Live data from Hacker News

Uncorrectable freedom and security issues on x86 platforms (2016)

decentralize.today

31–40 of 141 posts

Re: Uncorrectable freedom and security issues on x86 platforms (2016)

#31
post #8

Isn't it sci-fi-level incredible, and frankly both scary and shady, that every modern x86 CPU has this forced sub-ring-0 control program? And that the CPU vendors apparently go to extreme lengths in hiding its functionality? Why would even large vendors like Apple or Dell agree to this? The 30-minute timeout is particularly mischievous. It's like they REALLY want to slow down any effort at patching out the ME. Are we…

NSA 100% . Some time around 10 years ago governments decided the internet was too "dangerous" to be free. Arab spring cemented that into their minds, and now a bastion of free thought has become the worlds biggest spying apparatus.

So why not build our own network with crypto, blackjack & hookers on libre hardware? Say on an OrangePi PC2 with a bunch of high gain USB 5GHz radios attached, and throw some spinning rust on there so you can run a Nextcloud instance and/or join your local Ceph cluster/IPFS.

We have CJDNS (which salsa20's all your data & can VPN legacy networks to ya), fully FLOSS SBCs for under $20ea, and 802.11n and AC outdoor radios can be had for cheap, this is merely a community involvement problem.

Re: Uncorrectable freedom and security issues on x86 platforms (2016)

#32

Earlier quoted context omitted.

Libreboot and coreboot are trying to open source things on the software side of things (think dd-wrt or openwrt or tomato for routers, custom firmware basically). With hardware it's a bit of a different story. You hear about attempts from time to time, but getting away from Intel / AMD is really hard. The suggestions from the article about alternative architectures seem to be our best bet currently.

Alternative architectures is definitely the most pragmatic thing to go for. I was going off on a bit of a tangent from the article and just wondering if anyone has tried redoing the 70's - 90's without trying to be compatible with any existing technology but still learning from the mistakes.

Pure speculation: Any entity that obtains the (financial, other) resources necessary to help facilitate such fundamental subversion is eventually convinced that the status quo is necessary to our survival.

Re: Uncorrectable freedom and security issues on x86 platforms (2016)

#33

This needs more attention. Particularly now that AMD may actually look into cooperating with the community on this matter somewhat. I wouldn't get my hopes up yet though, as this was a Reddit AMA done during a time when AMD is keen to please the community. This matter must not go away for something to be done about it.

RISC-V comes to mind as an open and free instruction set. The step to an actual implemented-in-silicon processor is pretty big though, and for any such chip it's hard to verify that it really is as free as it's claimed to be. You can't diassemble your CPU (or perhaps you can, but for very few values of "you").

Re: Uncorrectable freedom and security issues on x86 platforms (2016)

#34
post #31

Earlier quoted context omitted.

NSA 100% . Some time around 10 years ago governments decided the internet was too "dangerous" to be free. Arab spring cemented that into their minds, and now a bastion of free thought has become the worlds biggest spying apparatus.

So why not build our own network with crypto, blackjack & hookers on libre hardware? Say on an OrangePi PC2 with a bunch of high gain USB 5GHz radios attached, and throw some spinning rust on there so you can run a Nextcloud instance and/or join your local Ceph cluster/IPFS. We have CJDNS (which salsa20's all your data & can VPN legacy networks to ya), fully FLOSS SBCs for under $20ea, and 802.11n and AC outdoor radi…

The issue is not widely known, silicon is very costly to manufacture, and most people frankly don't care, as long that spying is unobtrusive (and hell it is so).

Also, most people already are living with the thought that their computers are cracked/hacked/virused the moment they are connected to the internet - all my friends and relatives ask me to check their computer for viruses - almost none trust their computers or phones (especially Android phones, it seems). For such people, where this is the natural state of the world, it's very hard to imagine that they can change anything about it - and telling them that there are backdoors from the moment the laptop is assembled, doesn't help much.

Re: Uncorrectable freedom and security issues on x86 platforms (2016)

#35
post #19

Earlier quoted context omitted.

> And I just don't understand how anyone can maintain that farce when the last year has shown that it's a genuine challenge even for the US FBI to unlock a mobile device without the owners say-so Difficulty? Yes. But the FBI is not the NSA, they don't specialize in such attacks. It's like asking your plumber to do heart surgery. So they commissioned it to else who does, and boom, they had access. Strong cryptographic…

I feel like you danced around the central point of my post: there is no suggestions for how to secure and harden devices without refining these trusted computing techniques. We need to harden these devices. Your argument is no one can be trusted to make them. But my argument is that if you believe that then you know you can't trust anyone to make anything one way or the other. Surely rather than botch the whole thing…

We can harden the devices by moving to a paradigm where our desktop and server executables are available exclusively through Intel AMT App Store and signed by Intel.

