Live data from Hacker News

Disabling Intel ME 11 via undocumented mode

blog.ptsecurity.com

91–100 of 228 posts

Re: Disabling Intel ME 11 via undocumented mode

#91
post #66

Impressive work on reverse engineering this. Am I correct in assuming that since this backdoor chip has access to all of the peripheral I/O that it could even be used on a device with onboard wireless in "power off" mode, which is usually some kind of low-level sleep? So a compromise of this subsystem (or intentional backdoor) would allow one to take control of even a device that is "off". Given the trend to non-remo…

a Faraday cage laptop bag is probably a less drastic solution.

Re: Disabling Intel ME 11 via undocumented mode

#92

TL;DR: Intel put a special High Assurance Platform (HAP) mode in ME for the US government. If toggled on, it disables all non-critical ME functionality. Questioned, Intel responded: > In response to requests from customers with specialized requirements we sometimes explore the modification or disabling of certain features. In this case, the modifications were made at the request of equipment manufacturers in support…

Historically, high-assurance security used a mix of commodity and custom hardware. SCOMP had IO/MMU plus type enforcement at memory & storage level. Congress mandated use of commercial off-the-shelf which forced ports to insecure architectures. Aesec's GEMSOS, one of first security kernels, did some kind of custom firmware when ported to x86. Paul Karger, one of INFOSEC's founders, decided on VMM's for easier security & legacy compatibility with modifications to PALcode. Many products, like INTEGRITY-178B, targeted PowerPC to get better hardware with cross-selling to aerospace. General Dynamics with NSA modified Intel stuff with misnamed HAP (Linux + VMware aint high assurance). Others are doing custom CPU's and firmware designed for security whereas Joshua Edmison made attachment that reuses high-performing CPU's.

So, there's a long history in high-assurance security of securing each layer. Mainstream security ignored it as usual until recently focusing on that stuff. Many smart folks among them are trying to secure software on backdoored CPU's while others (eg Raptor POWER, Cambridge CHERI) are trying to give us non-backdoored systems. At one point, I knew most of the latter since so few are working on that angle. Rarely fix root cause over tactical mitigations.

Re: Disabling Intel ME 11 via undocumented mode

#93

This is why I support Power/MIPS/RISC development going forward. It's just a shame that we allowed intel and amd to both put in cpu backdoors at such an obvious level (I like x86 but it's not the cpu of the future unless it's open). I highly suspect some national security letter type shit is going on in the background, ala Promis and William A. Hamilton who has claimed on Bruce Schneiers blog they (intel agencies) we…

They added it for business reasons for remote monitoring and control since enterprises like it. That's a large part of their sales. It also had consumer benefits. Related tech also helped DRM machines through Trusted Computing alliance. And they probably got defense contracts or payments for selective use by NSA or other organizations. Lots of return on that investment. Lots of reasons unrelated to those you mention.

>remote monitoring and control

There are opensource ways to do out of band management without it.

>consumer benefits. Related tech also helped DRM machines through Trusted Computing alliance.

Nobody I knew who was knowledgeable wanted that shit in the first place. It was always edging away consumer control of the platform. DRM is part of the problem here! Same thing with web standards. What annoys me the most about this is the audacity of calling it "consumer benefits".

>probably got defense contracts or payments for selective use by NSA or other organizations

Fine, but that's not a good enough reason to backdoor literally everything for everyone else. (reminds me of systemd and redhat actually)

Re: Disabling Intel ME 11 via undocumented mode

#94
post #78
post #54

Earlier quoted context omitted.

basically govt finally learned about ME (like VNC built into CPU) and said "what?! are you kidding!?" and on second breath - "keep it on for everybody else though!"

ME isn't like VNC built into the CPU - that's AMT. AMT is restricted to higher-end Intel platforms, but ME is everywhere.

https://en.wikipedia.org/wiki/Intel_Active_Management_Techno... :

>AMT is part of the Intel Management Engine, which is built into PCs with Intel vPro technology.

>Currently, AMT is available in desktops, servers, ultrabooks, tablets, and laptops with Intel Core vPro processor family, including Intel Core i3, i5, i7, and Intel Xeon processor E3-1200 product family.

Re: Disabling Intel ME 11 via undocumented mode

#95

This is why I support Power/MIPS/RISC development going forward. It's just a shame that we allowed intel and amd to both put in cpu backdoors at such an obvious level (I like x86 but it's not the cpu of the future unless it's open). I highly suspect some national security letter type shit is going on in the background, ala Promis and William A. Hamilton who has claimed on Bruce Schneiers blog they (intel agencies) we…

I got a mail from a company doing power9 boards (something eagle ??). A bit pricey but it seems worth it if you have such needs.

