g>
Before I get started on that one though, two more quick references about "abstraction hierarchies" aka "rabbit holes".
On the one hand, we have Joel Spolsky's magnificent essay, "The Law of Leaky Abstractions (https://www.joelonsoftware.com/2002/11/11/the-law-of-leaky-a...) and on the other, we have the Biblical story of "The Tower Of Babel".
Now, I am not the member of any religion, I don't endorse any religious text over any other, but any intellectual worth his salt -- should read both of these writings, and compare them.
Once you've done that, then compare what's being said to abstraction hierarchies of all sorts.
We see abstraction hierarchies in code, we see them in language (especially when a language changes over many years, as it changes, fractures and sediments). We see them in Law (Law in the U.S. as it is practiced today can be compared to an abstraction hierarchy -- not at all unlike The Tower Of Babel as a metaphor for this phenomenon, or Joel's essay as a more complete modern-day explanation of it...)
We see them in a number of places and systems.
We even see them in x86-land...
That's because the x86 (as far as all of my research has suggested, and someone correct me if you think I am wrong, with links/references please!) -- is really a RISC core with a separate microcode execution engine (the level of abstraction above the RISC core), and has been since at least the Pentium Pro (P6, 1995):
https://stackoverflow.com/questions/5806589/why-does-intel-h...
http://i.blackhat.com/us-18/Thu-August-9/us-18-Domas-God-Mod... (Or Google "Christopher Domas God Mode Unlocked") (Also, see the patents listed in this PDF)
https://arxiv.org/pdf/1910.00948v1.pdf
https://troopers.de/events/troopers16/655_the_chimaera_proce... ("We take a 12-core processor, inject microcode to simulate a PowerPC (2 cores) and a MIPS processor (2 cores), restrict 2 cores to i386 and leave 4 cores to amd64.")
So with all this in mind, let's turn back and look at VISA:
https://threatpost.com/undocumented-intel-visa-tech-can-be-a...
>"The Intel technology is called Visualization of Internal Signals Architecture (VISA), and is used for manufacturing-line testing of chips.
However, Maxim Goryachy and Mark Ermolov, security researchers with Positive Technologies, said in a Thursday Black Hat Asia session that VISA can be accessed – and subsequently abused — to capture data from the CPU using a series of previously-disclosed vulnerabilities in Intel technology."
You know, that sort of reminds me of lyrics from The Who's "You Better You Bet":
"I showed up late one night with a neon light for a VISA,
But knowing I'm so eager to fight can't make letting me in any easier..."
Hmmm, now who is "me" in the above context?
?
Could it be... (With my apologies to SNL's Dana Carvey as "The Church Lady")... a TLA? (Three Letter... er, group? <g>)
Hey, if any power-that-be is offended, then I'd like them to know that I only quote things that I find on some places on the Internet -- on other places on the Internet....
In other words, I am only the messenger... one of millions and billions, that also quote things that they find on the Internet -- on other places on the Internet...
(Side note: There should be a Monty Python sketch for that topic! <g>)
In other words, "don't shoot the messenger...(s)" <g>...