this post was submitted on 08 Mar 2025
964 points (93.3% liked)
Technology
64936 readers
3962 users here now
This is a most excellent place for technology news and articles.
Our Rules
- Follow the lemmy.world rules.
- Only tech related content.
- Be excellent to each other!
- Mod approved content bots can post up to 10 articles per day.
- Threads asking for personal tech support may be deleted.
- Politics threads may be removed.
- No memes allowed as posts, OK to post as comments.
- Only approved bots from the list below, this includes using AI responses and summaries. To ask if your bot can be added please contact a mod.
- Check for duplicates before posting, duplicates may be removed
- Accounts 7 days and younger will have their posts automatically removed.
Approved Bots
founded 2 years ago
MODERATORS
you are viewing a single comment's thread
view the rest of the comments
view the rest of the comments
Not the first time a backdoor was found on Chinese made hardware and it won‘t be the last time. Decoupling can‘t happen quickly enough.
Which government's backdoors would you prefer?
"We know you have a choice in oppressive governments, so we appreciate you choosing ours."
None of them, that's why the only things in my house that connect to the internet are my computers, game consoles, and cell phone
Assuming you're not joking here, if your computers are any way modern they almost certainly have a backdoor.
Obviously, but I trust my Linux mint laptop a hell of a lot better than my aunt's XIPPLG branded wifi cat feeder that she bought off Amazon
You probably shouldn't, check out Intel management engine and AMD secure technology.
From what I understand, the only way to mitigate the risks relating to IME or AMD PSP is to simply not have a computer in the first place. Like I've said elsewhere twice now, it's worth mitigating some risks even if we can't mitigate all of them. I don't want the most advanced computing device in my home to be an astrolabe.
I don't think Lemmy shitposters are getting them premium zero days used on them.
This isn't some crazy zero day, it's pretty well known. Intel management engine and AMD secure technology.
Not sure if joking or naive...
Like I said 6 hours ago, just because I can't mitigate all of the risk doesn't mean that I shouldn't mitigate as much as I reasonably can.
My 3d printer is a fire hazard, but that's no excuse for leaving a bunch of candles unattended.
Ah I missed the other comment, my client still had a cached view apparently. And definitely true regarding mitigation, your phrasing just read funny to me :)
I guarantee all off those have components from manufacturers that a government could pressure for a backdoor.
You are correct, and it doesn't change my stance at all. It's still worth it to mitigate risk even if you can't mitigate all risk.
Like, the fact that my 3d printer is already a fire hazard does not justify leaving a bunch of candles unattended
True, but the ESP32 is used by a lot of devices. This backdoor is pretty huge in scope of devices impacted.
It depends on what the method of attack is. I'm not seeing anything saying that it would be possible to exploit wirelessly, so this could easily be mostly a non-issue.
I mean, most users here are browsing using a device with an AMD or Intel CPU, both with known backdoors. Not the first time a backdoor was found on American made hardware and it won't be the last.