Re: Uncorrectable freedom and security issues on x86 platforms (2016)

#36
post #8

Isn't it sci-fi-level incredible, and frankly both scary and shady, that every modern x86 CPU has this forced sub-ring-0 control program? And that the CPU vendors apparently go to extreme lengths in hiding its functionality? Why would even large vendors like Apple or Dell agree to this? The 30-minute timeout is particularly mischievous. It's like they REALLY want to slow down any effort at patching out the ME. Are we…

NSA 100% . Some time around 10 years ago governments decided the internet was too "dangerous" to be free. Arab spring cemented that into their minds, and now a bastion of free thought has become the worlds biggest spying apparatus.

Please. While no-doubt the NSA take advantage of this probably-insecure privileged processor, I seriously doubt they were behind it. Secure boot is an obvious business need and Intel and AMD clearly implemented it in the laziest way possible. And by laziest I mean: nobody is going to argue with you in a meeting if you say "we don't need to release the source code for this".

Seriously, anyone who has actually worked in a real company knows that it is a huge amount of effort to get source code released to the public, and if any of it is licensed from third parts it is probably near-impossible.

Re: Uncorrectable freedom and security issues on x86 platforms (2016)

#37
post #31

Earlier quoted context omitted.

NSA 100% . Some time around 10 years ago governments decided the internet was too "dangerous" to be free. Arab spring cemented that into their minds, and now a bastion of free thought has become the worlds biggest spying apparatus.

So why not build our own network with crypto, blackjack & hookers on libre hardware? Say on an OrangePi PC2 with a bunch of high gain USB 5GHz radios attached, and throw some spinning rust on there so you can run a Nextcloud instance and/or join your local Ceph cluster/IPFS. We have CJDNS (which salsa20's all your data & can VPN legacy networks to ya), fully FLOSS SBCs for under $20ea, and 802.11n and AC outdoor radi…

I'm a software engineer myself - but I can't even contribute to projects such as lowRISC - is way beyond my abilities. Right now I'm learning to program microcontrollers, and I want to learn about FPGA's as the next step.

I also work at a company that has exactly this focus - to sell, and eventually produce devices that can be run with free software from top to bottom - but I don't see ourselves producing our own devices in the next 5 years, even if we would become wildly sucessful.

The hope seems to lie with ARM for the moment - C100 / C201 have even the Embedded Controller (EC) code avaiable - but they do have plans to implement something simillar to ME, AFAIK.

Re: Uncorrectable freedom and security issues on x86 platforms (2016)

#38

I was struck by the following passage: >including Secure Boot, which even now requires FOSS users to purchase a license from Microsoft to boot FOSS on affected machines that lack an appropriate Secure Boot override." Can someone explain this to me, would this be for instance be Lenovo laptops making a deal with Microsoft since Windows is the default OS installed on these laptops? Is Microsoft mandating all OEMs/hardw…

Secure boot has 4 types of keys: The signature database (db) and forbidden signature database (dbx) contain a whitelist and blacklist respectivly of keys, signatures, and hashes that are trusted to run. Updates to either of the above lists must be signed by a Key Exchange Key (KEK). Most implementations allow multiple Key Exchanges Keys. Updates to the list of Key Exchange Keys must be signed by the Platform Key (PK)…

Thanks for the detailed answer. In regards to:

>" Most implementations only allow 1 PK, and that PK is Microsoft's."

Isn't this a bit monopolistic and coercive though? "If you want the Microsoft Hologram on your product the PK has to be has to be Microsoft and there can only be one PK." I can't believe this doesn't violate some type of anti-trust laws.

Re: Uncorrectable freedom and security issues on x86 platforms (2016)

#39
post #31

Earlier quoted context omitted.

So why not build our own network with crypto, blackjack & hookers on libre hardware? Say on an OrangePi PC2 with a bunch of high gain USB 5GHz radios attached, and throw some spinning rust on there so you can run a Nextcloud instance and/or join your local Ceph cluster/IPFS. We have CJDNS (which salsa20's all your data & can VPN legacy networks to ya), fully FLOSS SBCs for under $20ea, and 802.11n and AC outdoor radi…

The issue is not widely known, silicon is very costly to manufacture, and most people frankly don't care, as long that spying is unobtrusive (and hell it is so). Also, most people already are living with the thought that their computers are cracked/hacked/virused the moment they are connected to the internet - all my friends and relatives ask me to check their computer for viruses - almost none trust their computers…

Sure, but the silicon & libre drivers already exist and don't need to be manufactured, so at this point its a marketing problem of selling a more secure computing box.

Re: Uncorrectable freedom and security issues on x86 platforms (2016)

#40
post #16

I was struck by the following passage: >including Secure Boot, which even now requires FOSS users to purchase a license from Microsoft to boot FOSS on affected machines that lack an appropriate Secure Boot override." Can someone explain this to me, would this be for instance be Lenovo laptops making a deal with Microsoft since Windows is the default OS installed on these laptops? Is Microsoft mandating all OEMs/hardw…

Is Microsoft mandating all OEMs/hardware vendors to configure secure boot with a MS signing key? Basically yes; it's required to get the Windows sticker. I haven't heard that MS charges money to sign bootloaders, though.

Thanks, I have to wonder how much of bureaucratic headache that is to get your bootloader signed.
Post reply on HN