Live data from Hacker News

The Intel ME subsystem can take over your machine, can't be audited

boingboing.net

191–200 of 282 posts

Re: The Intel ME subsystem can take over your machine, can't be audited

#191
post #107

Earlier quoted context omitted.

CSS is only 40 bits, which is ridiculously easy to crack. 56-bit DES keys are pretty unsafe these days, so you want at least 128 bits if you're talking private keys. If it's using 2048-bit RSA, that's perhaps equivalent to a 256-bit private key. So entirely different ballpark to CSS.

Wrong. 2048-bit RSA has an effective security level of approximately 112 bits, just like 3-DES. If you want 256 bits of security, you go all the way up to 15360-bit RSA. That's why Elliptic Curve systems are so attractive: they involve operations that are more costly per-bit, but the required key sizes to meet a security level are much less. Ofcourse, Elliptic Curve Cryptography as specified by NIST has its own downs…

Though when the NSA has done things like this in the past, we've found their choices prevented implementation weaknesses that weren't found (by anyone else) for several more years.

Re: The Intel ME subsystem can take over your machine, can't be audited

#192

This adds a whole new dimension to 'Intel Inside'. It says exactly what anyone needs to know. If it's for enterprise features as 'innocently' suggested that those who do not need or want this feature should be able to put it off simply without drama, debate or discussion. Its not surprising that both AMD and ARM have it. This is an orchestrated effort signifying the win of paranoia and security over privacy in the we…

This cruft doesn't need three letter agencies to exist. Big customers pay for it so it's done. Once it's done, it's easier to leave it there and soft-disable for people who haven't paid for it than to actually build two versions of the chip, with and without this feature.

However, speaking of spooks, I heard rumors that either Intel AMT or BIOS or some drivers (don't remember which exactly) is sold to the Chinese market with castrated crypto. Reportedly it's because the Chinese government requires imported crypto to be just strong enough to resist average guy, but not their supercomputers.

Re: The Intel ME subsystem can take over your machine, can't be audited

#193
post #129

Earlier quoted context omitted.

> Atheros Wifi chips work with open-source firmwares. Interesting. Isn't such firmware able to initiate unlawful transmissions? How are they going to deal with this new FCC goodness?

Funnily, the FCC requirement is incompatible with the EU laws. The EU laws say that while a normal user shouldn’t be able to make unlawful transmissions, the manufacturer may NOT prevent the customer from installing alternative software (like openwrt) just to fulfil the first requirement. Basically, to conform with EU law, you have to violate US law, and the other way round.

Any sources?

And no, it's not mutually exclusive. In principle, it should be possible to enforce regulatory constraints in hardware. But then I guess you can forget about taking this hardware to another country, unless they make this hardware as smart (read: complex) as drivers currently are.

Re: The Intel ME subsystem can take over your machine, can't be audited

#194

Earlier quoted context omitted.

https://puri.sm/posts/petition-for-intel-to-release-an-me-le...

Another lame petition won't get the same kind of results as a well connected question. The PR department lives to shield a company from such negative external noise, a well connected question can surface inside the company and be heard by people with the capability to actually do things.

> allowing Purism to provide this petition to our Intel Partner Account Manager

It's at least worth a shot to see what they have to say about it...

Re: The Intel ME subsystem can take over your machine, can't be audited

#195

I wasn't aware about Intel ME until recently bought a brand new Lenovo ThinkPad and saw the "Intel Management Engine" on BIOS/UEFI boot menu. The thing is: how can I configure this ME thing in order to avoid (or minimize, at least) possible attacks?

You can't. The whole point of the thing is that it can't be disabled and will always be running to let your theoretical IT department take over your machine.

Re: The Intel ME subsystem can take over your machine, can't be audited

#196

Earlier quoted context omitted.

Wrong. 2048-bit RSA has an effective security level of approximately 112 bits, just like 3-DES. If you want 256 bits of security, you go all the way up to 15360-bit RSA. That's why Elliptic Curve systems are so attractive: they involve operations that are more costly per-bit, but the required key sizes to meet a security level are much less. Ofcourse, Elliptic Curve Cryptography as specified by NIST has its own downs…

Though when the NSA has done things like this in the past, we've found their choices prevented implementation weaknesses that weren't found (by anyone else) for several more years.

When has this happened? I'm curious about things that could cast the NSA in a positive light.

Re: The Intel ME subsystem can take over your machine, can't be audited

#199

This adds a whole new dimension to 'Intel Inside'. It says exactly what anyone needs to know. If it's for enterprise features as 'innocently' suggested that those who do not need or want this feature should be able to put it off simply without drama, debate or discussion. Its not surprising that both AMD and ARM have it. This is an orchestrated effort signifying the win of paranoia and security over privacy in the we…

> the win of paranoia and security over privacy

The win of paranoia over security and privacy.

Post reply on HN