Live data from Hacker News

The Intel ME subsystem can take over your machine, can't be audited

boingboing.net

141–150 of 282 posts

Re: The Intel ME subsystem can take over your machine, can't be audited

#141
post #119
post #109

Earlier quoted context omitted.

>1) Intel has such technology implemented in allmost all desktops/servers currently running Ever wondered why Google is working on their own CPU?

Wondering - when that happens - if their firmware is open source but monitored for ad targeting should we be OK with it?

Freedom 1 of the FSF is (https://www.gnu.org/philosophy/free-sw.html):

"The freedom to study how the program works, and change it so it does your computing as you wish"

In this sense you should be able to change the firmware (since it is open source in the sense of the OSI definition) and remove the monitoring for ad targeting. If this is not possible, Google's firmware is not open source (see https://opensource.org/osd).

Re: The Intel ME subsystem can take over your machine, can't be audited

#142

It may be, that Intel didn't plan this as an NSA/XYZ back door - but it doesn't actually matter. What matters is that we know 1) Intel has such technology implemented in allmost all desktops/servers currently running 2) you can access those machines remotely (even over GSM) and perform reads/writes. Example misuse: somebody can put illegal stuff on your machine and then sue you... (Intel has marketed this feature for…

>> you can access those machines remotely (even over GSM) Is this really true? All modern Intel chips come with embedded mobile phone tech to allow remote access? Sources on this?

One example source: http://www.intel.com/content/dam/doc/product-brief/mobile-co...

I guess they don't (yet) have embedded mobile phone tech. I guess they use wireless cellular modem integrated in many laptops.

EDIT: Here the relevant part from link above: "Notification via an encrypted SMS text message over a 3G network. For this option, the laptop does not need to be connected to the Internet. This feature works even if the OS in not running or has been reinstalled, thanks to a hardware-to-hardware link between the 3G card and the Intel AT system."

Re: The Intel ME subsystem can take over your machine, can't be audited

#143
post #42
post #14

Why can't Intel implement proper security and open up this blob to begin with? Not opening it and not allowing to disable it, suggests it's intended for something sinister.

As stated in the article, some researchers have managed to unpack it, and it can now be dissembled. You can't (and hpefully won't) be able to execute your own code there. There are 2 good reasons for this: 1) As per the article, to actually prevent ring -3 malware. The implemented signature is the best way to do this. If we could run our own "libre" code there, so could the attacker. 2) I bet this firmware controlls…

Of course you can execute your own code, you just send a National Security Letter to Intel; or did you mean "you can't execute your own code unless you're the NSA"?

Re: The Intel ME subsystem can take over your machine, can't be audited

#144
post #88

Nice breakdown of how ME works, but nothing new here. Still, I'm glad I hold on to a ton of older, pre Core i-series Intel machines, AMD machines, and ARM boards. If ME is ever truly compromised at least I have a fallback or three.

You use three different platforms and every have backdoors in it.

Name one that doesn't. Sorry, name a modern, useful hardware platform that is 100% guaranteed not to have a backdoor or vulnerability of some sort.

It's about mitigating threats, because it's impossible to do more than that today. If you don't design and build the hardware yourself from the board and chips on up, it's not guaranteed to be safe. Even then, without being tested by the masses, you're bound to accidentally design a weakness in your system that you won't discover until you've been compromised.

So yes, I'm happy that I have older platforms with known, documented, manageable vulnerabilities to fall back on should ME's mysterious, undocumented vulnerabilities become compromised by a bad actor.

Re: The Intel ME subsystem can take over your machine, can't be audited

#145
post #42
post #14

Why can't Intel implement proper security and open up this blob to begin with? Not opening it and not allowing to disable it, suggests it's intended for something sinister.

As stated in the article, some researchers have managed to unpack it, and it can now be dissembled. You can't (and hpefully won't) be able to execute your own code there. There are 2 good reasons for this: 1) As per the article, to actually prevent ring -3 malware. The implemented signature is the best way to do this. If we could run our own "libre" code there, so could the attacker. 2) I bet this firmware controlls…

IME is on the motherboard chipset, not the CPU. The i3 vs i5 is controlled by fuses set at manufacturing time on the CPU itself.

