Live data from Hacker News

How to become the sole owner of your PC [pdf]

github.com

111–120 of 126 posts

Re: How to become the sole owner of your PC [pdf]

#111
post #54
post #52

Earlier quoted context omitted.

Really??

Yeah, really. It's relatively well known among free software enthusiasts. The trouble is, what do you do about it?

On the phone side you would have to use Replicant, which sandboxes the modem.

http://www.replicant.us/

Problem is the project is mostly dead. Nothing in from the last four years is supported, and its stuck on Android 4.2.

Re: How to become the sole owner of your PC [pdf]

#112
post #61

Earlier quoted context omitted.

AMT is the reason I mock anyone here that talks about concerns of backdoors in Intel's RNG's being ridiculous. The whole CPU is backdoored with a backdoor that can run when it's off . Including probably the RNG given debug wires are probably connected to it. Let's not worry about one feature when we have a subversion this big. Biggest irony: they advertise it as a feature for IT management. ;)

I'd argue that a factory backdoored RNG would be infinitely more dangerous. An AMT exploit wouldn't be passive, and it wouldn't weaken every crypto operation proceeding the time of the attack. Between the two, which do you think an entity with a massive surveillance network, and a history of intentionally weakening security infrastructure, would prefer?

An AMT exploit, if having internal access to CPU, could weaken a RNG plus anything else you can think of. Passive attacks are definitely possible with a backdoor. It just makes a component, hardware or software, do something upon certain trigger conditions. Otherwise it stays silent. Example from high-assurance field:

https://calhoun.nps.edu/bitstream/handle/10945/6073/02Mar_An...

Re: How to become the sole owner of your PC [pdf]

#113

Earlier quoted context omitted.

AMT is the reason I mock anyone here that talks about concerns of backdoors in Intel's RNG's being ridiculous. The whole CPU is backdoored with a backdoor that can run when it's off . Including probably the RNG given debug wires are probably connected to it. Let's not worry about one feature when we have a subversion this big. Biggest irony: they advertise it as a feature for IT management. ;)

My team spent a bunch of time looking at AMT as a management tool -- it adds lots of complexity and accomplishes almost nothing that cannot be done easier a half dozen other ways. The only functionality we saw any real use for was an always on VPN and remote wake up where networks block WoL. The other thing that's even stranger is Absolute Software, a little company nobody has ever heard of who somehow got every OEM…

re Absolute

It seriously reads like a botnet description. I'd have believed them if they said "From the innovators behind Storm comes new endpoint protection..."

https://www.absolute.com/en/about/persistence

Re: How to become the sole owner of your PC [pdf]

#114
post #38

So ... is my macbook or Dell server pre-pwned by Intel and re-pwned by the Chinese? What, exactly, am I supposed to be afraid of here?

Nothing, as long as you have nothing to hide. :-)

https://en.wikipedia.org/wiki/Nothing_to_hide_argument

Re: How to become the sole owner of your PC [pdf]

#115
post #61

Earlier quoted context omitted.

I'd argue that a factory backdoored RNG would be infinitely more dangerous. An AMT exploit wouldn't be passive, and it wouldn't weaken every crypto operation proceeding the time of the attack. Between the two, which do you think an entity with a massive surveillance network, and a history of intentionally weakening security infrastructure, would prefer?

An AMT exploit, if having internal access to CPU, could weaken a RNG plus anything else you can think of. Passive attacks are definitely possible with a backdoor. It just makes a component, hardware or software, do something upon certain trigger conditions. Otherwise it stays silent. Example from high-assurance field: https://calhoun.nps.edu/bitstream/handle/10945/6073/02Mar_An...

I think woodmans argument is that AMT is an active service, you should see network traffic to the management engine and such -- so firewalls/airgaps/SPI should detect and prevent tampering. I think that is a naive view of AMT, it seems far more capable, network management is just one avenue (and it's been proven difficult to comprehensively implement anyways).

Re: How to become the sole owner of your PC [pdf]

#116
post #115

Earlier quoted context omitted.

An AMT exploit, if having internal access to CPU, could weaken a RNG plus anything else you can think of. Passive attacks are definitely possible with a backdoor. It just makes a component, hardware or software, do something upon certain trigger conditions. Otherwise it stays silent. Example from high-assurance field: https://calhoun.nps.edu/bitstream/handle/10945/6073/02Mar_An...

I think woodmans argument is that AMT is an active service, you should see network traffic to the management engine and such -- so firewalls/airgaps/SPI should detect and prevent tampering. I think that is a naive view of AMT, it seems far more capable, network management is just one avenue (and it's been proven difficult to comprehensively implement anyways).

