Live data from Hacker News

Disabling Intel ME 11 via undocumented mode

blog.ptsecurity.com

71–80 of 228 posts

Re: Disabling Intel ME 11 via undocumented mode

#71
post #11

Earlier quoted context omitted.

If ME isn't a backdoor why did Russia and China start efforts to surplant Intel with locally sourced processors (even before US embargo'd Intel from china)

>even before US embargo'd Intel from china You can see how well this embargo works in every electronics mall

>> even before US embargo'd Intel from china

> You can see how well this embargo works in every electronics mall

IIRC, the embargo was only against very specific processors used in a specific supercomputer design.

Re: Disabling Intel ME 11 via undocumented mode

#72
post #69

Could somebody explain in layman terms what exactly (say, 'spy-wise') ME could enable some parties to (remotely?) do with one's pc? And what are the chances this actually is being done?

They could put in a backdoor that opens when a magic packet is passed. These things exist[1]. Your cell phone likely has one in the radio[2]. The problem with this existing, other than the privacy issues, is that the packet can eventually be discovered by fuzzing[3] the hardware.

[1]https://github.com/elvanderb/TCP-32764

[2]https://www.contextis.com/resources/blog/binary-sms-old-back...

[3]https://www.owasp.org/index.php/Fuzzing

Re: Disabling Intel ME 11 via undocumented mode

#73
post #58

Earlier quoted context omitted.

It can be useful for other purposes too, for example for enforcing DRM so that DRM code runs on a ME engine. And of course DRM code can be backdoored too so playing a specially crafted video would run code from it.

Intel ME is not an effective DRM scheme. You need to be exceptionally careful when you mention DRM, because if it becomes commonly believed that Intel ME could be used to implement DRM all of a sudden the DMCA comes into play. Research into Intel ME vulnerabilities becomes a federal crime.

> because if it becomes commonly believed that Intel ME could be used to implement DRM all of a sudden the DMCA comes into play

It is already common knowledge that the ME is used to implement DRM.

The DRM functionality of the ME has been discussed in several books. [0] The ME contains DRM functions to securely decode content (e.g. streaming video) in a way such that decoded content cannot be snooped by the host processor before it is displayed to the user (ostensibly via a secure channel like HDCP).

[0] http://www.apress.com/us/book/9781430265719

Re: Disabling Intel ME 11 via undocumented mode

#74
post #66

Impressive work on reverse engineering this. Am I correct in assuming that since this backdoor chip has access to all of the peripheral I/O that it could even be used on a device with onboard wireless in "power off" mode, which is usually some kind of low-level sleep? So a compromise of this subsystem (or intentional backdoor) would allow one to take control of even a device that is "off". Given the trend to non-remo…

Yes, that's correct.

Re: Disabling Intel ME 11 via undocumented mode

#75
post #46
post #34

Earlier quoted context omitted.

They aren't going to: https://news.ycombinator.com/item?id=14803373

This makes one wonder if there is a secret legal requirement for this kind of capability.

Years and years ago, when color printer/scanners were fairly new, I tried to scan and print a $5 dollar bill. I was curious. The machine printed out about a third of the image but the rest of what it printed was a very official looking notice to please call the US Treasury.

(edit: HP was the manufacturer.)

Re: Disabling Intel ME 11 via undocumented mode

#76

I wonder if Apple is ok with this. They usually don't like someone's else software running on their machines, especially on such a low level. They will probably negotiate a kill switch for them too.

They'll build their own, presumably. The decision they made almost 10 years ago to bring the PA Semi designers in-house is looking better every day.

The iOS devices don't use Intel chips and the Macs don't really need to.

Re: Disabling Intel ME 11 via undocumented mode

#77
This is why I support Power/MIPS/RISC development going forward. It's just a shame that we allowed intel and amd to both put in cpu backdoors at such an obvious level (I like x86 but it's not the cpu of the future unless it's open). I highly suspect some national security letter type shit is going on in the background, ala Promis and William A. Hamilton who has claimed on Bruce Schneiers blog they (intel agencies) were infiltrating even low level chip manufacturers. Danny Casalaro's death was likely a required nastyness to keep it covered up.

Re: Disabling Intel ME 11 via undocumented mode

#78
post #54

TL;DR: Intel put a special High Assurance Platform (HAP) mode in ME for the US government. If toggled on, it disables all non-critical ME functionality. Questioned, Intel responded: > In response to requests from customers with specialized requirements we sometimes explore the modification or disabling of certain features. In this case, the modifications were made at the request of equipment manufacturers in support…

basically govt finally learned about ME (like VNC built into CPU) and said "what?! are you kidding!?" and on second breath - "keep it on for everybody else though!"

ME isn't like VNC built into the CPU - that's AMT. AMT is restricted to higher-end Intel platforms, but ME is everywhere.

Re: Disabling Intel ME 11 via undocumented mode

#79

This is why I support Power/MIPS/RISC development going forward. It's just a shame that we allowed intel and amd to both put in cpu backdoors at such an obvious level (I like x86 but it's not the cpu of the future unless it's open). I highly suspect some national security letter type shit is going on in the background, ala Promis and William A. Hamilton who has claimed on Bruce Schneiers blog they (intel agencies) we…

They added it for business reasons for remote monitoring and control since enterprises like it. That's a large part of their sales. It also had consumer benefits. Related tech also helped DRM machines through Trusted Computing alliance. And they probably got defense contracts or payments for selective use by NSA or other organizations.

Lots of return on that investment. Lots of reasons unrelated to those you mention.

Re: Disabling Intel ME 11 via undocumented mode

#80

I wonder if Apple is ok with this. They usually don't like someone's else software running on their machines, especially on such a low level. They will probably negotiate a kill switch for them too.

They've been shipping hardware with an ME for a decade, so they can't be too upset.
Post reply on HN