Live data from Hacker News

Disabling Intel ME 11 via undocumented mode

blog.ptsecurity.com

111–120 of 228 posts

Re: Disabling Intel ME 11 via undocumented mode

#111
post #23
post #22

Earlier quoted context omitted.

That is pretty much standard term for processor features that are not supported by Intel. The main selling point of the whole Intel's x86 platform is that when something is supported and documented it will either behave the same way on newewr processors or newer processors would include some mechanism to emulate the old behavior. Intel tends to go especially overboard with this approach and even support feature combi…

Just to clarify: the A20 stuff was an IBM PC/AT feature in the chipset of the original machine, not a CPU thing. It was actually a response to an Intel mistake in backward compatibility between the 8086 and 286 (real mode segments that pointed "beyond" the first 1MB would wrap around on the original processor but hit the second megabyte on the 286). But when the memory mapping went on-chip in later devices, it needed…

> Just to clarify: the A20 stuff was an IBM PC/AT feature in the chipset of the original machine, not a CPU thing.

To quote https://en.wikipedia.org/w/index.php?title=A20_line&oldid=79...

"Support for the A20 gate was changed in the Nehalem microarchitecture (some sources incorrectly claim A20 support was removed). Rather than the CPU having a dedicated A20M# pin which receives the signal whether or not to mask the A20 bit, it has been virtualized so that the information is sent from the peripheral hardware to the CPU using special bus cycles."

So it is now a CPU thing.

Re: Disabling Intel ME 11 via undocumented mode

#112
post #84

Earlier quoted context omitted.

Ehh, SPARC was a great architecture for ancient process nodes, but doesn't really line up with today's needs IMO.

Why not?

Because the IP is too freely available for any one company to engage in the rent-seeking behavior the US is so fond of.

Re: Disabling Intel ME 11 via undocumented mode

#113

This is why I support Power/MIPS/RISC development going forward. It's just a shame that we allowed intel and amd to both put in cpu backdoors at such an obvious level (I like x86 but it's not the cpu of the future unless it's open). I highly suspect some national security letter type shit is going on in the background, ala Promis and William A. Hamilton who has claimed on Bruce Schneiers blog they (intel agencies) we…

If some other CPU architecture were the dominant PC platform, do you think it wouldn't grow such features too?

It's not hard to imagine an alternate universe in which we all have RISC workstations with the equivalent of ME, and Intel/AMD are the minorities who have more "open" CPUs without, but only because they hadn't grown enough.

The underlying reason why ME became popular is the same reason why proprietary walled gardens became popular: because they are heavily promoted as a security/safety feature, and "who doesn't want to be safe and secure?"

Remember that, shortly before the turn of the century, Intel was convinced by the masses to remove a feature that would seem almost innocuous today, a serial number, but only because they marketed it as for DRM/identification instead of a security feature:

https://www.wired.com/1999/01/intel-on-privacy-whoops/

Re: Disabling Intel ME 11 via undocumented mode

#114

What I consider as "interesting" is the fact that much more research (at least if you look at HN headlines/posts) goes into "Intel ME" vs. "AMD Secure Processor" (formerly known as "AMD PSP" ("Platform Security Processor")). I really don't want to badmouth this important research on "Intel ME", but I am a little bit confused from this asymmetry.

Perhaps this is because Intel ME is deployed much more widely than AMD PSP.

Re: Disabling Intel ME 11 via undocumented mode

#115
post #83
post #64

Earlier quoted context omitted.

For the same reason the government requires chips made in the US for Classified uses. If a fab is in another country there is always the possibility that the design could be compromised. Even shipping chips internationally can cause this concern as the chips can be swapped out. This isn't exactly a new concept... Russia did this to the US embassy a long while back http://www.cryptomuseum.com/covert/bugs/selectric/

So what chips does the US government use for classified purposes?

Mostly the same chips everybody else does, but made in a special purpose fab in the US. This extends to everything in a computer (even firmware etc.). This means that a computer for use in classified settings is a LOT more expensive than your average desktop.

Re: Disabling Intel ME 11 via undocumented mode

#116
post #83
post #64

Earlier quoted context omitted.

For the same reason the government requires chips made in the US for Classified uses. If a fab is in another country there is always the possibility that the design could be compromised. Even shipping chips internationally can cause this concern as the chips can be swapped out. This isn't exactly a new concept... Russia did this to the US embassy a long while back http://www.cryptomuseum.com/covert/bugs/selectric/

So what chips does the US government use for classified purposes?

Given the Intel ME has a High Assurance Program mode in it... probably Intel chips?

Re: Disabling Intel ME 11 via undocumented mode

#117
post #83
post #64

Earlier quoted context omitted.

For the same reason the government requires chips made in the US for Classified uses. If a fab is in another country there is always the possibility that the design could be compromised. Even shipping chips internationally can cause this concern as the chips can be swapped out. This isn't exactly a new concept... Russia did this to the US embassy a long while back http://www.cryptomuseum.com/covert/bugs/selectric/

So what chips does the US government use for classified purposes?

We know that Amazon had Intel create custom chips specially for them, like the E5-2666 v3. So of course Uncle Sam have their own top secret bespoke Intel SKUs.

Re: Disabling Intel ME 11 via undocumented mode

#118
post #66

Impressive work on reverse engineering this. Am I correct in assuming that since this backdoor chip has access to all of the peripheral I/O that it could even be used on a device with onboard wireless in "power off" mode, which is usually some kind of low-level sleep? So a compromise of this subsystem (or intentional backdoor) would allow one to take control of even a device that is "off". Given the trend to non-remo…

a Faraday cage laptop bag is probably a less drastic solution.

I think if you're at that point, a laptop is a luxury you can't really afford.

Re: Disabling Intel ME 11 via undocumented mode

#119
post #66

Impressive work on reverse engineering this. Am I correct in assuming that since this backdoor chip has access to all of the peripheral I/O that it could even be used on a device with onboard wireless in "power off" mode, which is usually some kind of low-level sleep? So a compromise of this subsystem (or intentional backdoor) would allow one to take control of even a device that is "off". Given the trend to non-remo…

Or remove the wifi chip?

don't forget the microphone, and the speakers (ultrasonic exfiltration) and the display (ISTR a fairly reproducable van eck attack in the last few years?) and the cpu (various research on elliptic curve extraction by monitoring CPU power draw using off the shelf SDR equipment)
Post reply on HN