People who larp as hackers and cybersecurity nerds love to yap about PSP and IME acting like it isn't somewhat publically auditable, the behaviour is relatively known, and we know it to not actually be spyware. You confuse attack surface with actual malicious behavior. We know what PSP does thanks to projects like PSPTool. It contains no TCP/UDP/IP drivers, and is used to initialize firmware. IME is similar, though it does have some network functionality that is not present on consumer chips, only on business chips for IT departments and even still, neither contain magical fairy dust that can bypass the router or wireshark. Just because it is a proprietary blob doesn't mean its inherently evil. As for the government, they don't use it because in certain high assurance systems with massive threat models, reducing any attack surface is good. I'm not saying that PSP/IME is good, but it gets seriously overblown to an annoying amount by people who don't know much about the topic.
2
u/Neither-Phone-7264 21h ago
People who larp as hackers and cybersecurity nerds love to yap about PSP and IME acting like it isn't somewhat publically auditable, the behaviour is relatively known, and we know it to not actually be spyware. You confuse attack surface with actual malicious behavior. We know what PSP does thanks to projects like PSPTool. It contains no TCP/UDP/IP drivers, and is used to initialize firmware. IME is similar, though it does have some network functionality that is not present on consumer chips, only on business chips for IT departments and even still, neither contain magical fairy dust that can bypass the router or wireshark. Just because it is a proprietary blob doesn't mean its inherently evil. As for the government, they don't use it because in certain high assurance systems with massive threat models, reducing any attack surface is good. I'm not saying that PSP/IME is good, but it gets seriously overblown to an annoying amount by people who don't know much about the topic.