Live data from Hacker News

Uncorrectable freedom and security issues on x86 platforms (2016)

decentralize.today

131–140 of 141 posts

Re: Uncorrectable freedom and security issues on x86 platforms (2016)

#131
post #106

Earlier quoted context omitted.

Try using Intel ME. Than come back and tell us that's a tool for mass surveillance. If you think there's a evil NSA front for this type of stuff -- its Absolute Software. Their bits have been embedded in most BIOS packages since the 90s, and nobody has heard of them.

Absolute with their Computrace product is selling what amounts to a hardware rootkit, which can be enabled with a simple unprivileged exe or bash script. You can wipe, encrypt, lock, view & kill processes, retrieve any file and view every file on machine, and view hardware & software status and licensing. It also incorporates a bunch of other features, but those are what scare me most. This is only made worse by the…

It certainly seems unusual that this software exists, but only from a single company. You would think HP/Dell/Lenovo/etc who are desperate for services revenue, would be making a similar technology if it was valuable.

A past employer looked into the product and had a reasonably high level engagement. We never got complete answers to many questions, and the company itself didn't feel particularly large. Granted we disengaged when we couldn't make the ROI work -- we just don't lose many devices. It seems unusual that a teeny company from Vancouver that nobody has heard of can navigate the bureaucracy of massive PC vendors and Asian suppliers of motherboards and android SoCs for decades.

It also seems weird when you consider that Intel, despite having a near monopoly on x86 and the ability to get other mega corps to put Intel stickers on things, (and even push them to make Atom phones that nobody wants!) gets comparatively little love for its management layer.

Re: Uncorrectable freedom and security issues on x86 platforms (2016)

#132

>As Intel owns all rights to the x86 architecture, there will never be any new manufacturers licensed to make x86 chips ... This strikes me as the root problem here. How can one company be granted a monopoly on what is basically an instruction set? Particularly in the case of the instruction set our civilization runs on? Since I can't understand how something like this could happen I don't understand why any replacem…

The legality of x86's ISA being copyrighted/patented aside, the x86 ISA isn't that attractive for any new endeavours. It's a very complex ISA which is incredibly difficult to decode. Internally, it is anyway converted to RISC style microops. So as a competitor, you don't really gain a whole lot by implementing the x86 ISA apart from the ability to run software without writing a new compiler. What's more important is the microarchitecture.

Re: Uncorrectable freedom and security issues on x86 platforms (2016)

#133
post #106

Earlier quoted context omitted.

Absolute with their Computrace product is selling what amounts to a hardware rootkit, which can be enabled with a simple unprivileged exe or bash script. You can wipe, encrypt, lock, view & kill processes, retrieve any file and view every file on machine, and view hardware & software status and licensing. It also incorporates a bunch of other features, but those are what scare me most. This is only made worse by the…

It certainly seems unusual that this software exists, but only from a single company. You would think HP/Dell/Lenovo/etc who are desperate for services revenue, would be making a similar technology if it was valuable. A past employer looked into the product and had a reasonably high level engagement. We never got complete answers to many questions, and the company itself didn't feel particularly large. Granted we dis…

Intel's ME/vPro can do a lot, but its nowhere near the fit and finish of Computrace. They aren't very good on sales, but once you become a reseller there are a ton of features you can access & use to manage your computers.

The reason Absolute is Vancouver based by the way is the Canadian Govt gives massive tax breaks to software companies, hence why a ton of point of sale and other software companies are based just to the north.

Re: Uncorrectable freedom and security issues on x86 platforms (2016)

#134
post #114
post #72

Earlier quoted context omitted.

> now requires FOSS users to purchase a license from Microsoft to boot FOSS This isn't actually true, is it?

Nope. It should be normally possible to disable Secure Boot. In fact, many distributions don't support Secure Boot at all.

> Nope. It should be normally possible to disable Secure Boot.

This is only true on x86. On arm, Microsoft's requirements state that it should not be possible for users to disable Secure Boot.

Re: Uncorrectable freedom and security issues on x86 platforms (2016)

#135
post #101

Earlier quoted context omitted.

