What I’ve read just now is what I’d deliberately not gone looking for up to this point in case I found this out.
Linux and Windows happen to require that the executables that access that information be run with root privileges, but it looks like that’s merely an affectation.
It seems that any old piece of software, without root or other privileges, can independently run the CPUID instruction that obtains a processor’s serial number.
Are you a believer in the idea “They who have nothing to hide have nothing to fear”? Hint: You shouldn’t be.
And do you know for certain that your sandboxes and VMs don’t simply pass through the CPUID instruction? And if they don’t, do they rotate their fake CPUIDs? And how often does that happen?
What I’ve read just now is what I’d deliberately not gone looking for up to this point in case I found this out.
Linux and Windows happen to require that the executables that access that information be run with root privileges, but it looks like that’s merely an affectation.
It seems that any old piece of software, without root or other privileges, can independently run the CPUID instruction that obtains a processor’s serial number.
I do not like this one bit.
Why not? Is that information considered sensitive? Personally I tend to avoid running untrustworthy programs outside of a sandbox or VM.
Are you a believer in the idea “They who have nothing to hide have nothing to fear”? Hint: You shouldn’t be.
And do you know for certain that your sandboxes and VMs don’t simply pass through the CPUID instruction? And if they don’t, do they rotate their fake CPUIDs? And how often does that happen?