Live data from Hacker News

The Intel ME subsystem can take over your machine, can't be audited

boingboing.net

21–30 of 282 posts

Re: The Intel ME subsystem can take over your machine, can't be audited

#21
post #18

Does this apply to Macs?

Not sure. ME requires coordination/support from other electronic components to do its job. It only applies to Macs if Apple's motherboards have the necessary circuitry (I couldn't find this info so far).

The actual ME is in the chipset itself, though it is true that full AMT functionality may require additional hardware.

Re: The Intel ME subsystem can take over your machine, can't be audited

#22

No doubt various three-letter agencies are having a field-day with this right now. Hopefully a robin-hood type will reverse-engineer the blob and post a permanent fix to disable this thing before a more nefarious person/group uses it to devastate the PC landscape with something even worse than bitlocker.

It's impossible to "reverse-engineer" a cryptographic signature. Properly implemented (and you can bet that Intel has had time to finalize this) it's computationally insurmountable.

Re: The Intel ME subsystem can take over your machine, can't be audited

#23

Nice breakdown of how ME works, but nothing new here. Still, I'm glad I hold on to a ton of older, pre Core i-series Intel machines, AMD machines, and ARM boards. If ME is ever truly compromised at least I have a fallback or three.

When people realize that it has been "truly compromised" it will be too late. The whole thing is a huge mess from a security stand-point.

Re: The Intel ME subsystem can take over your machine, can't be audited

#24
post #21
post #18

Earlier quoted context omitted.

Not sure. ME requires coordination/support from other electronic components to do its job. It only applies to Macs if Apple's motherboards have the necessary circuitry (I couldn't find this info so far).

The actual ME is in the chipset itself, though it is true that full AMT functionality may require additional hardware.

Do we know if Apple uses the whole, standard Intel chipset or just the cpu + custom, Intel supplied chipset?

Re: The Intel ME subsystem can take over your machine, can't be audited

#25
post #24
post #21

Earlier quoted context omitted.

The actual ME is in the chipset itself, though it is true that full AMT functionality may require additional hardware.

Do we know if Apple uses the whole, standard Intel chipset or just the cpu + custom, Intel supplied chipset?

I think most of the time they use standard Intel chipsets, though there are exceptions.

Re: The Intel ME subsystem can take over your machine, can't be audited

#26

No doubt various three-letter agencies are having a field-day with this right now. Hopefully a robin-hood type will reverse-engineer the blob and post a permanent fix to disable this thing before a more nefarious person/group uses it to devastate the PC landscape with something even worse than bitlocker.

It also reminds me of this: http://www.nytimes.com/2016/02/18/business/dealbook/china-fa...

Re: The Intel ME subsystem can take over your machine, can't be audited

#27
post #16

Thats crazy talk, in what world is it ok for my cpu to run a tcp stack on its own?

It is in the chipset not in the CPU.

Maybe I'm missing something, is this chipset on the motherboard? The article makes it seem like its coupled with the cpu.

Re: The Intel ME subsystem can take over your machine, can't be audited

#30
I still don't understand why this ME feature has been created to begin with. Assuming that breaking it is a matter of time (someone clever enough thinking about it for long enough), it seems like a serious security vulnerability, worse still because an attack is undetectable.

Why create it in the first place? Are the enterprise uses the article mentions worth the risk?

Post reply on HN