Live data from Hacker News

The Intel ME subsystem can take over your machine, can't be audited

boingboing.net

211–220 of 282 posts

Re: The Intel ME subsystem can take over your machine, can't be audited

#211
post #67

Earlier quoted context omitted.

Pi-top like laptop with your choice of pi3 or BeagleBone running Linux. The performance of a pi3 is actually decent. It's not perfect as there's a GPU BLOB in the pi3 and the BB also has some issue. It's my compromise for now, hoping the blob will be reversed/replaced eventually. Or anything that runs libreboot: https://libreboot.org/docs/hcl/ If OpenBSD runs on it that's also a good sign usually as they won't touch…

I do actually on a Pi3, so that's an encouraging piece of info. A GPU blob is at least a step up from the ring-negative-3 management engine.

I don't think it's a big difference to be honest: The GPU firmware (start.elf) is required to boot the Pi. There is no source code available at the moment.

The GPU firmware runs in parallel to the CPU and has access to the complete memory. Video decoding is done by the GPU and happens while the CPU is completely idle. And it can (of course) crash. If you've done anything related to OMX programming on the Pi, you might have experienced that.

In theory there is nothing that would prevent the a rogue firmware from hooking into kernel structures to interface with the outside world.

Re: The Intel ME subsystem can take over your machine, can't be audited

#212
post #86
post #32

Earlier quoted context omitted.

I don't know how its actually implemented, but normally to enable AMT you have to have both a compatible motherboard and processor. Intel calls it VPRO. Most desktop consumer boards do not have this feature, but quite a few of the i5 processors do.

> Most desktop consumer boards do not have this feature, but quite a few of the i5 processors do. Considering how many firmware updates I've installed on gaming-oriented motherboards with Z-series chipsets that have included ME firmware payload, it's worth looking in to what it means for those boards to not have the feature. We know that all the transistors are physically present on both CPU and chipset. Are they tru…

I think the AMT code is just omitted from the ME firmware.

Re: The Intel ME subsystem can take over your machine, can't be audited

#213
post #79

Earlier quoted context omitted.

> GPUs without BLOBs are hard to find Any devices without firmware are hard to find. Even if only some have option to upload firmware almost every device on market have closed-source firmware inside it: NICs, USB controllers, hard drives and especially modern SSD, sound cards, etc.

NICs exist, occasionally: Atheros Wifi chips work with open-source firmwares. And it shouldn't be too hard to find a GBit ethernet NIC without. Everything else is a lost cause right now. Keyboards, mice, displays, … Everything is running proprietary firmware blobs.

Keyboards and mice have the distinction of being low enough resource that they can be independently implemented with cheap microcontrollers - there's currently a whole cottage industry for keyboards, spurred on by enthusiasm for discrete switches. And hopefully these microcontrollers' cheapness is enough to ward off Hanlon's razor's silicon. Furthermore, there's fewer avenues for backhaul from non-connected peripherals, especially mass backhaul.

I think in time, "Internet access" will come to be recognized as a bug, much the same way that "turing completeness" is starting to be recognized as such for programming languages. Not needed for most uses, very easy to accidentally obtain, and game-over for tractability when it shows up. The question is what a general better "restricted language" looks like that is able to accomplish all that we'd like.

Re: The Intel ME subsystem can take over your machine, can't be audited

#215

Earlier quoted context omitted.

When has this happened? I'm curious about things that could cast the NSA in a positive light.

The DES standard's S-Boxes were changed by the NSA in the 1970s. It was long thought that this was to weaken them. However in the 1990's differential cryptanalysis was publicly discovered, and the NSA's changes to the S-boxes were found to have hardend DES agaist differential cryptanalysis.

Now here's something fascinating. According to https://en.wikipedia.org/wiki/Differential_cryptanalysis#His..., IBM discovered differential cryptanalysis in the 1970s when designing DES. They opted to keep it a secret, given its general applicability against ciphers. It is unclear whether IBM shared it with the NSA or the NSA discovered it independently, but there's strong evidence that both IBM and the NSA were aware of differential cryptanalysis well before the public discovery in the 90s.

¹ This has what looks like a good citation but requires a subscription to access the relevant paper (sigh).

Re: The Intel ME subsystem can take over your machine, can't be audited

#216
post #170

Earlier quoted context omitted.

And i think the variant found on Qualcomm SOCs were recently cracked open.

If you mean CVE-2015-6639 The Widevine QSEE TrustZone application in Android 5.x before 5.1.1 LMY49F and 6.0 before 2016-01-01 allows attackers to gain privileges via a crafted application that leverages QSEECOM access, aka internal bug 24446875. then it's not strictly TrustZone that have been cracked, but some software running within, already patched. TrustZone itself is a hardware mechanism, basically a new level a…

I may have gotten it confused with something else. I think it said something about Qualcomm private keys having been extracted.

Re: The Intel ME subsystem can take over your machine, can't be audited

#217

This adds a whole new dimension to 'Intel Inside'. It says exactly what anyone needs to know. If it's for enterprise features as 'innocently' suggested that those who do not need or want this feature should be able to put it off simply without drama, debate or discussion. Its not surprising that both AMD and ARM have it. This is an orchestrated effort signifying the win of paranoia and security over privacy in the we…

Why limit your statement to "the USA and Europe"? Do you imagine the People's Republic of China is some sort of paragon of openness and transparency?

Re: The Intel ME subsystem can take over your machine, can't be audited

#218

This adds a whole new dimension to 'Intel Inside'. It says exactly what anyone needs to know. If it's for enterprise features as 'innocently' suggested that those who do not need or want this feature should be able to put it off simply without drama, debate or discussion. Its not surprising that both AMD and ARM have it. This is an orchestrated effort signifying the win of paranoia and security over privacy in the we…

This is rather melodramatic. People don't care about things like Intel ME because for almost all of them, they don't ever affect their lives in any direct way at all, not because they've been beaten into submission and are in "survival mode."

Re: The Intel ME subsystem can take over your machine, can't be audited

#219

And this is why monopoly of one giant monolith is bad, in any area or case! They get to the whatever the f they want! It's not like everything is made today to track, and give access to "authorities" when they want it. But what really drives me mad is that I feel tricked! You put trust into someone and it's work, and give them money for that, but they do this, without you even knowing. I was always making fun of swor…

> And this is why monopoly of one giant monolith is bad, in any area or case!

The Intel/AMD duopoly in this case is just as bad, as AMD has comparable backdoors in its hardware. The whole x86/x86_64 architecture is compromised.

> But maybe they were on the track!

https://www.reddit.com/r/stallmanwasright

Re: The Intel ME subsystem can take over your machine, can't be audited

#220
post #129

Earlier quoted context omitted.

NICs exist, occasionally: Atheros Wifi chips work with open-source firmwares. And it shouldn't be too hard to find a GBit ethernet NIC without. Everything else is a lost cause right now. Keyboards, mice, displays, … Everything is running proprietary firmware blobs.

> Atheros Wifi chips work with open-source firmwares. Interesting. Isn't such firmware able to initiate unlawful transmissions? How are they going to deal with this new FCC goodness?

It will likely be ignored. How do you prevent NSA from anything.
Post reply on HN