507 karma · joined October 30, 2023
Such actions are part of the private sphere, which the state has absolutely no business policing, unless e.g. you commit some violent crime or are diagnosed with a severe mental illness.
The state's policing of what we are allowed to read is a modern day witch hunt.
I'll just take my speech to another site, before I get banned from this Hacker News completely.
Distributing or creating such material (with real children) is rightfully illegal. Possession with intent to distribute, as well. But absolutely not simple possession.
These crazy laws need to go, it's a modern 21st Century form of morality policing[1]. Such morality policing is not much more that primally driven primitive behavior, akin to which our tribal ancestors carried out, and coming from a part of our brain that is thousands of years old. It does not belong in a modern technologically based society. And the internet, with its fundamental lack of privacy, has enabled such morality policing on a shocking scale.
Such material can be easily generated locally with AI with no risk of detection by law enforcement, and planted into people's web browser caches or other temporary storage so easily. The government is basically giving any sophisticated hacker or state actor (e.g. Russia) a push-button way of destroying any political opponent with ease.
If you live in a Western country and criticize a Russian political figure too much, well the FSB (the successor to the KGB) is going to put child porn on your computer. They've already been caught doing precisely that. [2] So it's especially important in this current geopolitical situation we're in.
1. https://journals.sagepub.com/doi/abs/10.1177/135485652311936...
As was stated in the article[1], close to half a million dollars was spent on a social-justice related organization, the Mackenzie Mack Group.
“[Mckensie Mack Group] is a change management firm redefining innovation in the white-dominant change management industry.”
In the article it also says " While The Lunduke Journal does not like to delve too deeply into the Political Woods (tm), it should be questioned why so much money — possibly millions of dollars donated by individuals who thought they were supporting a web browser — is being funneled into highly political organizations that seem to have no involvement with the World Wide Web, Web Browsers, or any related standards. "
1. https://lunduke.locals.com/post/4387539/firefox-money-invest... "
https://support.xilinx.com/s/question/0D52E00006hpKdKSAU/zyn...
I understand burning eFuses is necessary during production, but having them blowable when the device is operating normally could be compared to building disposable devices. One logic or software error and the device can be bricked permanently. That is a ridiculous state of affairs. What about single event upsets or some EMI induced glitch causing eFuse corruption?
The power for burning the important fuses should be off at all times during normal operation. And we can have a test pad to supply the VPP during production.
In the case of the AMD processors, a separate bank of fuses can be used to store diagnostic data for warranty returns, if necessary. If those get corrupted somehow, the device won't malfunction. But the important ones should not be possible to program after manufacturing, no matter what happens to the logical state of the hardware, period.
If they did such a thing with car components, it would be shut down in no time. No different for computer parts.
Also a CPU that can be rendered permanently inoperable due to a software issue could be considered not fit for purpose and thus a defective product. Especially if it was intentionally designed this way - such that the CPU can self-cripple itself.
Maybe a legal firm would want to take up a class action against AMD for this potential product defect? Viruses and malware should not be able to physically destroy a CPU. There should be physical hardware protections against such destructive behaviour occurring due to a software induced logic error.
The PSP is not truly secure, someone should write a PSP eFuse bricker tool (Ryzenkill?) that can be run as a proof of concept to show the CPUs are defective, and then we can have a recall or free replacement of the CPU by AMD. I'll look into it myself - I need to ensure it's legal for me to write it from the country that I'm residing in right now. I personally have extensive experience hacking older AMD processors and GPUs through JTAG.
I'm sure it's still legal to provide a list of addresses and data writes that you need to perform to permanently brick the CPU?. I don't think that is classed as a "hacking tool". I can get t-shirts printed with it on, together with the words "AMD Ryzen CPU Self-Destruct Sequence". I don't think selling those would be illegal?
Of course the risk of targeted surveillance still exists, and nothing is going to stop a hidden camera from being placed in your home.
But in most cases there would be no reason to ever place the average person under such surveillance. So the bulk mass surveillance of the population would be hindered. And they won't be able to persecute people for reading or viewing certain things anymore. So that puts an end to the morality policing that has been enabled by the Internet.
