Live data from Hacker News

Disabling Intel ME 11 via undocumented mode

blog.ptsecurity.com

1–10 of 228 posts

Re: Disabling Intel ME 11 via undocumented mode

#2
Rather than assume anything nefarious on the part of the USG, I'm willing to bet a buck that someone in the USG asked the right questions during contract negotiation, which is why this kill switch was added but not publicized to anyone outside participants in the HAP Program.

Re: Disabling Intel ME 11 via undocumented mode

#3
post #2

Rather than assume anything nefarious on the part of the USG, I'm willing to bet a buck that someone in the USG asked the right questions during contract negotiation, which is why this kill switch was added but not publicized to anyone outside participants in the HAP Program.

But maybe that contract negotiation also included a rhetorical question like "And you won't offer this option to other governments, will you?".

Re: Disabling Intel ME 11 via undocumented mode

#6

If ME is not a backdoor then why doesn't Intel allow to disable it? Why don't they publish detailed descriptions? Why don't they allow user to run their programs on ME CPU?

If ME isn't a backdoor why did Russia and China start efforts to surplant Intel with locally sourced processors (even before US embargo'd Intel from china)

Re: Disabling Intel ME 11 via undocumented mode

#7
TL;DR: Intel put a special High Assurance Platform (HAP) mode in ME for the US government. If toggled on, it disables all non-critical ME functionality. Questioned, Intel responded:

> In response to requests from customers with specialized requirements we sometimes explore the modification or disabling of certain features. In this case, the modifications were made at the request of equipment manufacturers in support of their customer’s evaluation of the US government’s “High Assurance Platform” program. These modifications underwent a limited validation cycle and are not an officially supported configuration.

Re: Disabling Intel ME 11 via undocumented mode

#8

If ME is not a backdoor then why doesn't Intel allow to disable it? Why don't they publish detailed descriptions? Why don't they allow user to run their programs on ME CPU?

Where is the suggestion that Intel ME isn't a backdoor? The article states:

> In this article, we describe how we discovered this undocumented mode and how it is connected with the U.S. government's High Assurance Platform (HAP) program.

> Googling did not take long. The second search result said that the name belongs to a trusted platform program linked to the U.S. National Security Agency (NSA).

>We believe that this mechanism is designed to meet a typical requirement of government agencies, which want to reduce the possibility of side-channel leaks. But the main question remains: how does HAP affect Boot Guard? Due to the closed nature of this technology, it is not possible to answer this question yet, but we hope to do so soon.

Post reply on HN