Live data from Hacker News

Uncorrectable freedom and security issues on x86 platforms (2016)

decentralize.today

41–50 of 141 posts

Re: Uncorrectable freedom and security issues on x86 platforms (2016)

#41
post #4

Would love to see and ARM or MIPS setup get within shouting range of Intel. I have yet to hear any explanation of the IME that makes sense without the presence user-hostile intent.

Management of "corporate" computers. Installing Windows on hundreds of machines at once, remotely wiping stolend laptops with corporate secrets. But the cancer has spread to all computers, regardless of domain of activity.

Re: Uncorrectable freedom and security issues on x86 platforms (2016)

#42
post #10
post #6

The article states the following for RISCV: >"While this architecture is extremely limited in performance, price" Can anyone say thy the performance of RISCV is so lacking?

Likely because there's no major consumer devices shipping them (or at least high-end versions of them) that could help them hit a scale that brings the cost down, which makes them less viable for a general public consumer standpoint, which means there's less time spent optimizing it. I remember a wihle back when Google was shopping around for Intel replacements (likely a negotiation tactic), people were saying they s…

>"I remember a wihle back when Google was shopping around for Intel replacements (likely a negotiation tactic), people were saying they should buy the POWER division from IBM (IIRC). "

Funny, I was speaking to some IBM engineers a few months ago and brought up the POWER chips and they kind of laughed and said something to effect that biggest use case for POWER was Google as a means of keeping Intel pricing in check.

Re: Uncorrectable freedom and security issues on x86 platforms (2016)

#43
post #26

I'm trying to understand all of this and especially the threats to privacy, control of my computing hardware, and data security. I read about some new hard/software for secure boot , etc., but don't recall all the details now. So, for a shorter approach, suppose I just buy a processor from AMD, a motherboard from ASUS, hard disk drives from Western Digital, etc., and plug it all together for myself. So, then I'm the…

1. The motherboad has a ARC chip, that loads a firmware included in the flash chip. That ARC chip is supposedly inside the PCH (Platform Controller Hub, a north bridge on steroids) - it's efectively in the silicon, you can't remove it.

2. Depends on the motherboard and the BIOS written in the flash chip

3. No. They are already signed.

4. If somebody controls them and ask them to do so. All that's necesary is a LAN connection (or wifi, but only with Intel chips) and power. The HDD is completely irrelevant, as is the OS.

Re: Uncorrectable freedom and security issues on x86 platforms (2016)

#44
post #4

Would love to see and ARM or MIPS setup get within shouting range of Intel. I have yet to hear any explanation of the IME that makes sense without the presence user-hostile intent.

> I have yet to hear any explanation of the IME that makes sense without the presence user-hostile intent.

The entirety of enterprise laptop management. Not because you don't want users to change their laptop. The point is to be able to run updates for the users.

Or consider the remote KVM option. Disregarding security, that is a sysadmin's wet dream. Being able to recover a system that can't boot saves a lot of boots on the ground.

Re: Uncorrectable freedom and security issues on x86 platforms (2016)

#45
post #8

Isn't it sci-fi-level incredible, and frankly both scary and shady, that every modern x86 CPU has this forced sub-ring-0 control program? And that the CPU vendors apparently go to extreme lengths in hiding its functionality? Why would even large vendors like Apple or Dell agree to this? The 30-minute timeout is particularly mischievous. It's like they REALLY want to slow down any effort at patching out the ME. Are we…

More details on this http://wiki.osdev.org/SMM

Re: Uncorrectable freedom and security issues on x86 platforms (2016)

#46
post #31

Earlier quoted context omitted.

NSA 100% . Some time around 10 years ago governments decided the internet was too "dangerous" to be free. Arab spring cemented that into their minds, and now a bastion of free thought has become the worlds biggest spying apparatus.

So why not build our own network with crypto, blackjack & hookers on libre hardware? Say on an OrangePi PC2 with a bunch of high gain USB 5GHz radios attached, and throw some spinning rust on there so you can run a Nextcloud instance and/or join your local Ceph cluster/IPFS. We have CJDNS (which salsa20's all your data & can VPN legacy networks to ya), fully FLOSS SBCs for under $20ea, and 802.11n and AC outdoor radi…

tomesh is literally doing CJDNS+OrangePiZero+5GHz+WAP+802.11s to get the most inexpensive yet performant meshing node. Come chat via Matrix at #software:tomesh.net

Re: Uncorrectable freedom and security issues on x86 platforms (2016)

#47
post #33

This needs more attention. Particularly now that AMD may actually look into cooperating with the community on this matter somewhat. I wouldn't get my hopes up yet though, as this was a Reddit AMA done during a time when AMD is keen to please the community. This matter must not go away for something to be done about it.

RISC-V comes to mind as an open and free instruction set. The step to an actual implemented-in-silicon processor is pretty big though, and for any such chip it's hard to verify that it really is as free as it's claimed to be. You can't diassemble your CPU (or perhaps you can, but for very few values of "you").

Yeah, basically you have to have a bunch made and destructively analyze some of them (https://www.extremetech.com/extreme/141077-how-to-crack-open...).

That'll build confidence that the others aren't compromised.

The costs could be reasonable (http://electronics.stackexchange.com/questions/7042/how-much...) under a kickstarter-style campaign.

Re: Uncorrectable freedom and security issues on x86 platforms (2016)

#48
post #44
post #4

Would love to see and ARM or MIPS setup get within shouting range of Intel. I have yet to hear any explanation of the IME that makes sense without the presence user-hostile intent.

> I have yet to hear any explanation of the IME that makes sense without the presence user-hostile intent. The entirety of enterprise laptop management. Not because you don't want users to change their laptop. The point is to be able to run updates for the users. Or consider the remote KVM option. Disregarding security, that is a sysadmin's wet dream. Being able to recover a system that can't boot saves a lot of boot…

Even if the CPU running Windows is bluescreened, you can still pull up a KVM remotely. Demonstrates the power that AMT possesses for good or ill.

Re: Uncorrectable freedom and security issues on x86 platforms (2016)

#49
post #6

The article states the following for RISCV: >"While this architecture is extremely limited in performance, price" Can anyone say thy the performance of RISCV is so lacking?

Major manufacturers -- like Intel, AMD or ARM -- have spent years upons years developing methodologies, technologies, micro-architectural optimizations, and testing+development+evaluation infrastructure. This is the key for understanding how to navigate and ensure good performance across the many different trade-off and optimization domains in performant-processor design.

This is not easy to acquire or build. Some is wisdom from decades of design and iteration. Some is hundreds of thousands of engineering hours. Some is big money.

RISC V is a new open source project. Who knows how close they will ever get.

Re: Uncorrectable freedom and security issues on x86 platforms (2016)

#50
While it would be great to liberate x86, more than 4 billion people in the world use mobile phones, and phones are beyond saving. x86 is in very healthy shape compared to the clusterfuck that is the smartphone industry. If you think that coreboot is a fringe project, you need to head over to replicant or neo900 to see what the fringe actually is.
Post reply on HN