Re: Disabling Intel ME 11 via undocumented mode

#96
post #94
post #78

Earlier quoted context omitted.

ME isn't like VNC built into the CPU - that's AMT. AMT is restricted to higher-end Intel platforms, but ME is everywhere.

https://en.wikipedia.org/wiki/Intel_Active_Management_Techno... : >AMT is part of the Intel Management Engine, which is built into PCs with Intel vPro technology. >Currently, AMT is available in desktops, servers, ultrabooks, tablets, and laptops with Intel Core vPro processor family, including Intel Core i3, i5, i7, and Intel Xeon processor E3-1200 product family.

AMT is a piece of software that runs on the Management Engine. vPro-enabled platforms are the ones aimed at business laptops and workstations, not consumer stuff. It's important to make the distinction because people can check, find that their machine doesn't have the VNC functionality and then assume that they don't have anything to worry about as far as the ME goes, which is a false sense of security.

Re: Disabling Intel ME 11 via undocumented mode

#97
post #96
post #94

Earlier quoted context omitted.

https://en.wikipedia.org/wiki/Intel_Active_Management_Techno... : >AMT is part of the Intel Management Engine, which is built into PCs with Intel vPro technology. >Currently, AMT is available in desktops, servers, ultrabooks, tablets, and laptops with Intel Core vPro processor family, including Intel Core i3, i5, i7, and Intel Xeon processor E3-1200 product family.

AMT is a piece of software that runs on the Management Engine. vPro-enabled platforms are the ones aimed at business laptops and workstations, not consumer stuff. It's important to make the distinction because people can check, find that their machine doesn't have the VNC functionality and then assume that they don't have anything to worry about as far as the ME goes, which is a false sense of security.

i don't think you described the behavior of typical HN reader :) Anyway, vPro with VNC seems to be present on all consumer (ie. with IGP) CPUs, so there is nothing to worry about in the sense that one anyway can't do anything about it, and thus the worrying is futile.

Re: Disabling Intel ME 11 via undocumented mode

#98

If ME is not a backdoor then why doesn't Intel allow to disable it? Why don't they publish detailed descriptions? Why don't they allow user to run their programs on ME CPU?

If ME isn't a backdoor why did Russia and China start efforts to surplant Intel with locally sourced processors (even before US embargo'd Intel from china)

Why wouldn't they? It seems like Westerners believe in comparative advantage to the point they can't imagine wanting local competitors to other countries' most successful monopolies.

Re: Disabling Intel ME 11 via undocumented mode

#99

I wonder if Apple is ok with this. They usually don't like someone's else software running on their machines, especially on such a low level. They will probably negotiate a kill switch for them too.

>I wonder if Apple is ok with this.

https://www.theguardian.com/world/2013/jun/06/us-tech-giants...

Oct 2012. Never forget.

Re: Disabling Intel ME 11 via undocumented mode

#100

The more details leak about ME the more shocking it becomes. Why is this accepted in any free democratic society? There can be discussions, there can be debates but in everyday life this is already accepted. And even if one does not want to accept it what are the choices given similar technology is now integrated in other processors? If we accept that computers are essential to operate in modern society then this is…

> And even if one does not want to accept it what are the choices given similar technology is now integrated in other processors?

Unfortunately, there are few, but alternatives are being pursued by a few different groups which you can support in various ways. In rough ascending order of time horizon:

- Minifree sell old ThinkPads, with old processors which predate the ME, and use Libeboot[0]

- Purism use new processors, but do their best to neuter the ME, by buying processors with minimal remote control features, stopping the ME from being able to control the networking card, using and running Coreboot. They're working to use me_cleaner to completely neutralize the ME on new processors, but there's lots of work to do to fix bugs caused (e.g.[1]). I think they'll get there in the end![2]

- Raptor Engineering are trying to fund a run of fully open POWER processors (less powerful cores, but loads of them). Avoids Intel altogether. Very large upfront costs.

- The RISC-V team at Berkeley are working on a new instruction set. Years before you can buy anything, but I'm sure there's a way to send them beer money, or apply to work there![4]

None of these is projects is ideal, but by supporting them you're enabling people who care to keep working on the this problem.

[0]: https://minifree.org/

[1]: https://puri.sm/posts/neutralizing-intel-management-engine-o...

[2]: https://puri.sm/

[3]: https://www.raptorcs.com/TALOSII/

[4]: https://en.wikipedia.org/wiki/RISC-V

Post reply on HN