Live data from Hacker News

Disabling Intel ME 11 via undocumented mode

blog.ptsecurity.com

211–220 of 228 posts

Re: Disabling Intel ME 11 via undocumented mode

#211
post #143

Such blatant security holes are why Google resorts to measures like this: https://cloudplatform.googleblog.com/2017/08/Titan-in-depth-...

The company I founded built something very similar to a titan equipped server to allow attestation/measurement/signed logs/full external policy. I can tell you point blank that while the product we built is great, getting enterprises, the majority of whom ___still___ haven't patched eternal blue to worry about clean source, log traceability, etc. can be quite a challenging business at times. They don't understand problems with IPMI or anything else.

The only thing that is going to change the face of the security market is that the loop between responsibility and inaction gets closed; as things stand today, the primary difficulty in the space is that for your average, not-very-knowledgeable customer, there is effectively no difference in mostly fraudulent security solutions and real ones - both get auditors out of your hair, so why bother buying anything real (or even not deploying anything like Comodo which actually makes things worse but still checks the box)?

Re: Disabling Intel ME 11 via undocumented mode

#212
post #172

What happened to 3rd party chipsets? Seems like VIA, ALi, SiS, Nvidia nForce, all stopped making them for Intel processors around 2008. If there were alternative chipsets still around, we would see more motherboard makers adopting something like openBMC with an alternative chipset and using it. No Intel PCH, no Intel ME.

I believe Intel stopped releasing the documentation required to make them around that timeframe.

Re: Disabling Intel ME 11 via undocumented mode

#213

Earlier quoted context omitted.

As do all countries with any sense.

And sufficient money and other resources. I'm all for national governments making their own hardware not subject to backdoors installed by other national governments, but there's a huge difference in capability between Russia and, say, Lebanon.

That's a good point. Big countries can afford to fab their own chips; small countries cannot. This has geopolitical considerations: The best option for a small country may be to decide which of the big countries it wants to be an ally or puppet of.

Incidentally this is one reason I think the UK is daft to leave the EU.

Re: Disabling Intel ME 11 via undocumented mode

#214

Earlier quoted context omitted.

Most BMCs are rather limited aren't they? They can switch power off and on, read a few sensors. ME goes well beyond that from what I gather.

They've supported a lot more than that for a very long time. The BMCs on both my ThinkServer TD340 and ProLiant ML10 support remote KVM access, CD/DVD emulation (mount a local .iso as a virtual drive on the server), firmware updates, and quite a bit more. On top of that, I should note they do this without assistance of the Intel ME. The remote KVM access is handled through a video adapter embedded in the BMC.

I agree but those are servers, where the extra investment is worthwhile (server outages cost much more than a user desktop) and market demand is driven by people like you and me. I was talking about end-user desktops and laptops.

Re: Disabling Intel ME 11 via undocumented mode

#215
post #186

Earlier quoted context omitted.

I'd love it. But it probably would increase the manufacturer's costs for the motherboard (including engineering, component costs, etc.), distract the organization (managers, engineers, purchasing personnel, etc. spending time on this novel tech instead of just buying Intel/AMD chipsets), reduce quality (can they really compete with Intel's engineering resources?), which increases support costs, etc. ... all for a mar…

The consumer market might be small, but the enterprise market would be what it is. I can't imagine openbmc being more expensive than a builtin wifi card with an external antenna connector for basic features. Features like RDP would be more off course. I imagine they could take a similar embedded processor and slap openbmc on it and market it as open just fine. The fact is, no alternatives to Intel PCH exist, so doing…

> I can't imagine openbmc being more expensive than a builtin wifi card with an external antenna connector for basic features

The cost of IoT devices supports what you are saying.

Re: Disabling Intel ME 11 via undocumented mode

#216

Can someone explain simply what this means for projects like libreboot and coreboot? I'm always interested with this stuff and it's implications, but don't have the background to understand a lot of low level details. Is the verdict still the same or are we gaining ground? Last time I checked, purism was quite optimistic about it, but the libreboot website seemed really pessimistic about it.

