Live data from Hacker News

Disabling Intel ME 11 via undocumented mode

blog.ptsecurity.com

141–150 of 228 posts

Re: Disabling Intel ME 11 via undocumented mode

#141

This is why I support Power/MIPS/RISC development going forward. It's just a shame that we allowed intel and amd to both put in cpu backdoors at such an obvious level (I like x86 but it's not the cpu of the future unless it's open). I highly suspect some national security letter type shit is going on in the background, ala Promis and William A. Hamilton who has claimed on Bruce Schneiers blog they (intel agencies) we…

If some other CPU architecture were the dominant PC platform, do you think it wouldn't grow such features too? It's not hard to imagine an alternate universe in which we all have RISC workstations with the equivalent of ME, and Intel/AMD are the minorities who have more "open" CPUs without, but only because they hadn't grown enough. The underlying reason why ME became popular is the same reason why proprietary walled…

First, because of undisclosed design and patents it is difficult for competition to compete in the x86 market.

Second, competition is exactly what we need to get rid of hardware backdoors and unwanted features. If I had the coice to buy a PC without closed firmware and hardware, I would do so. The more open, the better. We direly need competition there.

Re: Disabling Intel ME 11 via undocumented mode

#142

This is why I support Power/MIPS/RISC development going forward. It's just a shame that we allowed intel and amd to both put in cpu backdoors at such an obvious level (I like x86 but it's not the cpu of the future unless it's open). I highly suspect some national security letter type shit is going on in the background, ala Promis and William A. Hamilton who has claimed on Bruce Schneiers blog they (intel agencies) we…

This is why Russia makes their own chips in their own fabs for defense applications. [1]

1. https://en.m.wikipedia.org/wiki/MCST

Re: Disabling Intel ME 11 via undocumented mode

#144

This is why I support Power/MIPS/RISC development going forward. It's just a shame that we allowed intel and amd to both put in cpu backdoors at such an obvious level (I like x86 but it's not the cpu of the future unless it's open). I highly suspect some national security letter type shit is going on in the background, ala Promis and William A. Hamilton who has claimed on Bruce Schneiers blog they (intel agencies) we…

This is why Russia makes their own chips in their own fabs for defense applications. [1] 1. https://en.m.wikipedia.org/wiki/MCST

As do all countries with any sense.

Re: Disabling Intel ME 11 via undocumented mode

#145

Earlier quoted context omitted.

This is why Russia makes their own chips in their own fabs for defense applications. [1] 1. https://en.m.wikipedia.org/wiki/MCST

As do all countries with any sense.

And sufficient money and other resources.

I'm all for national governments making their own hardware not subject to backdoors installed by other national governments, but there's a huge difference in capability between Russia and, say, Lebanon.

Re: Disabling Intel ME 11 via undocumented mode

#146
post #122

Nonetheless, our research team (Dmitry Sklyarov, Mark Ermolov, and Maxim Goryachy) Dmitry Sklyarov! There's a name I haven't seen in a while... good to see he's still actively doing this stuff. The immense complexity of the base firmware and hardware in a modern system is astonishing. XML, MINIX, and three(!) complete 486 cores in the PCH. Given this amazing feat of engineering, and the goals of the ME, it makes me w…

In my experience firmware is developed by an underclass who are happy to have any decent-paying job at all. Or maybe the people who work on the ME realize that it's far from the largest risk in the system.

  Underclass
LOLWUT?

Firmware pays pretty damn well. If you know what you're doing.

Re: Disabling Intel ME 11 via undocumented mode

#147

Earlier quoted context omitted.

>>remote monitoring and control > There are opensource ways to do out of band management without it. I'd be surprised if there is a cost-effective open source alternative to this requirement: Remotely access and control a computer under any circumstance where it has power and a physical network connection. Solutions like AMT work even if there is no functioning processor or memory, because ME provides its own process…

Most BMCs are rather limited aren't they? They can switch power off and on, read a few sensors. ME goes well beyond that from what I gather.

That's what BMCs were like 15 years ago; they're much more sophisticated now.

Re: Disabling Intel ME 11 via undocumented mode

#148

Earlier quoted context omitted.

Intel's response to the authors kind of explains it: they added this feature hastily to meet specific requirements of the HAP program and didn't fully validate it – so it's not supported.

You missed the point. It was added for people with big money. I promise you - it is supported. Just not for you. You need to be backdoorable. They don't

> I promise you - it is supported.

For a general purpose consumer chip, "supported" generally doesn't carry the implicit caveat of:

"... if you bring your own hardware engineers, pay enough $$$ to be worth letting your hardware engineers talk to our hardware engineers, and coordinate with us so we can test your very specific hardware setup(s) instead of trying to verify compatibility with a wider range of motherboards etc."

You're of course correct that Intel is supporting it for $BIG_CUSTOMER that meets this exacting list (and likely more) of requirements. But I'd say codezero is just as correct in saying "it's not supported [for general use.]"

Re: Disabling Intel ME 11 via undocumented mode

#149
post #84

Earlier quoted context omitted.

Ehh, SPARC was a great architecture for ancient process nodes, but doesn't really line up with today's needs IMO.

Why not?

Register windows and delay slots.

These turned out to be not such a great idea.

Re: Disabling Intel ME 11 via undocumented mode

#150

This is why I support Power/MIPS/RISC development going forward. It's just a shame that we allowed intel and amd to both put in cpu backdoors at such an obvious level (I like x86 but it's not the cpu of the future unless it's open). I highly suspect some national security letter type shit is going on in the background, ala Promis and William A. Hamilton who has claimed on Bruce Schneiers blog they (intel agencies) we…

It seems to me that the alternate vendor argument does not make sense. If we do not trust Intel, then there is no reason at all to trust any of the other vendors. Intel might actually require infiltration or an order; most of your smaller chip would add backdoors for cash (and in contrast to intel, a little cash would make a huge difference in their bottom lines).
Post reply on HN