Live data from Hacker News

Disabling Intel ME 11 via undocumented mode

blog.ptsecurity.com

171–180 of 228 posts

Re: Disabling Intel ME 11 via undocumented mode

#171

Earlier quoted context omitted.

>remote monitoring and control There are opensource ways to do out of band management without it. >consumer benefits. Related tech also helped DRM machines through Trusted Computing alliance. Nobody I knew who was knowledgeable wanted that shit in the first place. It was always edging away consumer control of the platform. DRM is part of the problem here! Same thing with web standards. What annoys me the most about t…

>>remote monitoring and control > There are opensource ways to do out of band management without it. I'd be surprised if there is a cost-effective open source alternative to this requirement: Remotely access and control a computer under any circumstance where it has power and a physical network connection. Solutions like AMT work even if there is no functioning processor or memory, because ME provides its own process…

Wouldn't it just take a motherboard maker or two to find an alternative to the PCH, like Nvidia nforce or a VIA chipset. adopt something like openbmc and sell it as an open feature? No intel PCH, no Intel ME. Seems like the Linux kernel is eager to support it: https://lwn.net/Articles/683320/

What happened to 3rd parties making chipsets? Another case of Intel abusing it's monopoly?

Re: Disabling Intel ME 11 via undocumented mode

#172
What happened to 3rd party chipsets? Seems like VIA, ALi, SiS, Nvidia nForce, all stopped making them for Intel processors around 2008. If there were alternative chipsets still around, we would see more motherboard makers adopting something like openBMC with an alternative chipset and using it. No Intel PCH, no Intel ME.

Re: Disabling Intel ME 11 via undocumented mode

#173

This is why I support Power/MIPS/RISC development going forward. It's just a shame that we allowed intel and amd to both put in cpu backdoors at such an obvious level (I like x86 but it's not the cpu of the future unless it's open). I highly suspect some national security letter type shit is going on in the background, ala Promis and William A. Hamilton who has claimed on Bruce Schneiers blog they (intel agencies) we…

Speaking as a naive outside observer, I am excited with the rumors that Microsoft and Apple will be making a move toward ARM in the nearish future. I don't think ARM is the answer (dear god give us riscv) but I see it as a step in the right direction away from closed systems.

ARM chips are going to end up with management cores for the same reasons that the ME exists.

Re: Disabling Intel ME 11 via undocumented mode

#174
post #172

What happened to 3rd party chipsets? Seems like VIA, ALi, SiS, Nvidia nForce, all stopped making them for Intel processors around 2008. If there were alternative chipsets still around, we would see more motherboard makers adopting something like openBMC with an alternative chipset and using it. No Intel PCH, no Intel ME.

If there were alternative chipsets still around, we would see more motherboard makers adopting something like openBMC with an alternative chipset and using it.

No we wouldn't. All the chipsets would be subject to the same market forces and thus would converge on similar features, including the ME. Just like how 99% of x86 systems are running UEFI instead of coreboot.

Re: Disabling Intel ME 11 via undocumented mode

#175
post #171

Earlier quoted context omitted.

>>remote monitoring and control > There are opensource ways to do out of band management without it. I'd be surprised if there is a cost-effective open source alternative to this requirement: Remotely access and control a computer under any circumstance where it has power and a physical network connection. Solutions like AMT work even if there is no functioning processor or memory, because ME provides its own process…

Wouldn't it just take a motherboard maker or two to find an alternative to the PCH, like Nvidia nforce or a VIA chipset. adopt something like openbmc and sell it as an open feature? No intel PCH, no Intel ME. Seems like the Linux kernel is eager to support it: https://lwn.net/Articles/683320/ What happened to 3rd parties making chipsets? Another case of Intel abusing it's monopoly?

I'd love it. But it probably would increase the manufacturer's costs for the motherboard (including engineering, component costs, etc.), distract the organization (managers, engineers, purchasing personnel, etc. spending time on this novel tech instead of just buying Intel/AMD chipsets), reduce quality (can they really compete with Intel's engineering resources?), which increases support costs, etc. ... all for a market that unfortunately is too small to measure.

Re: Disabling Intel ME 11 via undocumented mode

#176

Earlier quoted context omitted.

If some other CPU architecture were the dominant PC platform, do you think it wouldn't grow such features too? It's not hard to imagine an alternate universe in which we all have RISC workstations with the equivalent of ME, and Intel/AMD are the minorities who have more "open" CPUs without, but only because they hadn't grown enough. The underlying reason why ME became popular is the same reason why proprietary walled…

"... because they marketed it as for DRM/identification" Scott McNealy, Sun Microsystems (1999): "You have zero privacy anyway. Get over it." https://www.wired.com/1999/01/sun-on-privacy-get-over-it/

> Millions of American consumers tell us that privacy is a grave concern to them when they are thinking about shopping online

Wow! And look where we are now. Quite the irony how things played out.

Re: Disabling Intel ME 11 via undocumented mode

#177
post #174
post #172

What happened to 3rd party chipsets? Seems like VIA, ALi, SiS, Nvidia nForce, all stopped making them for Intel processors around 2008. If there were alternative chipsets still around, we would see more motherboard makers adopting something like openBMC with an alternative chipset and using it. No Intel PCH, no Intel ME.

If there were alternative chipsets still around, we would see more motherboard makers adopting something like openBMC with an alternative chipset and using it. No we wouldn't. All the chipsets would be subject to the same market forces and thus would converge on similar features, including the ME. Just like how 99% of x86 systems are running UEFI instead of coreboot.

That is not an apples to apples comparison. Plenty of features differ from motherboard to motherboard. Someone like an ASUS could adopt openbmc much easier if an alternative chipset existed. I'm not arguing about the marketability of openbmc, I know it exists. I'm talking about why there are no chipset alternatives to Intel PCH that would force Intel ME on us.

Re: Disabling Intel ME 11 via undocumented mode

#178
post #30

Earlier quoted context omitted.

Search for "AMD PSP".

> Search for "AMD PSP". To quote https://news.ycombinator.com/item?id=14803645 "AMD seems not to use the brand name "AMD PSP" anymore. Instead some years ago they began to use the name "AMD Secure Processor". Nevertheless it is just the same: Read the small footnote at http://www.amd.com/en-gb/innovations/software-technologies/s... which begins with 'AMD Secure Processor (formerly “Platform Security Processor” or “PS…

Thank you

Re: Disabling Intel ME 11 via undocumented mode

#179
post #151

I wonder if Apple is ok with this. They usually don't like someone's else software running on their machines, especially on such a low level. They will probably negotiate a kill switch for them too.

i've heard the ME is not enabled in macs. for technical/architectural reasons. somebody please enlighten me if that is true.

I've heard that ME can't communicate over a non Intel WiFi or Ethernet chip-set. Possibly related?
Post reply on HN