
"Europe is pouring more than €2 billion into sovereign cloud initiatives designed to reduce exposure to US legal reach. The EU's IPCEI-CIS program funds infrastructure development. France qualifies operators under SecNumCloud, a framework with nearly 1,200 technical requirements promising "immunity from extraterritorial laws.""
"But most datacenters and qualified cloud operators still rely heavily on Intel or AMD processors. And inside those processors sits a computer beneath the computer: management engines operating at Ring -3, below the operating system, outside the control of host security software, persistent even when the machine appears powered off. Under the US Reforming Intelligence and Securing America Act (RISAA) 2024, hardware manufacturers count as "electronic communications service providers" subject to secret government orders."
"That computer beneath the computer has a name. On Intel processors, it is the Management Engine (ME), or more precisely the Converged Security and Management Engine (CSME). On AMD, it is the Platform Security Processor (PSP). Both run at what security researchers call Ring -3, below the operating system, below the hypervisor, in a privilege level the host cannot see or log."
""It's a computer inside your computer," explains John Goodacre, Professor of Computer Architectures and former director of the UK's £200 million Digital Security by Design program. He is clear about what that means in practice. The ME has its own memory, its own clock, and its own network stack, and because it can share the host's MAC and IP addresses, any traffic it generates is indistinguishable from the host's own traffic to the firewall."
European sovereign cloud initiatives receive funding to reduce exposure to US legal reach, and certification frameworks set technical requirements for cloud operators. Many certified services still depend on Intel or AMD processors. Those processors include management engines running at Ring -3, below the operating system and hypervisor, outside host security software control. The management engines persist even when systems appear powered off. Under the US RISAA 2024, hardware manufacturers can be treated as electronic communications service providers subject to secret government orders. European frameworks certify cloud services but do not assess the silicon-level components that generate indistinguishable network traffic from the host.
#digital-sovereignty #sovereign-cloud #hardware-security #intelamd-management-engines #extraterritorial-legal-exposure
Read at theregister
Unable to calculate read time
Collection
[
|
...
]