Ahh. I think the hardware parts of my write-up on smartphone risks will help here:

https://news.ycombinator.com/item?id=10906999

Basically, modern SOC's are mixed-signal systems that have digital, analog, and often RF capabilities. I've imagined, with limited HW knowledge, quite a few attacks on digital subsystems using analog or RF components. HW gurus I know encounter sneaky stuff like that in 3rd party I.P. regularly and have to mitigate it. Most people have no clue it exists. They're mitigating at the networking channel which is a mere abstraction for more complex stuff going on in chip and interface point. You could even embed a radio in the sucker that turned on when it detected a certain signal in a packet header that NIDS certainly wasn't analyzing.

Note that NSA TAO catalog includes active attacks with radars that rely on physical materials in counterfeit parts and SOC's with embedded radios hidden in USB connectors. Quite a few attacks at SOC level software people will never see coming.

Re: How to become the sole owner of your PC [pdf]

#117
post #64

Earlier quoted context omitted.

> they really intended it to be a backdoor-ish sort of thing Occam's razor says they really just sell a ton of CPUs to huge datacenters and wanted to solve the problem of having to have some tech go out and physically reset a machine when it misbehaves. If you've ever accidentally powered down a machine that's sitting in some lights-out facility in Northern Alabraska, this kind of technology is a godsend. Now I'm not…

> If you've ever accidentally powered down a machine, ... this kind of technology is a godsend. How do I use this technology to, say, boot my turned off but plugged in and network-connected laptop? I mean in a legitimate way. I'd really love to see how this works (and then be horrified).

Search Google for AMT tools. You will find what you are looking for. AMT will need to be turned on from the BIOS though

Re: How to become the sole owner of your PC [pdf]

#118

Earlier quoted context omitted.

My team spent a bunch of time looking at AMT as a management tool -- it adds lots of complexity and accomplishes almost nothing that cannot be done easier a half dozen other ways. The only functionality we saw any real use for was an always on VPN and remote wake up where networks block WoL. The other thing that's even stranger is Absolute Software, a little company nobody has ever heard of who somehow got every OEM…

re Absolute It seriously reads like a botnet description. I'd have believed them if they said "From the innovators behind Storm comes new endpoint protection..." https://www.absolute.com/en/about/persistence

Glad to see my laptop vendor is not on their list

Re: How to become the sole owner of your PC [pdf]

#119
post #74
post #71

Earlier quoted context omitted.

Buy a Libreboot T400? It comes without Intel ME and is FSF-certified: https://minifree.org/product/libreboot-t400/ It is pretty expensive for the amount of performance you get, but you are getting a fully documented, auditable and free product. It comes with instructions on how to update/build/flash/modify your firmware. You're also supporting the Libreboot project.

Wow, thanks for introducing me to this. Been wanting a new laptop for coding and writing and I would be 100% behind something of that nature. Have you had the chance of using it?

I haven't yet, but mine is underway.

The model I got has 8gb ram, 240gb SSD, 1tb HDD, Core2Duo processor, and is upgradeable to a Core2Quad.

However, I'm strongly considering just keeping it as a backup. To me it represents the best possible backup computer, durable and auditable.

It's backup for when my current computer breaks down, but also for when new sinister surveillance and encryption laws are passed. Or for when the web turns into even more of a wild-west with hackers and nation-states doing whatever they feel like.

I kinda feel like it was a bad idea to even discuss my ordering of this on a non-throwaway, from an IP vaguely linked to me.

.

That went kinda dark. Guess I haven't been taking enough Soma.

Re: How to become the sole owner of your PC [pdf]

#120
post #61

Earlier quoted context omitted.

I'd argue that a factory backdoored RNG would be infinitely more dangerous. An AMT exploit wouldn't be passive, and it wouldn't weaken every crypto operation proceeding the time of the attack. Between the two, which do you think an entity with a massive surveillance network, and a history of intentionally weakening security infrastructure, would prefer?

An AMT exploit, if having internal access to CPU, could weaken a RNG plus anything else you can think of. Passive attacks are definitely possible with a backdoor. It just makes a component, hardware or software, do something upon certain trigger conditions. Otherwise it stays silent. Example from high-assurance field: https://calhoun.nps.edu/bitstream/handle/10945/6073/02Mar_An...

I'm not saying that AMT is no big deal, I'm saying that an intentionally weakened RNG is pretty much the worst thing ever. All crypto prior to targeting would be vulnerable: tor, bitcoin, pgp - for every machine leaving the factory with an Intel chip hosting badRNG v0.89 (depending on OS utilization).
Post reply on HN