Disabling Intel ME 11 via undocumented mode
blog.ptsecurity.com
Disabling Intel ME 11 via undocumented mode
1–10 of 228 posts
Re: Disabling Intel ME 11 via undocumented mode
#2Re: Disabling Intel ME 11 via undocumented mode
#3Rather than assume anything nefarious on the part of the USG, I'm willing to bet a buck that someone in the USG asked the right questions during contract negotiation, which is why this kill switch was added but not publicized to anyone outside participants in the HAP Program.
Re: Disabling Intel ME 11 via undocumented mode
#4Re: Disabling Intel ME 11 via undocumented mode
#5Re: Disabling Intel ME 11 via undocumented mode
#6If ME is not a backdoor then why doesn't Intel allow to disable it? Why don't they publish detailed descriptions? Why don't they allow user to run their programs on ME CPU?
Re: Disabling Intel ME 11 via undocumented mode
#7> In response to requests from customers with specialized requirements we sometimes explore the modification or disabling of certain features. In this case, the modifications were made at the request of equipment manufacturers in support of their customer’s evaluation of the US government’s “High Assurance Platform” program. These modifications underwent a limited validation cycle and are not an officially supported configuration.
Re: Disabling Intel ME 11 via undocumented mode
#8If ME is not a backdoor then why doesn't Intel allow to disable it? Why don't they publish detailed descriptions? Why don't they allow user to run their programs on ME CPU?
> In this article, we describe how we discovered this undocumented mode and how it is connected with the U.S. government's High Assurance Platform (HAP) program.
> Googling did not take long. The second search result said that the name belongs to a trusted platform program linked to the U.S. National Security Agency (NSA).
>We believe that this mechanism is designed to meet a typical requirement of government agencies, which want to reduce the possibility of side-channel leaks. But the main question remains: how does HAP affect Boot Guard? Due to the closed nature of this technology, it is not possible to answer this question yet, but we hope to do so soon.
Re: Disabling Intel ME 11 via undocumented mode
#9Re: Disabling Intel ME 11 via undocumented mode
#10The interesting question here is: why undocumented. It was created on request, but nobody was told. Who pushed so hard ME to be on for everything but them? And why? We know the answer :)