Live data from Hacker News

The Intel ME subsystem can take over your machine, can't be audited

boingboing.net

171–180 of 282 posts

Re: The Intel ME subsystem can take over your machine, can't be audited

#171
post #149

And this is why monopoly of one giant monolith is bad, in any area or case! They get to the whatever the f they want! It's not like everything is made today to track, and give access to "authorities" when they want it. But what really drives me mad is that I feel tricked! You put trust into someone and it's work, and give them money for that, but they do this, without you even knowing. I was always making fun of swor…

I think AMD and ARM have similar features though. ARM with TrustZone for example, hiding the "secure world" from knowledge by the "normal world".

Trustzone is different, although it can be used to wall things off from the user (and their viruses) it's more of a secure hypervisor, or way of constructing a TPM-equivalent that shares chip resources.

If you have control over the boot process on an ARM chip, you don't have to enable Trustzone.

Re: The Intel ME subsystem can take over your machine, can't be audited

#172
post #127

Very naively, I wonder what happens if you just call Intel and complain about this. Say you want a way to remove the ME completely. They won't help you, but I wonder how they will justify making it compulsory if pressed. Now if I call them, I wouldn't reach anybody important. But surely there are a couple of people on HN who are lawyers, CEOs, with the government etc.? If you have an imposing job and a few minutes to…

There are plenty of reasons why this is useful. See slides 7 and 8 from http://www.slideshare.net/codeblue_jp/igor-skochinsky-enpub If this functionality is a good trade-off is a different question.

Non-enterprise customers need not any of those. Hence they should be allowed to turn ME off if they wish so. That ME thing actually mean i don't have full control of my computer anymore. Anybody can access my hardware even when its turned off. Scary sh*t.

Re: The Intel ME subsystem can take over your machine, can't be audited

#173

Earlier quoted context omitted.

NICs exist, occasionally: Atheros Wifi chips work with open-source firmwares. And it shouldn't be too hard to find a GBit ethernet NIC without. Everything else is a lost cause right now. Keyboards, mice, displays, … Everything is running proprietary firmware blobs.

And it shouldn't be too hard to find a GBit ethernet NIC without. I think just about every cheap, "value" (i.e. no advanced features) NIC qualifies; the Realtek ones come to mind.

Actually, since you mention Realtek, some of their gigabit NICs do take some firmware. I have a vague notion that it's not needed for the basic functionality of sending and receiving packets, but I might be wrong - it's been a few years since I dealt with it.

Re: The Intel ME subsystem can take over your machine, can't be audited

#176
post #97

Strange that Intel gives people more reason to go to other processors like ARM when Intel is under such pressure from competition.

Who does this give reason to move to ARM? End-users generally don't have a choice (good luck running AutoCAD on ARM) and OEMs either don't seem to care or list ME as one of the selling points of their systems. You could make the case that this might convince people to use AMD CPUs, but from what I hear AMD has all the same issues with worse performance to boot.

I am pretty sure you can run VirtualBox on Linux. And you can run Linux on ARM.

Re: The Intel ME subsystem can take over your machine, can't be audited

#177

Maybe I missed it in the article, but why is this only present on x86 chips? How do 64-bit processors from Intel offer the same management functionality without this ME subsystem?

Except for the Itanic (is this thing still made?), 64-bit processors from Intel are x86 ;)

It's common to apply this label to x86-64 too, in other words.

Re: The Intel ME subsystem can take over your machine, can't be audited

#178
post #129

Earlier quoted context omitted.

NICs exist, occasionally: Atheros Wifi chips work with open-source firmwares. And it shouldn't be too hard to find a GBit ethernet NIC without. Everything else is a lost cause right now. Keyboards, mice, displays, … Everything is running proprietary firmware blobs.

> Atheros Wifi chips work with open-source firmwares. Interesting. Isn't such firmware able to initiate unlawful transmissions? How are they going to deal with this new FCC goodness?

Funnily, the FCC requirement is incompatible with the EU laws.

The EU laws say that while a normal user shouldn’t be able to make unlawful transmissions, the manufacturer may NOT prevent the customer from installing alternative software (like openwrt) just to fulfil the first requirement.

Basically, to conform with EU law, you have to violate US law, and the other way round.

Re: The Intel ME subsystem can take over your machine, can't be audited

#179

Maybe I missed it in the article, but why is this only present on x86 chips? How do 64-bit processors from Intel offer the same management functionality without this ME subsystem?

In this case x86 means both 32bit x86 (also referred as IA-32) and x86_64.

From https://en.wikipedia.org/wiki/Intel_Active_Management_Techno...

  "The Management Engine (ME) is an isolated and protected coprocessor, embedded as a non-optional part in all current (as of 2015) Intel chipsets."

Re: The Intel ME subsystem can take over your machine, can't be audited

#180
Oh my god it began with the oems installing a bunch of spyware on the default install. Many of which with vulnerabilities. Not to mention "modern" OSes not respecting users privacy. To make matters worse the hardware companies decided to follow suit and thus added unwanted and compromising features to everyday systems. Way to go! It seems I'll have to switch to stone age hardware just to have a little peace of mind. Evolution! >(
Post reply on HN