Live data from Hacker News

The Intel ME subsystem can take over your machine, can't be audited

boingboing.net

221–230 of 282 posts

Re: The Intel ME subsystem can take over your machine, can't be audited

#221

While that article is correct, it's full of FUD with the constant littering of 'secret' and 'take over' in the text. We already know about Igor's research and the published ARC CPU reverse engineering, "Ring -3" rootkits and the DEF CON presentations. This is bad, and this needs even more reverse engineering so at some point we might add an 'open' replacement for the required ME functions and run it together with say…

Yeah, the language is a bit excessive, but this is downright terrifying. Given the absurd security protections implemented in IPMI I can't imagine the successor being trustworthy enough to satisfy serious security requirements. Anyone remember the infamous cypher zero bug/feature in IPMI where you could specify an undocumented connection encryption mode which made authentication optional?

Re: The Intel ME subsystem can take over your machine, can't be audited

#223

Earlier quoted context omitted.

> On modern systems it's will just poweroff every 30 minutes if ME firmware not present That's highly suggestive of a hidden agenda.

You can still turn ME into "manufacturing test mode", where it will not execute things. But in that mode Intel Network Cards will poweroff every 3 minutes. I wondered why my I219-V didn’t work, until I found it worked with ME in normal mode. Now I’m back on a 2006 100M Realtek NIC

Will it also shut down add-in cards in a PCIe slot?

Re: The Intel ME subsystem can take over your machine, can't be audited

#224

When it comes to hardware backdoors, one particular case seems to keep popping up in my mind, and that is Bill Hamilton of the infamous Inslaw/Promis octopus debacle. A few years ago when I was on Scheiers blog regular, he was claiming they had prearranged the backdoor installation at the silicon manufacturing level... Something about that has never left my mind, and I suspect its generally correct. Heres hoping that…

Is this the company you are referencing?

https://en.wikipedia.org/wiki/Inslaw

Re: The Intel ME subsystem can take over your machine, can't be audited

#225

Earlier quoted context omitted.

You can still turn ME into "manufacturing test mode", where it will not execute things. But in that mode Intel Network Cards will poweroff every 3 minutes. I wondered why my I219-V didn’t work, until I found it worked with ME in normal mode. Now I’m back on a 2006 100M Realtek NIC

Will it also shut down add-in cards in a PCIe slot?

Nope, that’s why my 2006 Realtek card works.

Re: The Intel ME subsystem can take over your machine, can't be audited

#226

Nice breakdown of how ME works, but nothing new here. Still, I'm glad I hold on to a ton of older, pre Core i-series Intel machines, AMD machines, and ARM boards. If ME is ever truly compromised at least I have a fallback or three.

In fact, I still don't see much of a reason to upgrade quad core Yorkfield Q9xxx servers except for cheap SSD upgrades. An 8 year old desktop still compares favorably to a $700 laptop (except, of course, for electricity).

Re: The Intel ME subsystem can take over your machine, can't be audited

#227
Previously:

https://news.ycombinator.com/item?id=10458318 (233 days)

https://news.ycombinator.com/item?id=11422531 (73 days)

https://news.ycombinator.com/item?id=8813029 (534 days)

https://news.ycombinator.com/item?id=11880935 (5 days)

Among many, many others...

Re: The Intel ME subsystem can take over your machine, can't be audited

#228
I think at this point pretty much anything on your PC is backdoorable. I can't think of a single device in my computer that doesn't respond to "magic I/O packets" which are undocumented (obviously) and prone to bugs (possibly).

Gaming mouse? Yeah send some I/O packets and you can change the DPI, USB update rate, whatever. A write-protected USB device? Uh-huh, send some magic-packets to the controllers to reset it/format it/whatever (Recently did this with one of those Dell USB Mentor Media drives that they ship the OS on). Access point? Yeah, send some magic packets and you can set the password/SSID/whatever. Hard Disk? undocumented SATA commands allows for reprogramming. This is just the 'easy' way, without going into JTAG and other diagnostic interfaces.

Re: The Intel ME subsystem can take over your machine, can't be audited

#230

This adds a whole new dimension to 'Intel Inside'. It says exactly what anyone needs to know. If it's for enterprise features as 'innocently' suggested that those who do not need or want this feature should be able to put it off simply without drama, debate or discussion. Its not surprising that both AMD and ARM have it. This is an orchestrated effort signifying the win of paranoia and security over privacy in the we…

This is rather melodramatic. People don't care about things like Intel ME because for almost all of them, they don't ever affect their lives in any direct way at all, not because they've been beaten into submission and are in "survival mode."

Its like don't caring there's an idle remote controlled mine under your driveway. You need near perfect trust to consider yourself safe.
Post reply on HN