Source Link Privacy.
Tarlogic Security has detected a backdoor in the ESP32, a microcontroller that enables WiFi and Bluetooth connection and is present in millions of mass-market IoT devices. Exploitation of this backdoor would allow hostile actors to conduct impersonation attacks and permanently infect sensitive devices such as mobile phones, computers, smart locks or medical equipment by bypassing code audit controls.
Update: The ESP32 “backdoor” that wasn’t.
Obviously, but I trust my Linux mint laptop a hell of a lot better than my aunt’s XIPPLG branded wifi cat feeder that she bought off Amazon
You probably shouldn’t, check out Intel management engine and AMD secure technology.
From what I understand, the only way to mitigate the risks relating to IME or AMD PSP is to simply not have a computer in the first place. Like I’ve said elsewhere twice now, it’s worth mitigating some risks even if we can’t mitigate all of them, and given the fact that the entire internet hasn’t collapsed, I’m going to assume IME isn’t as big of a security vulnerability as it looks.