Live data from Hacker News

The Intel ME subsystem can take over your machine, can't be audited

boingboing.net

51–60 of 282 posts

Re: The Intel ME subsystem can take over your machine, can't be audited

#51
post #42

Earlier quoted context omitted.

As stated in the article, some researchers have managed to unpack it, and it can now be dissembled. You can't (and hpefully won't) be able to execute your own code there. There are 2 good reasons for this: 1) As per the article, to actually prevent ring -3 malware. The implemented signature is the best way to do this. If we could run our own "libre" code there, so could the attacker. 2) I bet this firmware controlls…

> As per the article, to actually prevent ring -3 malware. The implemented signature is the best way to do this. If we could run our own "libre" code there, so could the attacker. That's completely false; allowing the execution of libre software doesn't worsen security, and the security-by-obscurity model doesn't improve it.

Codesigning is "security-by-obscurity" now?

Re: The Intel ME subsystem can take over your machine, can't be audited

#52

I find people freaking out about this extremely strange. AMT is Intel's equivalent of IPMI. It is a non-standard implementation of it, and does not follow any of the relevant specifications. It does not integrate into most server management platforms. AMT costs extra. Most mobos do not have it enabled as you have to pay Intel's tax on it, even if some of the hardware to enable it is in every northbridge. A motherboar…

[deleted]

Re: The Intel ME subsystem can take over your machine, can't be audited

#53

Earlier quoted context omitted.

> As per the article, to actually prevent ring -3 malware. The implemented signature is the best way to do this. If we could run our own "libre" code there, so could the attacker. That's completely false; allowing the execution of libre software doesn't worsen security, and the security-by-obscurity model doesn't improve it.

Codesigning is "security-by-obscurity" now?

No, not that, the rest of it. I meant the fact that it's a binary blob which hasn't (recently) been subject to review by users.

Re: The Intel ME subsystem can take over your machine, can't be audited

#54

I find people freaking out about this extremely strange. AMT is Intel's equivalent of IPMI. It is a non-standard implementation of it, and does not follow any of the relevant specifications. It does not integrate into most server management platforms. AMT costs extra. Most mobos do not have it enabled as you have to pay Intel's tax on it, even if some of the hardware to enable it is in every northbridge. A motherboar…

Expressing a concern and "freaking out" are wholly different beasts. Most people are doing the former, but you're painting everyone with the latter brush. That's both rhetorically dishonest, and just plain uncool.

Re: The Intel ME subsystem can take over your machine, can't be audited

#55
post #42
post #14

Why can't Intel implement proper security and open up this blob to begin with? Not opening it and not allowing to disable it, suggests it's intended for something sinister.

As stated in the article, some researchers have managed to unpack it, and it can now be dissembled. You can't (and hpefully won't) be able to execute your own code there. There are 2 good reasons for this: 1) As per the article, to actually prevent ring -3 malware. The implemented signature is the best way to do this. If we could run our own "libre" code there, so could the attacker. 2) I bet this firmware controlls…

> 1) As per the article, to actually prevent ring -3 malware. The implemented signature is the best way to do this. If we could run our own "libre" code there, so could the attacker.

Why can't computers have physical switches that enable/disable writing the memory that this piece of software is located in?

Re: The Intel ME subsystem can take over your machine, can't be audited

#56
post #19

Taking another angle: What if the computer's owner wants to use it to access her computer remotely? Are there some instructions how to do this? Is it feasible? If not, then there seems little justification to have a relatively new feature like this turned on by default. Who is this feature really for? If it's not for all users then why is activation mandatory in CPUs after Core2? I mean, if ME has to be active, then…

I think it is intended for enterprises to enable.

It is intended for the "Intel defined enterprises" to be more precise. Ordinary Joe cannot declare him/her to be an enterprise and do so, unless he/she is willing to pay the Intel "thugs" an inordinate amount upfront.

Re: The Intel ME subsystem can take over your machine, can't be audited

#57
post #55
post #42

Earlier quoted context omitted.

As stated in the article, some researchers have managed to unpack it, and it can now be dissembled. You can't (and hpefully won't) be able to execute your own code there. There are 2 good reasons for this: 1) As per the article, to actually prevent ring -3 malware. The implemented signature is the best way to do this. If we could run our own "libre" code there, so could the attacker. 2) I bet this firmware controlls…

> 1) As per the article, to actually prevent ring -3 malware. The implemented signature is the best way to do this. If we could run our own "libre" code there, so could the attacker. Why can't computers have physical switches that enable/disable writing the memory that this piece of software is located in?

Good question. Why don't phones have physical switches on GPS and microphones?

In this case, the RSA sig is still better, though. Imagine that anyone sitting between the Intel plant and your local computer parts supplier could flip the switch.

It's a weak argument, I admit. There should be both protections at the same time.

Re: The Intel ME subsystem can take over your machine, can't be audited

#58

Taking another angle: What if the computer's owner wants to use it to access her computer remotely? Are there some instructions how to do this? Is it feasible? If not, then there seems little justification to have a relatively new feature like this turned on by default. Who is this feature really for? If it's not for all users then why is activation mandatory in CPUs after Core2? I mean, if ME has to be active, then…

It's marketed as Intel vPro. Pricing is probably typical enterprise level. This page has more details: http://www.intel.com/content/www/us/en/architecture-and-tech...

Re: The Intel ME subsystem can take over your machine, can't be audited

#59
post #42
post #14

Why can't Intel implement proper security and open up this blob to begin with? Not opening it and not allowing to disable it, suggests it's intended for something sinister.

As stated in the article, some researchers have managed to unpack it, and it can now be dissembled. You can't (and hpefully won't) be able to execute your own code there. There are 2 good reasons for this: 1) As per the article, to actually prevent ring -3 malware. The implemented signature is the best way to do this. If we could run our own "libre" code there, so could the attacker. 2) I bet this firmware controlls…

> As per the article, to actually prevent ring -3 malware. The implemented signature is the best way to do this.

No. If the thing has no persistent storage in it then just removing power from the machine would remove any such malware, and if it does have storage then it should have a "reset to factory" jumper somewhere that has the same effect.

There is no excuse for not letting the machine's owner replace any code on the machine.

Re: The Intel ME subsystem can take over your machine, can't be audited

#60
Very naively, I wonder what happens if you just call Intel and complain about this. Say you want a way to remove the ME completely. They won't help you, but I wonder how they will justify making it compulsory if pressed.

Now if I call them, I wouldn't reach anybody important. But surely there are a couple of people on HN who are lawyers, CEOs, with the government etc.? If you have an imposing job and a few minutes to spare, I'd like to see what Intel has to say about this.

Post reply on HN