Neutralize ME Firmware on SandyBridge and IvyBridge Platforms
21–30 of 81 posts
Re: Neutralize ME Firmware on SandyBridge and IvyBridge Platforms
#22rootkit is defined by google search as "a set of software tools that enable an unauthorized user to gain control of a computer system without being detected." * A set of software tools: Check * Unauthorized user: Check Caveat: user is not authorized by you, but by someone else (Intel) * Gain control of a computer system without being detected. Can access your machine while it appears to be "powered off" but plugged i…
Re: Neutralize ME Firmware on SandyBridge and IvyBridge Platforms
#23Earlier quoted context omitted.
Just reboot after neutralization. "With ME neutralized, the MEI interface disappears from the PCI bus, and the integrated NIC ceases to work, but will resume to work after a reboot."
The phrasing there is confusing. Does the NIC break because the ME is neutralized? Then rebooting again with the ME neutralized will break the NIC again. Why would the NIC only break once after the ME is neutralized? The system is started from a fully powered-off state after the ME firmware is updated. Maybe the NIC has some sort of non-volatile state that gets updated when the ME fails to initialize, and then the NI…
Re: Neutralize ME Firmware on SandyBridge and IvyBridge Platforms
#24rootkit is defined by google search as "a set of software tools that enable an unauthorized user to gain control of a computer system without being detected." * A set of software tools: Check * Unauthorized user: Check Caveat: user is not authorized by you, but by someone else (Intel) * Gain control of a computer system without being detected. Can access your machine while it appears to be "powered off" but plugged i…
AFAIK the remote network access ("AMT") has to be specifically enabled.
It's also conceivable that a state-level adversary could have hidden arbitrary DMA instructions in a NIC firmware, that only activate with a signed request embedded in a random packet. Some of the largest firmware blobs on Linux systems are for NICs.
Most people aren't facing state-level targeted attacks, but without open firmware, it's nearly impossible to know for sure if one is vulnerable. And, with botnets and worms, it only takes one non-state-level attacker discovering the backdoor for everyone to be affected.
Re: Neutralize ME Firmware on SandyBridge and IvyBridge Platforms
#25Earlier quoted context omitted.
Just reboot after neutralization. "With ME neutralized, the MEI interface disappears from the PCI bus, and the integrated NIC ceases to work, but will resume to work after a reboot."
The phrasing there is confusing. Does the NIC break because the ME is neutralized? Then rebooting again with the ME neutralized will break the NIC again. Why would the NIC only break once after the ME is neutralized? The system is started from a fully powered-off state after the ME firmware is updated. Maybe the NIC has some sort of non-volatile state that gets updated when the ME fails to initialize, and then the NI…
It's not strictly clear to me, but reading through what they're doing, the ME isn't re-engaged or its unclear how it recovers itself.
Unless the ME is operating with a recovery binary somewhere that isn't covered by Nicola's neutralizer and the subsequent flashing, I don't think it comes back in to normal operation.
Re: Neutralize ME Firmware on SandyBridge and IvyBridge Platforms
#26Re: Neutralize ME Firmware on SandyBridge and IvyBridge Platforms
#27Has Intel ever commented about this issue of removing ME? Surely, at least 1 Intel staffer reads HN and they must have discussed this internally. Unless they just brush this off as negligible (a couple thousand paranoid/"extremist" users) ?
Re: Neutralize ME Firmware on SandyBridge and IvyBridge Platforms
#28The ridiculous shit that needs to be done just to rid of some blob. RISC-V can't take the market over fast enough.
How much are you willing to pay for it? There's the Talos Secure Workstation, which has no such ME firmware (but costs ~$4.5k) [1]. A RISC-V desktop is pretty far out. There is an Arduino style microcontroller being made in silicon, though [2]. [1] https://www.crowdsupply.com/raptor-computing-systems/talos-s... [2] https://www.crowdsupply.com/onchip/open-v
Wrong question. Correct question would be: "How much are you willing and able to pay for it?" (for me it much more strongly fails because of the second criterion).
Re: Neutralize ME Firmware on SandyBridge and IvyBridge Platforms
#29Earlier quoted context omitted.
How much are you willing to pay for it? There's the Talos Secure Workstation, which has no such ME firmware (but costs ~$4.5k) [1]. A RISC-V desktop is pretty far out. There is an Arduino style microcontroller being made in silicon, though [2]. [1] https://www.crowdsupply.com/raptor-computing-systems/talos-s... [2] https://www.crowdsupply.com/onchip/open-v
> How much are you willing to pay for it? Wrong question. Correct question would be: "How much are you willing and able to pay for it?" (for me it much more strongly fails because of the second criterion).
Re: Neutralize ME Firmware on SandyBridge and IvyBridge Platforms
#30The ridiculous shit that needs to be done just to rid of some blob. RISC-V can't take the market over fast enough.
How much are you willing to pay for it? There's the Talos Secure Workstation, which has no such ME firmware (but costs ~$4.5k) [1]. A RISC-V desktop is pretty far out. There is an Arduino style microcontroller being made in silicon, though [2]. [1] https://www.crowdsupply.com/raptor-computing-systems/talos-s... [2] https://www.crowdsupply.com/onchip/open-v
Source: MeetBSDCon 2016, update on RISC-V by the team who designed it.