Live data from Hacker News

Disabling Intel ME 11 via undocumented mode

blog.ptsecurity.com

31–40 of 228 posts

Re: Disabling Intel ME 11 via undocumented mode

#32
post #26

So if i understand correctly, the way to disable intel me is to simply flip a bit? Using a software tool?

Thw article also mentions removing some non critical binaries and modifying the ME filesystem

My understanding is this step isn't really a necessity but rather was done to prove that ME could be disabled at an extremely low level since the missing binaries would no longer trigger what's effectively a failure condition.

Could be wrong. Probably safer to just set the killbit rather than also tamper with ME directly is ultimately my point. That's my risk aversion at work.

Re: Disabling Intel ME 11 via undocumented mode

#33

Does AMD have anything like Intel ME on their chipsets? I recently completed a Ryzen build and am curious.

Yes, they do https://libreboot.org/faq.html#amd. They even said recently that they are not planing to letting you disable it/remove it/share the source of it https://news.ycombinator.com/item?id=14803373.

Ironically enough, using an Intel processor with ME cleaner is more free than using an AMD processor.

Re: Disabling Intel ME 11 via undocumented mode

#34

Does AMD have anything like Intel ME on their chipsets? I recently completed a Ryzen build and am curious.

Yes, the AMD Platform Security Professor. The CEO said in a Reddit AMA they would look into open sourcing it.

They aren't going to:

https://news.ycombinator.com/item?id=14803373

Re: Disabling Intel ME 11 via undocumented mode

#35

If ME is not a backdoor then why doesn't Intel allow to disable it? Why don't they publish detailed descriptions? Why don't they allow user to run their programs on ME CPU?

Where is the suggestion that Intel ME isn't a backdoor? The article states: > In this article, we describe how we discovered this undocumented mode and how it is connected with the U.S. government's High Assurance Platform (HAP) program. > Googling did not take long. The second search result said that the name belongs to a trusted platform program linked to the U.S. National Security Agency (NSA). >We believe that th…

> We believe that this mechanism is designed to meet a typical requirement of government agencies, which want to reduce the possibility of side-channel leaks.

Interesting that Intel will provide this to the US government for enough money, but wouldn't offer it as an additional $50 or $100 option for end-customers to disable the ME.

I think there are probably enough privacy conscious people who would be willing to buy a Skylake or newer platform from Intel if they could easily disable the non-BUP components of the ME for a reasonable fee.

Re: Disabling Intel ME 11 via undocumented mode

#36
This is something I always have been wondering about. I can't imagine the US government is happy having the ME in every computer, with a closed source operating system running that has complete access to CPU, memory and network. If anybody can call Intel and ask for a custom version without this stuff, it is the government. And it looks like they did.

(If any important Silicon Valley CEO reads this, why don't you give Intel a call, as an important customer, and ask why 1) you can't disable the ME and 2) for a written guarantee that there is no backdoor in the ME?)

Something else: does anybody know if the trick mentioned in the article has negative side effects? Does power management still work? Can we be sure that this doesn't activate a backdoor to begin with, and the computer tries to connect to an NSA domain :-) ?

Re: Disabling Intel ME 11 via undocumented mode

#37

Imagine if some non-US government voided Intel and AMD's patents as a self-defence measure against these probably-backdoored 'features'. Why should they protect the profits of hostile corporations?

because they are paid to protect those profits with those profits, and you sheep are too feeble to do anything about it.

you're all idiots.

Re: Disabling Intel ME 11 via undocumented mode

#38

Earlier quoted context omitted.

Intel's response to the authors kind of explains it: they added this feature hastily to meet specific requirements of the HAP program and didn't fully validate it – so it's not supported.

You missed the point. It was added for people with big money. I promise you - it is supported. Just not for you. You need to be backdoorable. They don't

ME itself was added for people with big money.

I'm not an engineer experienced in this kind of work, but I fail to see how a company whose core business is manufacturing chips would develop an entire computer (comprising an x86 CPU, its own RAM, MINIX OS, and access to all kinds of I/O) hidden inside each one of their chips and made largely inaccessible to regular users and developers. Unless they are paid very well to do so.

In retrospect they were kind of naive not to make it much harder to enable this HAP mode, considering the lengths they went to make ME tamper proof. They left the flag wide open and even commented it in an XML file.

Re: Disabling Intel ME 11 via undocumented mode

#39

This is something I always have been wondering about. I can't imagine the US government is happy having the ME in every computer, with a closed source operating system running that has complete access to CPU, memory and network. If anybody can call Intel and ask for a custom version without this stuff, it is the government. And it looks like they did. (If any important Silicon Valley CEO reads this, why don't you giv…

Considering that they left the HAP flag in the open and even commented it in an XML file; considering how it does not disable all of ME, but only certain bits; and contrasting it with the otherwise inscrutable, encrypted, and tamper-proof nature of ME, it's hard not to see it as a honeypot or bait.

Re: Disabling Intel ME 11 via undocumented mode

#40

Earlier quoted context omitted.

Where is the suggestion that Intel ME isn't a backdoor? The article states: > In this article, we describe how we discovered this undocumented mode and how it is connected with the U.S. government's High Assurance Platform (HAP) program. > Googling did not take long. The second search result said that the name belongs to a trusted platform program linked to the U.S. National Security Agency (NSA). >We believe that th…

> We believe that this mechanism is designed to meet a typical requirement of government agencies, which want to reduce the possibility of side-channel leaks. Interesting that Intel will provide this to the US government for enough money, but wouldn't offer it as an additional $50 or $100 option for end-customers to disable the ME. I think there are probably enough privacy conscious people who would be willing to buy…

$50 or $100 for turning off the spyware in my own CPU is hardly reasonable.
Post reply on HN