I imagine coreboot might integrate this functionality or recommend that people using coreboot do so themselves, but libreboot won't, because the entire point of libreboot is to only use entirely free software and the ME firmware (even the stripped down version that obeys this disable bit) which is required to boot the machine is not free.

Re: Disabling Intel ME 11 via undocumented mode

#217
post #23

Earlier quoted context omitted.

Just to clarify: the A20 stuff was an IBM PC/AT feature in the chipset of the original machine, not a CPU thing. It was actually a response to an Intel mistake in backward compatibility between the 8086 and 286 (real mode segments that pointed "beyond" the first 1MB would wrap around on the original processor but hit the second megabyte on the 286). But when the memory mapping went on-chip in later devices, it needed…

> Just to clarify: the A20 stuff was an IBM PC/AT feature in the chipset of the original machine, not a CPU thing. To quote https://en.wikipedia.org/w/index.php?title=A20_line&oldid=79... "Support for the A20 gate was changed in the Nehalem microarchitecture (some sources incorrectly claim A20 support was removed). Rather than the CPU having a dedicated A20M# pin which receives the signal whether or not to mask the A…

In fact it is CPU thing since x86 CPUs have on-die caches, because the masking has to happen before the access hits cache.

Nehalem removed the physical pin for outside control of that feature (for the northbridge/southbridge platforms this involved a wire that went directly from CPU to EC/SuperIO connected to LPC or ISA, which is highly weird from architectural standpoint).

Re: Disabling Intel ME 11 via undocumented mode

#218
post #156

Are there any good open computers?

I think that depends on what you mean by good and computer . You might, for example, want something that costs on the same order of magnitude as an Intel or AMD x86_64-bit cpu. Afaik the answer to that question then becomes no . There's some hope around power9-based systems: https://www.raptorcs.com/TALOSII/ For more modest demands on performance, and affordability , there's LEON and OpenSPARC.

Thanks. I couldn't find LEON (bad google-fu?), can you link?

So in effect, big $CORPs own computers and with Alphabet agency influence and systemic flaws, the hope for open and secure and powerful computing should be forgotten.

Re: Disabling Intel ME 11 via undocumented mode

#219
post #156

Earlier quoted context omitted.

I think that depends on what you mean by good and computer . You might, for example, want something that costs on the same order of magnitude as an Intel or AMD x86_64-bit cpu. Afaik the answer to that question then becomes no . There's some hope around power9-based systems: https://www.raptorcs.com/TALOSII/ For more modest demands on performance, and affordability , there's LEON and OpenSPARC.

Thanks. I couldn't find LEON (bad google-fu?), can you link? So in effect, big $CORPs own computers and with Alphabet agency influence and systemic flaws, the hope for open and secure and powerful computing should be forgotten.

See: https://en.m.wikipedia.org/wiki/LEON

> the hope for open and secure and powerful computing should be forgotten

I'd say it depends a bit. IBM still throwing money at POWER is interesting. The openSPARC is interesting for certain embedded applications that deal with signal processing - where there's real work to be done both in software and hardware (asic / fpga) - like wireless communication. Having a few sparc cores that run Linux well ready to drop in on a fpga is very nice.

But for consumer hw... Yeah, it's difficult to compete with arm on one side and Intel/AMD on the other. Remember that even transmeta had to throw in the towel trying to compete in that space.

Re: Disabling Intel ME 11 via undocumented mode

#220
post #136

Earlier quoted context omitted.

Know what's even crazier? If the CPU has the "Intel® Anti-Theft Technology", then the Management Engine has 3G built-in.

It's probably more accurate to say that the ME can communicate with the 3G card if there is one installed.

You're right. Unfortunately HN won't let me edit my comment.
Post reply on HN