Hacker News (curated)new | past | comments | ask | show | jobs| show hidden

The founder Joanna Rutkowska left QubesOS in 2018. All the code involved in this bug was committed by her successor Marek Marczykowski-Górecki.

Joanna seems to be a genuine good guy, she once wrote a paper titled "Intel x86 considered harmful". That's why Huawei and the Chinese government aren't even trying any more to make western CPU architectures secure, it's a hopeless cause.



Is there some evidence that x86 is uniquely prone to exploitable memory corruption? I haven't seen it, if so.

> That's why Huawei and the Chinese government aren't even trying any more to make western CPU architectures secure, it's a hopeless cause.

I suspect there are much more boring reasons for this, ranging from licensing to geopolitics (i.e., it being useful/valuable to have a domestic base of engineers who can design an ISA).


The paper X86 considered harmful was about how the BIOS / Intel management Engine (now also AMD PSP), are completely opaque.

If the lowest layer is hidden, proprietary, there are infinite vectors for state actors to include their desired backdoors.


My understanding is that IME and PSP come more from the world of corporate compliance than anything else. In other words they exist for x86 because x86 gets deployed in corporate settings, and any ISA that attempts to occupy a similar niche will meet a similar fate.

(Compare ARM’s TrustZone, etc.)


> good guy,

> she




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact | github