Live data from Hacker News

The Intel ME subsystem can take over your machine, can't be audited

boingboing.net

261–270 of 282 posts

Re: The Intel ME subsystem can take over your machine, can't be audited

#261

It may be, that Intel didn't plan this as an NSA/XYZ back door - but it doesn't actually matter. What matters is that we know 1) Intel has such technology implemented in allmost all desktops/servers currently running 2) you can access those machines remotely (even over GSM) and perform reads/writes. Example misuse: somebody can put illegal stuff on your machine and then sue you... (Intel has marketed this feature for…

Seems like they finally got the "Clipper" chip through... this is basically a trojan horse for spy agencies.

Re: The Intel ME subsystem can take over your machine, can't be audited

#262

I find people freaking out about this extremely strange. AMT is Intel's equivalent of IPMI. It is a non-standard implementation of it, and does not follow any of the relevant specifications. It does not integrate into most server management platforms. AMT costs extra. Most mobos do not have it enabled as you have to pay Intel's tax on it, even if some of the hardware to enable it is in every northbridge. A motherboar…

Not exactly, ME even without AMT is scary[1]. [1] https://libreboot.org/faq/#intelme

Yes, early versions of the ME had issues.

However, that website is a known source of FUD. Shame, since I used to like the FSF before it just started attacking everyone that didn't comply with their requests.

Re: The Intel ME subsystem can take over your machine, can't be audited

#263

I find people freaking out about this extremely strange. AMT is Intel's equivalent of IPMI. It is a non-standard implementation of it, and does not follow any of the relevant specifications. It does not integrate into most server management platforms. AMT costs extra. Most mobos do not have it enabled as you have to pay Intel's tax on it, even if some of the hardware to enable it is in every northbridge. A motherboar…

IPMI is equally scary: https://www.youtube.com/watch?v=GZeUntdObCA https://lwn.net/Articles/630778/ http://fish2.com/ipmi/

IPMI should always be used on a dedicated port, and on an isolated network with strict access control.

Disclaimer: I run a dedicated server host.

Re: The Intel ME subsystem can take over your machine, can't be audited

#264

I'm very surprised that no-one on HN has talked about their experiences of using AMT for enterprise IT management. Aside from the security problems, I've personally never encountered or seen it's use, which makes the ME's inclusion (on all chips, for about 6 years) seem like an odd decision from Intel.

> I've personally never encountered or seen it's use, which makes the ME's inclusion (on all chips, for about 6 years) seem like an odd decision from Intel. I consider it as quite plausible that the reason why Intel included ME into all chips is that it is much cheaper to add those unnecessary gates to any chip than to create two different versions of it. The much more interesting question is why ME cannot be disable…

It could be hardware switch on motherboard.

Re: The Intel ME subsystem can take over your machine, can't be audited

#265
post #249

Earlier quoted context omitted.

This is simply a barrier of resources and technology. Let's consider how software became "free". An idealist, an university and a motivated Finnish student, among many others, were able to create two complete, free operating systems and toolchains, on top of which anybody and everybody in the world could build. Now free software is a resounding reality and even increasingly adopted by large corps who were 100% closed…

Aren't FPGAs a possible solution?

Well at least one incident seems to indicate that FPGAs can also have backdoors engineered into them just as easily: https://www.schneier.com/blog/archives/2012/05/backdoor_foun...

We need the manufacturing process to also be opened up just as much as the chip design, but the latter seems an easier goal, though in itself still difficult thanks to IP and economics.

Re: The Intel ME subsystem can take over your machine, can't be audited

#266

Earlier quoted context omitted.

But how do you know? Even if you can flash new firmware, how do you know it is all the firmware? There may be a layer below what you can see, with its own CPU, memory, and firmware.

> But how do you know? Even if you can flash new firmware, how do you know it is all the firmware? There may be a layer below what you can see, with its own CPU, memory, and firmware. We have to differ here: First question is whether there is a deeper layer below and the other one whether there is additional hardware on the SoC which could also patch the (main) firmware (say: firmware update Over The Air (OTA)). I ca…

"If you know the processor you can simply look up in the documentation of the processor whether there are other even more privileged modes"

That requires trusting that the documentation is complete.

And I think such a lower layer could be hidden very well, and need not be involved in day-to-day operations. For example, in your network card it could sniff traffic, becoming active only after receiving a very specific series of packages. And the change could be as simple as ignoring a signature on over the air firmware updates.

Yes, decapping, X-raying, and years of work can always uncover such stuff, but it is the only way to be absolutely, absolutely sure. If you're China, Russia or the US and buy military hardware, I think you should be somewhat worried about this.

Re: The Intel ME subsystem can take over your machine, can't be audited

#267

I wish the European Commission study this problem and if found guilty impose a fine in such a way and quantity that in no way those firms can continue exposing their clients to possible economic damage. The previous imposed fine was of EUR 1.06 billion. Someone with the required knowledge should submit a detailed record of this potential hazard to the European Commission emphasizing how this system could expose clien…

Unfortunately even these kind of fines are still pocket chance for such large corporation. Moreover, this is always the same issue of imposing a penalty without offering an alternative. In this case offering a hardware/software platform competing with the long established Wintel.

Re: The Intel ME subsystem can take over your machine, can't be audited

#268

One thing, OK, so we have this super fantastic network enabled Java platform running autonomously from within around 3 billion devices across the globe since 2006 with the capability to read everything from the systems they are running completely unnoticed.. shouldn't this generate a FAIR amount of network traffic (and resulting suspicious log files, if not on the computers then on the routers) or am I missing someth…

Most are not enabled/activated or connected through the NIC.

OK (sources on that being the case?), but the issue then remains that we have no way of knowing whether it is activated or could be activated, is that correct?

Re: The Intel ME subsystem can take over your machine, can't be audited

#269
post #79

Earlier quoted context omitted.

> GPUs without BLOBs are hard to find Any devices without firmware are hard to find. Even if only some have option to upload firmware almost every device on market have closed-source firmware inside it: NICs, USB controllers, hard drives and especially modern SSD, sound cards, etc.

NICs exist, occasionally: Atheros Wifi chips work with open-source firmwares. And it shouldn't be too hard to find a GBit ethernet NIC without. Everything else is a lost cause right now. Keyboards, mice, displays, … Everything is running proprietary firmware blobs.

atheros microcode is not opensource, only the driver is. the microcode binary has a liberal license, but good luck turning that into source code.

Re: The Intel ME subsystem can take over your machine, can't be audited

#270

Nice breakdown of how ME works, but nothing new here. Still, I'm glad I hold on to a ton of older, pre Core i-series Intel machines, AMD machines, and ARM boards. If ME is ever truly compromised at least I have a fallback or three.

In fact, I still don't see much of a reason to upgrade quad core Yorkfield Q9xxx servers except for cheap SSD upgrades. An 8 year old desktop still compares favorably to a $700 laptop (except, of course, for electricity).

all intel chipsets since 2006 have had AMT/ME, including yours
Post reply on HN