Live data from Hacker News

MINIX: ​Intel's hidden in-chip operating system

zdnet.com

51–60 of 113 posts

Re: MINIX: ​Intel's hidden in-chip operating system

#51
post #17

So if switching to AMD is NOT the solution, what is? ARM? For your portable needs there is: https://puri.sm/posts/purism-librem-laptops-completely-disab...

For desktop your options are: — FX 8350 (Piledriver) from AMD with no PSP: very cheap, no flashing necessary, but not the best performance. Single core performance much worse than even Pentium G4620[1]. — Some Intel processors and a Raspberry Pi: much better performance but you have to ME_Clean the firmware, hence the Pi. — POWER9 processor for amazing performance and completely open & free firmware all around: the C…

> — Some Intel processors and a Raspberry Pi: much better performance but you have to ME_Clean the firmware, hence the Pi.

The Pi also has a binary blob requirement and a Trustzone implementation (which is however open to tinkering).

Re: MINIX: ​Intel's hidden in-chip operating system

#53
post #23

While I am unsure if switchting to Linux for ME is a good solution, open sourcing whatever runs ME is a very important step towards user/customer security. And that is not because we all want to know intels secrets about 'how to make the fastest CPU' but because ME can change the product on a fundamental level while we use the product. The reason I doubt that Linux is a good solution is that linux wasn't built to run…

MINIX is already open source, the ME services are not.

Re: MINIX: ​Intel's hidden in-chip operating system

#54
post #9

Earlier quoted context omitted.

If it's not open it's even less likely to be found in the first place. Do you have other options?

How many people were capable of spotting a backdoor in the standard[1]? Do you think that an average person can just look at a source code and spot any backdoor or security bug? 1. https://www.wired.com/images_blogs/threatlevel/2013/09/15-sh...

Doesn't have to be manual, despite kids being taught programming within the next generation.

Automated fuzzing is a solution amongst others.

Re: MINIX: ​Intel's hidden in-chip operating system

#55

While the backdoor and surveillance arguments are good, and the chips are very likely backdoored (if not deliberately then by undetected bugs) there are other issues with this closed source firmware. Let's say another bug [1] is found that lets anyone remotely control your computer, but Intel becomes bankrupt, or just doesn't see it as a big enough threat to roll out a firmware update. You then essentially have a com…

I find it hard to believe that such a scenario could play out in reality. Surely some government would step forward and compel or even fund a bankrupt Intel to fix such a disaster. But perhaps I am wet behind the ears, have there been any similar cases on a similar scale in the past?

Fix this computer or got to prison.

How would that work ?

Re: MINIX: ​Intel's hidden in-chip operating system

#56

While the backdoor and surveillance arguments are good, and the chips are very likely backdoored (if not deliberately then by undetected bugs) there are other issues with this closed source firmware. Let's say another bug [1] is found that lets anyone remotely control your computer, but Intel becomes bankrupt, or just doesn't see it as a big enough threat to roll out a firmware update. You then essentially have a com…

The fact that it's closed source is not actually the biggest problem --- it's the fact that the hardware completely refuses to run firmware that's not signed by Intel, and Intel is not giving you the keys or any other way out. Intel could open-source the firmware, but without any way to use it on the hardware, it'd be useless for anything but finding exploits --- arguably an even worse position. See also https://en.w…

> it'd be useless for anything but finding exploits

For all unmodified parts of MINIX that ended up in ME 11, this is precisely the case.

Re: MINIX: ​Intel's hidden in-chip operating system

#57

" What Minnich would like to see happen is for Intel to dump its MINIX code and use an open-source Linux-based firmware. This would be much more secure. The current software is only secured by "security by obscurity". Changing to Linux would also enable servers to boot much faster. According to Minnich, booting an Open Compute Project (OCP) Server takes eight minutes thanks to MINIX's primitive drivers. With Linux it…

I know Ron, he used to work at Sandia National Laboratories in Livermore, running Plan 9 on IBM's Deep Blue among other things.

e.g. running 1 million Linux kernel at once

https://share-ng.sandia.gov/news/resources/news_releases/san...

He's also one of the people behind CoreBoot or whatever its called now

Re: MINIX: ​Intel's hidden in-chip operating system

#58
post #3

Earlier quoted context omitted.

No need to. For anybody who's read the Snowden leaks it's 100% plausible that the NSA owns society through hardware backdoors. Conclusion: We need 100% open-source hardware ASAP if we're to become a sane society. Edit: Anyone remember the "Intel inside" trademark [0] which was supposed to add (marketing) value to any PC which was allowed to carry that label? Well, today it's clear that this label actually stands for…

In that case why didn't they remotely disable Snowden's laptop when he went on the run? My best guess is that the system isn't yet fully operational.

What would NSA spooks have achieved besides confirming that hardware backdoor are real (to those remaining few who still doubt)? Snowden could have simply took out HDD, put in into the new machine and resume his operation.
Post reply on HN