Live data from Hacker News

Neutralize ME Firmware on SandyBridge and IvyBridge Platforms

hardenedlinux.org

1–10 of 81 posts

Re: Neutralize ME Firmware on SandyBridge and IvyBridge Platforms

#4
This appears to be a legitimate ME neutralization.

The ME is purportedly placed in "recovery" mode:

  According to Nicola Corna, the current ME state should have been changed from “normal” to “recovery”.
Since the MEI interface is disabled (not visible from a PCI bus scan), there is no way to activate the ME at runtime, even after a full system compromise. It would still be possible to rewrite the BIOS flash chip with a new ME image, but the system would need to be restarted before the ME would read the changes.

I don't speak for the FSF, but it sounds like this is as close to an FSF RYF certification as any Intel CPU is going to get. FSF approval of a device requires that all user-modifiable software be Free Software. Previously, no recent Intel CPUs could be FSF certified as "RYF" because the ME chip would shut the system down after 30 minutes. (Side note: no recent Intel CPUs can be considered "stable" without microcode updates which also violate the FSF's RYF guidelines.)

[1] http://www.fsf.org/resources/hw/endorsement/respects-your-fr...

Re: Neutralize ME Firmware on SandyBridge and IvyBridge Platforms

#5
post #3

The ridiculous shit that needs to be done just to rid of some blob. RISC-V can't take the market over fast enough.

How much are you willing to pay for it?

There's the Talos Secure Workstation, which has no such ME firmware (but costs ~$4.5k) [1].

A RISC-V desktop is pretty far out. There is an Arduino style microcontroller being made in silicon, though [2].

[1] https://www.crowdsupply.com/raptor-computing-systems/talos-s... [2] https://www.crowdsupply.com/onchip/open-v

Re: Neutralize ME Firmware on SandyBridge and IvyBridge Platforms

#8
post #3

The ridiculous shit that needs to be done just to rid of some blob. RISC-V can't take the market over fast enough.

It's more than just "some blob" though. ME is a system within your system, that is completely out of your control. [0]

[0] https://libreboot.org/faq/#intelme

Re: Neutralize ME Firmware on SandyBridge and IvyBridge Platforms

#10
post #5
post #3

The ridiculous shit that needs to be done just to rid of some blob. RISC-V can't take the market over fast enough.

How much are you willing to pay for it? There's the Talos Secure Workstation, which has no such ME firmware (but costs ~$4.5k) [1]. A RISC-V desktop is pretty far out. There is an Arduino style microcontroller being made in silicon, though [2]. [1] https://www.crowdsupply.com/raptor-computing-systems/talos-s... [2] https://www.crowdsupply.com/onchip/open-v

Note that it looks like they may not make their goal. It ends on Dec 15th, and they only have about 10% raised ($344,310 raised of $3,700,000 goal)
Post reply on HN