Live data from Hacker News

MINIX: ​Intel's hidden in-chip operating system

zdnet.com

61–70 of 113 posts

Re: MINIX: ​Intel's hidden in-chip operating system

#61

It would be interesting to know the HFT attitude on this. How many nanoseconds can you shave off of your trades with ME removed? It seems like throws a spanner in the face of the unikernel / kernel bypass approach of getting closer to the metal, when your CPU can be directly running a web server(!) without your control.

I thought modern HFT machines run on FPGA/ASIC's?

Re: MINIX: ​Intel's hidden in-chip operating system

#62
post #17

Earlier quoted context omitted.

For desktop your options are: — FX 8350 (Piledriver) from AMD with no PSP: very cheap, no flashing necessary, but not the best performance. Single core performance much worse than even Pentium G4620[1]. — Some Intel processors and a Raspberry Pi: much better performance but you have to ME_Clean the firmware, hence the Pi. — POWER9 processor for amazing performance and completely open & free firmware all around: the C…

> — Some Intel processors and a Raspberry Pi: much better performance but you have to ME_Clean the firmware, hence the Pi. The Pi also has a binary blob requirement and a Trustzone implementation (which is however open to tinkering).

It’s just inexpensive flasher for the firmware.

Re: MINIX: ​Intel's hidden in-chip operating system

#63
post #3

Earlier quoted context omitted.

No need to. For anybody who's read the Snowden leaks it's 100% plausible that the NSA owns society through hardware backdoors. Conclusion: We need 100% open-source hardware ASAP if we're to become a sane society. Edit: Anyone remember the "Intel inside" trademark [0] which was supposed to add (marketing) value to any PC which was allowed to carry that label? Well, today it's clear that this label actually stands for…

"sane society" My personal belief is that this is a little optimistic. There's a lot wrong with our society, and intel embedding Minix in the ME doesn't really rise to the top of current issues. I would really like an option that did not have binary blobs in the bios or CPU. That's tough, though...CPU's always have microcode fixes, don't they? So far, I think the best option for this kind of thing is the Raptor works…

> "sane society"

> My personal belief is that this is a little optimistic. There's a lot wrong with our society, and intel embedding Minix in the ME doesn't really rise to the top of current issues.

It's not optimistic. Society will change massively - in the good direction. We have still a lot of work ahead of us, and there will of course be pain along the way, but the Planet will become peaceful and clean again. And we are assisted in this process. How do I know? I've seen it.

Re: MINIX: ​Intel's hidden in-chip operating system

#64

" What Minnich would like to see happen is for Intel to dump its MINIX code and use an open-source Linux-based firmware. This would be much more secure. The current software is only secured by "security by obscurity". Changing to Linux would also enable servers to boot much faster. According to Minnich, booting an Open Compute Project (OCP) Server takes eight minutes thanks to MINIX's primitive drivers. With Linux it…

Yes, it's complete FUD. It's also moot, because it really doesn't matter much whats in ME, ME just needs to not exist. The primary reason for choosing MINIX is memory footprint and reliability, additionally GNU is never popular for proprietary blobs like this... it would actually harm users with ME's current strategy if you think about it, GNU forces them to publish their likely buggy striped down version of linux, yet only intel can sign the firmware, so users are helpless and malicious people can find bugs in the code while intel sits on their hands.

I don't find it hard to believe that Minix drivers are slow and primitive... Minix is not widely used like Linux, that doesn't really mean anything more than that, it's an amazing kernel and there is no better choice for an embedded system that you can't afford to fail and require user intervention.

I guess the TL;DR is that Minix was the right system for the job, it's just that the job was unfortunately pure evil, so arguing about Minix is stupid.

Re: MINIX: ​Intel's hidden in-chip operating system

#65
post #63

Earlier quoted context omitted.

"sane society" My personal belief is that this is a little optimistic. There's a lot wrong with our society, and intel embedding Minix in the ME doesn't really rise to the top of current issues. I would really like an option that did not have binary blobs in the bios or CPU. That's tough, though...CPU's always have microcode fixes, don't they? So far, I think the best option for this kind of thing is the Raptor works…

> "sane society" > My personal belief is that this is a little optimistic. There's a lot wrong with our society, and intel embedding Minix in the ME doesn't really rise to the top of current issues. It's not optimistic. Society will change massively - in the good direction. We have still a lot of work ahead of us, and there will of course be pain along the way, but the Planet will become peaceful and clean again. And…

Look, friend, I'm not trying to be argumentative to be a troll or anything. I get that you think that this is a super serious issue. I do to, but you have to admit that getting Minix and the ME out of PC CPU's won't really stop cops from shooting unarmed black men, or stop proliferation of cheap small arms in conflict zones, or the lack of clean water...I won't keep beating the drum.

I'm also not an SJW or whatever. I'm just saying that things that can be very important to us...that we think will have a tremendous impact on the future...those things aren't universal issues. Maybe it's just my lack of understanding of where you are coming from to see how this would be a major component of getting to a peaceful and clean world. If so, I would like to hear more. Thanks.

Re: MINIX: ​Intel's hidden in-chip operating system

#66
post #58

Earlier quoted context omitted.

In that case why didn't they remotely disable Snowden's laptop when he went on the run? My best guess is that the system isn't yet fully operational.

What would NSA spooks have achieved besides confirming that hardware backdoor are real (to those remaining few who still doubt)? Snowden could have simply took out HDD, put in into the new machine and resume his operation.

The ME has full control of the hardware and could have wiped the hard drive before bricking the machine. The NSA presumably would have preferred a bit of bad PR to actual classified information being leaked. A better argument would be that all laptops approved for use by NSA staff routinely have the HAP bit enabled.

Re: MINIX: ​Intel's hidden in-chip operating system

#67
post #58

Earlier quoted context omitted.

What would NSA spooks have achieved besides confirming that hardware backdoor are real (to those remaining few who still doubt)? Snowden could have simply took out HDD, put in into the new machine and resume his operation.

The ME has full control of the hardware and could have wiped the hard drive before bricking the machine. The NSA presumably would have preferred a bit of bad PR to actual classified information being leaked. A better argument would be that all laptops approved for use by NSA staff routinely have the HAP bit enabled.

I somehow suspect that Snowden was smart enough not to keep all eggs in a single basket. His laptop might as well has been mugged or stolen.

Re: MINIX: ​Intel's hidden in-chip operating system

#68
In fairness to minix, it's far far better than linux for this. It's microkernel design is more stable, potentially more secure (since drivers aren't in the kernel), and the codebase is far far smaller. So it's easier to audit and easier to fit on a chip too.

The ME itself is a terrible idea - but why demand the switch to linux? Better just open source the minix variant they're using and fix it up ourselves.

What this does show is that Tannenbaum should have licensed his OS with GPL, then we might have avoided this mess!

Re: MINIX: ​Intel's hidden in-chip operating system

#70

While the backdoor and surveillance arguments are good, and the chips are very likely backdoored (if not deliberately then by undetected bugs) there are other issues with this closed source firmware. Let's say another bug [1] is found that lets anyone remotely control your computer, but Intel becomes bankrupt, or just doesn't see it as a big enough threat to roll out a firmware update. You then essentially have a com…

Is there no way to flash the ME without expensive tools (i.e. software-side)? If Intel goes bankrupt they might just release the keys needed to disable/update the ME.
Post reply on HN