Disabling Intel ME 11 via undocumented mode
51–60 of 228 posts
Re: Disabling Intel ME 11 via undocumented mode
#52Earlier quoted context omitted.
>even before US embargo'd Intel from china You can see how well this embargo works in every electronics mall
It isn't a blanket sanction, just against government and computing centers. The last 3 chinese super computers have used home grown FeiTeng RISC processors which were binary compatible to Itanium, but for new models their using OpenSPARC.
Where did you get that information?
https://en.wikipedia.org/wiki/SW26010 doesn't claim any of that.
Re: Disabling Intel ME 11 via undocumented mode
#53Earlier quoted context omitted.
My understanding is this step isn't really a necessity but rather was done to prove that ME could be disabled at an extremely low level since the missing binaries would no longer trigger what's effectively a failure condition. Could be wrong. Probably safer to just set the killbit rather than also tamper with ME directly is ultimately my point. That's my risk aversion at work.
I'm simply intrigued how this bit has managed to elude so many developers and hackers over the years. It's literally an option in an intel software tool, and yet you have people who have vehemently complained about Intel ME for the past few years. I have some serious cognitive dissonance going on right now.
Re: Disabling Intel ME 11 via undocumented mode
#54TL;DR: Intel put a special High Assurance Platform (HAP) mode in ME for the US government. If toggled on, it disables all non-critical ME functionality. Questioned, Intel responded: > In response to requests from customers with specialized requirements we sometimes explore the modification or disabling of certain features. In this case, the modifications were made at the request of equipment manufacturers in support…
Re: Disabling Intel ME 11 via undocumented mode
#55Earlier quoted context omitted.
The mistake was with the fact, that 8086 has 64kB-16B worth of user visible memory addresses that are beyond what the harware could actually address due to width of the physical address bus and thus got aliased to the other end of address space. People say that there was software that depended on this behavior, but I can't see any sane reason why somebody would write something like that (given how the address layout…
You're arguing semantics. Pulling the cache on-chip means that the memory bus and its mapping logic needs to be on-chip too, because it sits beneath the cache. We're saying exactly the same thing. (And FWIW: the mistake Intel made was that those accesses were legal on an 8086. They should have been an exception condition, which would have avoided this problem by making the 286 behavior a proper superset)
In hindsight, making accesses beyond the end of physical memory on 8086 an exception is nice solution. But I think that more useful solution would be different design of the 8086 pseudo-segmentation that would make such linear adresses unrepresentable on the user level. On the other hand whether this would be good idea depends on whether you view another horrible cludge (ie. HMA/UMB and potentially also usage of that as EMS window or bounce buffer) as useful.
Edit: as for the memory attached to processor behaving sanely it is interesting to look at Alpha which expects that memory is memory and could be write back cached. With one small and significant exception: the region on which ISA VGA would exist is hardwired to be uncacheable.
Re: Disabling Intel ME 11 via undocumented mode
#56The more details leak about ME the more shocking it becomes. Why is this accepted in any free democratic society? There can be discussions, there can be debates but in everyday life this is already accepted. And even if one does not want to accept it what are the choices given similar technology is now integrated in other processors? If we accept that computers are essential to operate in modern society then this is…
Re: Disabling Intel ME 11 via undocumented mode
#57Earlier quoted context omitted.
I'm simply intrigued how this bit has managed to elude so many developers and hackers over the years. It's literally an option in an intel software tool, and yet you have people who have vehemently complained about Intel ME for the past few years. I have some serious cognitive dissonance going on right now.
The latest version of ME, 11, uses a x86 processor. That's why the researchers were able to perform this analysis and find the bit to flip. It also doesn't disable ME, just most of it.
Re: Disabling Intel ME 11 via undocumented mode
#58Earlier quoted context omitted.
You are seeing this wrong. Intel has two reasons to have ME: 1. It is useful in business settings 2. It enables the US spy agencies complete surveillance of all PCs It's the second point that explains why they can't make it optional. And that makes business sense. That way they ensure backing from the NSA, instead of having to fight against them.
It can be useful for other purposes too, for example for enforcing DRM so that DRM code runs on a ME engine. And of course DRM code can be backdoored too so playing a specially crafted video would run code from it.
Re: Disabling Intel ME 11 via undocumented mode
#59Re: Disabling Intel ME 11 via undocumented mode
#60The more details leak about ME the more shocking it becomes. Why is this accepted in any free democratic society? There can be discussions, there can be debates but in everyday life this is already accepted. And even if one does not want to accept it what are the choices given similar technology is now integrated in other processors? If we accept that computers are essential to operate in modern society then this is…
Up until the 80s, anything you bought would, reasonably, provide schematics, diagnostic info, and at worst on request details on the original designs or how substitute parts would work in almost any mechanical system, including TVs. Phones were extraordinarily unique at the time in how proprietary they were, in that Bell Labs had a government monopoly until that decade that gave them carte blanche to not care about consumer satisfaction and let them extort people en masse both for money and never giving an inch of control in the PSTN.
Then computers happened, and they were sufficiently magical for a sufficient number of people to tip all of our society away from the autonomy to own things and know how they work towards having magical black boxes that seem to do what you want them to.
The Intel ME is just one aspect of this. Of how government will seize the opportunity to take advantage of the willful and tolerated ignorance of the people as a tool to spy on whomever they want.
This trend is also not even close to reversing. Cars made in the 90s were still fairly open, but introduced OBD computer systems that were proprietary black boxes of diagnostic info. Now, every new car is entirely computer driven, and that computer controls the whole vehicles operation in undocumented and proprietary ways. Talk to any garage that isn't a brand dealer - the newer the car, the less they can actually do to fix it.
This is applying to everything now. New tvs are now completely irreparable. Cell phones are holistically compromised and proprietary. New appliances all have proprietary computers in them. Your new house is built with proprietary computers that control the climate, the power, everything. If something breaks? You have to send it to the manufacturer I guess because you aren't allowed to know how it works or how to fix it anymore. Its "too complicated", is the excuse. Its the same excuse why the FCC is trying to cripple open source firmware on routers, or why ham radio and broadcast television are being sabotaged at every level of government.
People gave up trying to understand computers, to be able to treat them like any other machine they use - and break - in knowing how to fix them. And so governments and companies took full advantage of that yielding of knowledge and authority and now hold it over all of us as a tool of subjugation and exploitation.