Re: The Intel ME subsystem can take over your machine, can't be audited

#146

I'm very surprised that no-one on HN has talked about their experiences of using AMT for enterprise IT management. Aside from the security problems, I've personally never encountered or seen it's use, which makes the ME's inclusion (on all chips, for about 6 years) seem like an odd decision from Intel.

> I've personally never encountered or seen it's use, which makes the ME's inclusion (on all chips, for about 6 years) seem like an odd decision from Intel.

I consider it as quite plausible that the reason why Intel included ME into all chips is that it is much cheaper to add those unnecessary gates to any chip than to create two different versions of it. The much more interesting question is why ME cannot be disabled. It is clear (see http://www.intel.com/content/dam/doc/product-brief/mobile-co...) why Intel has a reason why ME should not be possible to disable on some chips. I can imagine that Intel fears that if it can be disabled on some chips, hackers will find a backdoor to also disable it on those chips where it shouldn't be possible.

Re: The Intel ME subsystem can take over your machine, can't be audited

#147
post #42

Earlier quoted context omitted.

As stated in the article, some researchers have managed to unpack it, and it can now be dissembled. You can't (and hpefully won't) be able to execute your own code there. There are 2 good reasons for this: 1) As per the article, to actually prevent ring -3 malware. The implemented signature is the best way to do this. If we could run our own "libre" code there, so could the attacker. 2) I bet this firmware controlls…

> As per the article, to actually prevent ring -3 malware. The implemented signature is the best way to do this. If we could run our own "libre" code there, so could the attacker. That's completely false; allowing the execution of libre software doesn't worsen security, and the security-by-obscurity model doesn't improve it.

> allowing the execution of libre software doesn't worsen security

It does if I get temporary physical access to your machine and flash something that can spy on you, or if the method of flashing it can be done via your OS and I hack that. Those are two HUGE flaws.

Re: The Intel ME subsystem can take over your machine, can't be audited

#148
I wish the European Commission study this problem and if found guilty impose a fine in such a way and quantity that in no way those firms can continue exposing their clients to possible economic damage.

The previous imposed fine was of EUR 1.06 billion.

Someone with the required knowledge should submit a detailed record of this potential hazard to the European Commission emphasizing how this system could expose clients to possible threats, its anticompetitive nature, since it could allow hackers gain access to economic secrets, and many other important points.

The FSF should stand up and speak clearly. I hope and wish that the FSF execute its mission, that is to gain and gather the necessary strength to expose the nature and extend of these problems and how to fight against them.

Those that impose on us tools that allow them to control our business, steal our ideas and plans, and ruin our enterprises plaguing with chaos. Those that thrive to submit our future to their will should be fined.

I certainly hope that a new economic fine be imposed. That initiative and measure would set up a strong message and a new precedent targeted to those threating our liberty and economy. A message encoded into an economic hammer with the power to make them shape their will to respect our freedom and integrity.

To be Free and Survive we should Fight. FSF.

Re: The Intel ME subsystem can take over your machine, can't be audited

#149

And this is why monopoly of one giant monolith is bad, in any area or case! They get to the whatever the f they want! It's not like everything is made today to track, and give access to "authorities" when they want it. But what really drives me mad is that I feel tricked! You put trust into someone and it's work, and give them money for that, but they do this, without you even knowing. I was always making fun of swor…

I think AMD and ARM have similar features though. ARM with TrustZone for example, hiding the "secure world" from knowledge by the "normal world".

Re: The Intel ME subsystem can take over your machine, can't be audited

#150
post #80

Earlier quoted context omitted.

Except libreboot doesn't help. ME executes below BIOS/UEFI.

Wrong. On some machines, such as the X200, you can actually remove and disable the ME with coreboot/libreboot.

Interesting, I understood that wrong then. But granted, I was researching it for the x220 and it was a while ago. Thanks for the hint.
Post reply on HN