Live data from Hacker News

MINIX: ​Intel's hidden in-chip operating system

zdnet.com

11–20 of 113 posts

Re: MINIX: ​Intel's hidden in-chip operating system

#11

So if switching to AMD is NOT the solution, what is? ARM? For your portable needs there is: https://puri.sm/posts/purism-librem-laptops-completely-disab...

AMD PSP is efficiently ARM tech called TrustZone so I would expect most of SOC to have own backdoors as well.

So far only option is POWER-based systems and they're costly.

Re: MINIX: ​Intel's hidden in-chip operating system

#12
post #8
post #7

Earlier quoted context omitted.

The open-source approach is our own chance to purge corruption in the technology layer. We may not yet have implemented the idea perfectly, but keep in mind the following: With every new player (government, company, user) joining the open-source approach, we get additional eyes on the code/hardware. Imagine all world governments using only open-source code/hardware: Given the current budgets at play, we would have 10…

Let's suppose that hardware is open-source. How do I know that my instance of the hardware is faithful to the spec? That my vendor didn't modify the hardware? Let's suppose that I have a 3D printer sophisticated enough to print open-source circuitboards. How do I trust my 3d printer? I think there's a hardware "trusting trust" problem; I can't imagine how your optimism could ever be realized. I hope I'm missing somet…

There will always be trust related issues, but that doesnt mean we shouldnt improve overall situation. Currently its possible there are all kind of backdoors in: hardware itself, firmware, drivers, some of closed source software. If we would limit it only to hardware itself that would be huge win.

Re: MINIX: ​Intel's hidden in-chip operating system

#13

So if switching to AMD is NOT the solution, what is? ARM? For your portable needs there is: https://puri.sm/posts/purism-librem-laptops-completely-disab...

SPARC was the solution. It's open and royalty free and was sold by multiple vendors. Add to that Open Firmware and you're done. It's also not the hacked up turd that x86-64 is or the fragmented mess that ARM is.

Problem is it's dead.

Going out on a limb here, but we can solve this with another layer of abstraction in the long term. We need to develop a fully portable open source virtual machine model (think p-code machine) that is portable and make that the canonical hardware abstraction. That makes all vendors irrelevant if they can't comply with it and opens the market to new hardware vendors with different sales models to provide an optimised hardware implementation of that abstraction. The incumbents (ARM, Intel, AMD) can't sell a security model if the abstraction denies them that ability. Sure they can sell you out, but new competition which is privacy focused should end that.

Re: MINIX: ​Intel's hidden in-chip operating system

#14
post #8
post #7

Earlier quoted context omitted.

The open-source approach is our own chance to purge corruption in the technology layer. We may not yet have implemented the idea perfectly, but keep in mind the following: With every new player (government, company, user) joining the open-source approach, we get additional eyes on the code/hardware. Imagine all world governments using only open-source code/hardware: Given the current budgets at play, we would have 10…

Let's suppose that hardware is open-source. How do I know that my instance of the hardware is faithful to the spec? That my vendor didn't modify the hardware? Let's suppose that I have a 3D printer sophisticated enough to print open-source circuitboards. How do I trust my 3d printer? I think there's a hardware "trusting trust" problem; I can't imagine how your optimism could ever be realized. I hope I'm missing somet…

I think the parent doesn't mean that open source will cure all problems but that it will move the bar higher for malicious players. If the designs were published and it'd be possible for anyone to review and build such a thing then it's exponentially harder to hide something.

Re: MINIX: ​Intel's hidden in-chip operating system

#15
Now that Intel ME is getting so much attention, are there similar efforts to analyze AMD's PSP? I wonder about that since I'm planning to buy a new PC next year and was planning to go for AMD this time. Should I wait until security researchers have found ways to disable these for a certain chip/motherboard/firmware combination?

I'm thinking about buying an Intel chip, trying to disable ME, and send the motherboard and chip back as faulty if it gets bricked during that process.

Re: MINIX: ​Intel's hidden in-chip operating system

#17

So if switching to AMD is NOT the solution, what is? ARM? For your portable needs there is: https://puri.sm/posts/purism-librem-laptops-completely-disab...

For desktop your options are:

— FX 8350 (Piledriver) from AMD with no PSP: very cheap, no flashing necessary, but not the best performance. Single core performance much worse than even Pentium G4620[1].

— Some Intel processors and a Raspberry Pi: much better performance but you have to ME_Clean the firmware, hence the Pi.

— POWER9 processor for amazing performance and completely open & free firmware all around: the CPU is $400 but you get $400 worth of performance, PCIe 4.0 etc., however the only mainboard you can get right now costs $2000, and it’s not x86, so you’d need to run your Windows VMs (if you need) on a seperate box.

Personally I recommend used IvyBridge-EP or Haswell Xeon E5 system, make sure it takes ECC DDR3 Reg ram and you can pick up lots of very cheap DDR3 ECC memory to go along with it.

Performance is pretty good, on par with mid level Ryzen[1], and it’s recent enough to have all the hardware extensions anyone cares about.

[1] http://cpu.userbenchmark.com/Compare/AMD-FX-8350-vs-Intel-Pe...

[2] http://cpu.userbenchmark.com/Compare/Intel-Xeon-E5-1650-v2-v...

EDIT: Post before wrongly stated that you need pre-Skylake chip. Skylake/Kabylake µarch is also an option now, however some restrictions apply. I don’t think it’s very good value though, at least until Coffeelake is compatible.

Re: MINIX: ​Intel's hidden in-chip operating system

#18
post #3

Earlier quoted context omitted.

No need to. For anybody who's read the Snowden leaks it's 100% plausible that the NSA owns society through hardware backdoors. Conclusion: We need 100% open-source hardware ASAP if we're to become a sane society. Edit: Anyone remember the "Intel inside" trademark [0] which was supposed to add (marketing) value to any PC which was allowed to carry that label? Well, today it's clear that this label actually stands for…

Implying opensource cannot contain backdoors for years. https://arstechnica.com/information-technology/2010/12/fbi-a...

Did they ever find backdoors, or are they still pure speculation?

Re: MINIX: ​Intel's hidden in-chip operating system

#19
"What Minnich would like to see happen is for Intel to dump its MINIX code and use an open-source Linux-based firmware. This would be much more secure. The current software is only secured by "security by obscurity".

Changing to Linux would also enable servers to boot much faster. According to Minnich, booting an Open Compute Project (OCP) Server takes eight minutes thanks to MINIX's primitive drivers. With Linux it would take less than 17 seconds to get to a shell prompt. That's a speedup of 32 times."

Anyone else think this is article is pretty FUD and crap? Not saying Minix has been security audited or is more/less secure than a Linux alternative, but there's something to be said for microkernels at the ME layer.

The OpenCompute annecdote (uncited?) doesn't designate whether Minix in ME is the bottleneck, or whether it's just slow to boot (it probably is when you're booting it with a platform worth of devices).

Good to know my involuntary shudder when opening a ZDNet article isn't entirely unfounded.

Post reply on HN