Live data from Hacker News

Disabling Intel ME 11 via undocumented mode

blog.ptsecurity.com

151–160 of 228 posts

Re: Disabling Intel ME 11 via undocumented mode

#151

I wonder if Apple is ok with this. They usually don't like someone's else software running on their machines, especially on such a low level. They will probably negotiate a kill switch for them too.

i've heard the ME is not enabled in macs. for technical/architectural reasons. somebody please enlighten me if that is true.

Re: Disabling Intel ME 11 via undocumented mode

#153

Earlier quoted context omitted.

If some other CPU architecture were the dominant PC platform, do you think it wouldn't grow such features too? It's not hard to imagine an alternate universe in which we all have RISC workstations with the equivalent of ME, and Intel/AMD are the minorities who have more "open" CPUs without, but only because they hadn't grown enough. The underlying reason why ME became popular is the same reason why proprietary walled…

> The underlying reason why ME became popular ... ... is also because it provides management features that are wanted by enterprise customers. If you're running hundreds of servers in a data center, the more management you can do remotely, without visiting the machine room and preferably automated as much as possible, the better. This is quite irrelevant and even undesirable for an individual's personal computer.

While enterprise customers might want remote control they also would like to be able to disable it.

Re: Disabling Intel ME 11 via undocumented mode

#154
post #90

Earlier quoted context omitted.

Likely to do with the EURion constellation: https://en.wikipedia.org/wiki/EURion_constellation Another item of interest may be printer stenography, in which every piece of printed paper, seemingly from every printer, can be traced back to make, model and potentially even the unit used to print it: https://en.wikipedia.org/wiki/Printer_steganography

I'm one of the most paranoid people you're ever likely to meet. (People more paranoid than I am won't communicate online.) Printer stenography is just beyond the limit I set for myself to try to disbelieve, and yet, here it is. (Meaning that I always assumed something like this was going on, because that's what I would do , but I try to disbelieve it so as to be able to act normal. I believe all phones are continuall…

i feel you, mate. even more troubling for me is that ppl, including snowden, believe he changed things. well, more ppl use encryption. but the vast majority doesnt even know. ppl are still too stupid to grasp the concept of privacy and freedom. its just some pretty words. like "i want my children to have better future" and off they go posting pictures of them on facebook.

Re: Disabling Intel ME 11 via undocumented mode

#155

This is why I support Power/MIPS/RISC development going forward. It's just a shame that we allowed intel and amd to both put in cpu backdoors at such an obvious level (I like x86 but it's not the cpu of the future unless it's open). I highly suspect some national security letter type shit is going on in the background, ala Promis and William A. Hamilton who has claimed on Bruce Schneiers blog they (intel agencies) we…

If some other CPU architecture were the dominant PC platform, do you think it wouldn't grow such features too? It's not hard to imagine an alternate universe in which we all have RISC workstations with the equivalent of ME, and Intel/AMD are the minorities who have more "open" CPUs without, but only because they hadn't grown enough. The underlying reason why ME became popular is the same reason why proprietary walled…

The pinebook (aarch64 machine) has an opensparc1000 in exactly the same capacity as the intel ME. The firmware blob is out and people have poked at it, but the functionality has yet to be reproduced in open software.

Re: Disabling Intel ME 11 via undocumented mode

#156

Are there any good open computers?

I think that depends on what you mean by good and computer. You might, for example, want something that costs on the same order of magnitude as an Intel or AMD x86_64-bit cpu. Afaik the answer to that question then becomes no.

There's some hope around power9-based systems:

https://www.raptorcs.com/TALOSII/

For more modest demands on performance, and affordability , there's LEON and OpenSPARC.

Re: Disabling Intel ME 11 via undocumented mode

#157
post #58

Earlier quoted context omitted.

Intel ME is not an effective DRM scheme. You need to be exceptionally careful when you mention DRM, because if it becomes commonly believed that Intel ME could be used to implement DRM all of a sudden the DMCA comes into play. Research into Intel ME vulnerabilities becomes a federal crime.

It's only a federal crime in the US ... aren't these guys in the UK?

All signatories to WIPO have DMCA-like laws (including the "effective anti-circumvention" clauses). All countries with "modern" copyright laws are signatories to WIPO, so I would not put money on it being legal in the UK.

Re: Disabling Intel ME 11 via undocumented mode

#158
post #122

Nonetheless, our research team (Dmitry Sklyarov, Mark Ermolov, and Maxim Goryachy) Dmitry Sklyarov! There's a name I haven't seen in a while... good to see he's still actively doing this stuff. The immense complexity of the base firmware and hardware in a modern system is astonishing. XML, MINIX, and three(!) complete 486 cores in the PCH. Given this amazing feat of engineering, and the goals of the ME, it makes me w…

In my experience firmware is developed by an underclass who are happy to have any decent-paying job at all. Or maybe the people who work on the ME realize that it's far from the largest risk in the system.

that's pretty funny ;) what sort of firmware development do you have experience with? I imagine there must be a huge array of types out there.

Re: Disabling Intel ME 11 via undocumented mode

#159

This is why I support Power/MIPS/RISC development going forward. It's just a shame that we allowed intel and amd to both put in cpu backdoors at such an obvious level (I like x86 but it's not the cpu of the future unless it's open). I highly suspect some national security letter type shit is going on in the background, ala Promis and William A. Hamilton who has claimed on Bruce Schneiers blog they (intel agencies) we…

I’m not sure where you got the idea that such things only exist on x86 and shame Intel and AMD for a feature that’s useful for many scenarios. Have you considered the fact that such features exist because there are actually many customers that want it? I was literally using the counterpart of ME on Power today. These tools are essential to many enterprise workloads, especially when you are in Boston and your data center is in Chicago. I wouldn’t write a useful feature off as a conspiracy for surveillance just like that.

Re: Disabling Intel ME 11 via undocumented mode

#160

This is why I support Power/MIPS/RISC development going forward. It's just a shame that we allowed intel and amd to both put in cpu backdoors at such an obvious level (I like x86 but it's not the cpu of the future unless it's open). I highly suspect some national security letter type shit is going on in the background, ala Promis and William A. Hamilton who has claimed on Bruce Schneiers blog they (intel agencies) we…

This is why Russia makes their own chips in their own fabs for defense applications. [1] 1. https://en.m.wikipedia.org/wiki/MCST

They're actually fabbed by TSMC. MCST is fabless, not an IDM.
Post reply on HN