Well, then you can go deeper and check out baseband firmware liberation project - OsmocomBB [1], since baseband firmware in a far worse shape than applications firmware (and TrustZone firmware) in smartphone industry. [1] https://osmocom.org/projects/baseband

I don't think baseband can ever be truly free because of regulatory issues. The only realistic way of containing it would be through isolation.

So the revolutionary wars didn't happen?

Re: Uncorrectable freedom and security issues on x86 platforms (2016)

#136

Earlier quoted context omitted.

How so? The OEMs want to make hardware that runs Windows. Microsoft provides a specification[0] and certification suites[1] that defines what "Windows-compatible" means, which OEMs then follow. Nothing coercive about that. There is no open standard that defines what a PC is. Linux and other operating systems are piggybacking on the Windows PC standard. If they want OEMs to manufacture hardware to their standards, the…

>"The OEMs want to make hardware that runs Windows." I disagree. I think the OEMs want to make hardware that consumer buy. I don't think they care one bit what OS consumers run on top of their hardware. In fact I would imagine OEMS would prefer to bring their products to market without consulting Microsoft at all. It's coercive in the sense the the secure execution is predicated on there only being one PK and the OEM…

They also want to make hardware that doesn't get them assasinated by the King's agents.

Re: Uncorrectable freedom and security issues on x86 platforms (2016)

#137
post #57

Earlier quoted context omitted.

tomesh is literally doing CJDNS+OrangePiZero+5GHz+WAP+802.11s to get the most inexpensive yet performant meshing node. Come chat via Matrix at #software:tomesh.net

Mmm, how is throughput? I know that on an OrangePi PC (same Allwinner H3) I was getting 5MB/s for a point to point transfer, didn't check relay throughput though. I assume the H5 would do better with gigabit and 2.5x better NEON performance, but I've yet to test (just got kernel 4.10 built for it & booting Debian reliably).

Seems to be good, here are some iperf3 tests over the link:

OPi with no build flags: [ ID] Interval Transfer Bandwidth Retr [ 4] 0.00-120.00 sec 290 MBytes 20.3 Mbits/sec 165 sender [ 4] 0.00-120.00 sec 290 MBytes 20.3 Mbits/sec receiver.

OPi with optimal build flags: [ ID] Interval Transfer Bandwidth Retr [ 4] 0.00-120.00 sec 366 MBytes 25.6 Mbits/sec 141 sender [ 4] 0.00-120.00 sec 366 MBytes 25.6 Mbits/sec receiver

Re: Uncorrectable freedom and security issues on x86 platforms (2016)

#138

Earlier quoted context omitted.

>NSA 100% What about the other powers? China, France, Russia have their own NSA's that would be asked to provide solutions to protect all the PCs in the service of their own governments, what are they doing about it?

also how can the American NSA trust the manufacturing process? Couldn't the Chinese counterpart of the NSA possibly reprogram the code of this processor when it was manufactured? Reflections on trusting trust that is...

Take sample processors, uncap them, x-ray them, compare the designed circuitry with the x-rayed one. That would be a way.

Re: Uncorrectable freedom and security issues on x86 platforms (2016)

#139
post #134
post #114

Earlier quoted context omitted.

Nope. It should be normally possible to disable Secure Boot. In fact, many distributions don't support Secure Boot at all.

> Nope. It should be normally possible to disable Secure Boot. This is only true on x86. On arm, Microsoft's requirements state that it should not be possible for users to disable Secure Boot.

But is there any interesting ARM hardware that is certified for Windows? (Honest question, I have no idea.)

Re: Uncorrectable freedom and security issues on x86 platforms (2016)

#140
post #139
post #134

Earlier quoted context omitted.

> Nope. It should be normally possible to disable Secure Boot. This is only true on x86. On arm, Microsoft's requirements state that it should not be possible for users to disable Secure Boot.

But is there any interesting ARM hardware that is certified for Windows? (Honest question, I have no idea.)

For Windows RT, looks like there wasn't that many certified devices.[1]

[1]: https://en.wikipedia.org/wiki/Windows_RT#Devices

Post reply on HN