And it doesn't have any of the privacy downsides that the Internet has. You can do anything you want with it, total freedom.
No more law enforcement or intelligence agencies being able to monitor your every move. So you could say it's way better even than the old Internet.
https://consolemods.org/wiki/Xbox_360:Disabling_the_eFuse_Bu... (see Method 2)
It was AMD with their PSP that pushed me into FPGAs and creating open source hardware, now that everything is getting locked down.
There's even worse possibilities, I think some hardware has ~1KB of executable OTP which can be programmed in that manner - so it may just be possible to implement some kind of backdoor that resides in the physical CPU. Maybe something only a state-level attacker could do.
For example, it could prevent CPU side-channel mitigations from ever working, somehow, e.g. by repeatedly writing to a private internal register to stealthily keep the CPU vulnerable. And few would ever know about it, because it's hidden in an on-chip security processor.
Personally I utterly hate all AMD chips which have a Platform Security Processor. Locking down your own property to prevent you from accessing it should be illegal.
There is a full Trustronic Trusted Execution Environment running in there, on both GPU and CPUs, I believe. For example the TEE firmware blob for a radeon GPU on Linux is "/lib/firmware/amdgpu/psp_13_0_7_sos.bin", with "sos" meaning Secure Operating System. And some of these firmware files are encrypted, so you can't reverse engineer them.
The moment some ARM SoC company such as Rockchip comes up with a chip that's within an order of magnitude in performance, then my AMD chip (EPYC) is going in the bin. After being smashed to pieces with a hammer, live on YouTube, with an explaination why. That might get AMD marketing to pay attention.
Update: Ampere Altra CPUs have seperate power pins for blowing eFuses, you can find it in the public datasheet here[1], on page 55, the supply pins are EFUSE_MFG_VDDQ1P8 and EFUSE_PCP_VDDQ1P8. It says tie to GND if unneeded.
Also they have a public datasheet for the chip. I wonder if we can buy unfused CPUs without secure boot enabled? Or is that the default state of the chip?
Could someone design a simple and cheap open-source motherboard for one of these processors, it's only a matter of time before the chips start turning up on Ebay? We will need more documentation from Ampere than just the datasheet, of course.
1. https://uawartifacts.blob.core.windows.net/upload-files/Altr...
In fact, hiring such people would be a step towards real diversity in the workplace, if we can find a way to fit them in somehow.
Or more subtly they could insert (or just not fix) a bug which allows packet descriptors to be overwritten on reception of a certain malformed WiFi packet, e.g. too short or long, which makes it possible to overwrite regions of the device's memory and thus compromise it. A SDR might be required to transmit the malformed packet(s).
By the way, I wonder if modern Realtek switch chips might still support RRCP, and an undocumented EEPROM bit or strapping resistor might re-enable it?
1. https://en.wikipedia.org/wiki/Realtek_Remote_Control_Protoco...
For the Bouffalo Lab and Beken WiFi SoCs we already have SVD files[1] for the WiFi MAC (and likely the PHY too). Thus we have nearly complete documentation for all chip registers and their bitfields. Both SoCs are based on CEVA RivieraWaves WiFi IP.
Also you might be able to use it as a SDR for the 2.4GHz band, there appears to be registers to send ADC data to on-chip SRAM. And USB 2.0 High Speed device functionality on some of the Bouffalo chips.
I was thinking of hacking it to use as a cheap uplink to the QO-100 amateur radio satellite, which uplinks in the 2.4GHz band. I think 100mW of power might be just enough for CW or some very narrowband PSK mode.
By the way, on the Bouffalo devices, watch out for the eFuse registers, they're not fully lockable and write protectable, one wrong register write and the whole chip itself can be bricked and stuck permanently in secure boot mode. It happened to me, and I'm going to try and work around it by glitching the clock input on boot, just at the right time, to disrupt the eFuse reading, just for the fun of it.
1. https://github.com/bouffalolab/bl_iot_sdk/blob/master/compon...