Live data from Hacker News

MINIX: ​Intel's hidden in-chip operating system

zdnet.com

81–90 of 113 posts

Re: MINIX: ​Intel's hidden in-chip operating system

#81

" What Minnich would like to see happen is for Intel to dump its MINIX code and use an open-source Linux-based firmware. This would be much more secure. The current software is only secured by "security by obscurity". Changing to Linux would also enable servers to boot much faster. According to Minnich, booting an Open Compute Project (OCP) Server takes eight minutes thanks to MINIX's primitive drivers. With Linux it…

This article is not FUD and crap. The source of the numbers quoted is here:

https://schd.ws/hosted_files/osseu17/84/Replace%20UEFI%20wit...

I know Ron Minnich. He is one of the founders of the coreboot project. He's been at this (replacing proprietary firmware with a free software alternative) for a very long time and he knows what he is talking about.

Re: MINIX: ​Intel's hidden in-chip operating system

#82
post #3

Earlier quoted context omitted.

No need to. For anybody who's read the Snowden leaks it's 100% plausible that the NSA owns society through hardware backdoors. Conclusion: We need 100% open-source hardware ASAP if we're to become a sane society. Edit: Anyone remember the "Intel inside" trademark [0] which was supposed to add (marketing) value to any PC which was allowed to carry that label? Well, today it's clear that this label actually stands for…

In that case why didn't they remotely disable Snowden's laptop when he went on the run? My best guess is that the system isn't yet fully operational.

> In that case why didn't they remotely disable Snowden's laptop when he went on the run?

There are several possible answers to that question:

1) "Just because you're paranoid doesn't mean they're not after you."

2) Because the risk of getting this backdoor known would not be worth the cost.

3) Because Snowden's laptop was used with airgap.

4) Because at that point, the cat was already out of the bag (the journalists had the data on SDs).

Re: MINIX: ​Intel's hidden in-chip operating system

#83
post #75

Earlier quoted context omitted.

Thanks for the options you mentioned! Are there tutorials do do this?: Some Intel processors and a Raspberry Pi: much better performance but you have to ME_Clean the firmware, hence the Pi.

https://github.com/corna/me_cleaner/wiki/How-to-apply-me_cle...

Thanks!

Re: MINIX: ​Intel's hidden in-chip operating system

#84
post #9

Earlier quoted context omitted.

If it's not open it's even less likely to be found in the first place. Do you have other options?

How many people were capable of spotting a backdoor in the standard[1]? Do you think that an average person can just look at a source code and spot any backdoor or security bug? 1. https://www.wired.com/images_blogs/threatlevel/2013/09/15-sh...

It does not have to be the average person. If it's open and if there is enough interest in the community, organizations can contract security professionals to audit the code. This has been done for several crypto projects even in recent history.

Re: MINIX: ​Intel's hidden in-chip operating system

#85

While the backdoor and surveillance arguments are good, and the chips are very likely backdoored (if not deliberately then by undetected bugs) there are other issues with this closed source firmware. Let's say another bug [1] is found that lets anyone remotely control your computer, but Intel becomes bankrupt, or just doesn't see it as a big enough threat to roll out a firmware update. You then essentially have a com…

Is there no way to flash the ME without expensive tools (i.e. software-side)? If Intel goes bankrupt they might just release the keys needed to disable/update the ME.

Flashing ME firmware is quite trivial for older laptops -- you just need a flash programmer, a raspberry pi and some patience. It's one of the key parts of how me_cleaner[1] works -- you "clean up" the firmware and flash a new version. However, newer Intel CPUs have BootGuard[2] which makes this impossible.

But I wouldn't hold my breath that they'll release the keys -- why would they? Releasing keys is the last thing you'll think of if a decades-old business is going up in flames.

[1]: https://github.com/corna/me_cleaner [2]: https://github.com/corna/me_cleaner/wiki/Intel-Boot-Guard

Re: MINIX: ​Intel's hidden in-chip operating system

#86
post #47

While the backdoor and surveillance arguments are good, and the chips are very likely backdoored (if not deliberately then by undetected bugs) there are other issues with this closed source firmware. Let's say another bug [1] is found that lets anyone remotely control your computer, but Intel becomes bankrupt, or just doesn't see it as a big enough threat to roll out a firmware update. You then essentially have a com…

You just described the actual situation with most Android devices, smart TVs, home routers and IoT of shame.

I wonder when people are going to realize RMS was right the whole time.

I'm constantly amazed at the pushback here and other forums against copyleft-foss.

Re: MINIX: ​Intel's hidden in-chip operating system

#87
post #13

So if switching to AMD is NOT the solution, what is? ARM? For your portable needs there is: https://puri.sm/posts/purism-librem-laptops-completely-disab...

SPARC was the solution. It's open and royalty free and was sold by multiple vendors. Add to that Open Firmware and you're done. It's also not the hacked up turd that x86-64 is or the fragmented mess that ARM is. Problem is it's dead. Going out on a limb here, but we can solve this with another layer of abstraction in the long term. We need to develop a fully portable open source virtual machine model (think p-code ma…

wasn't Java supposed to be precisely that?

Re: MINIX: ​Intel's hidden in-chip operating system

#88
post #58

Earlier quoted context omitted.

In that case why didn't they remotely disable Snowden's laptop when he went on the run? My best guess is that the system isn't yet fully operational.

What would NSA spooks have achieved besides confirming that hardware backdoor are real (to those remaining few who still doubt)? Snowden could have simply took out HDD, put in into the new machine and resume his operation.

My guess is that with insider knowledge and a good firewall, a no-updates policy you can prevent phoning into the backdoor for a while.

Re: MINIX: ​Intel's hidden in-chip operating system

#89
post #26
post #13

Earlier quoted context omitted.

SPARC was the solution. It's open and royalty free and was sold by multiple vendors. Add to that Open Firmware and you're done. It's also not the hacked up turd that x86-64 is or the fragmented mess that ARM is. Problem is it's dead. Going out on a limb here, but we can solve this with another layer of abstraction in the long term. We need to develop a fully portable open source virtual machine model (think p-code ma…

> Problem is it's dead. and if it's so good, why is sparc dead?

They are not making more, but reasonably priced used sparc64 servers are still reasonably easy to find. OpenBSD runs well on most models.

Re: MINIX: ​Intel's hidden in-chip operating system

#90

Earlier quoted context omitted.

I find it hard to believe that such a scenario could play out in reality. Surely some government would step forward and compel or even fund a bankrupt Intel to fix such a disaster. But perhaps I am wet behind the ears, have there been any similar cases on a similar scale in the past?

Fix this computer or got to prison. How would that work ?

More like, release your signing keys to us so we can fix the problem (and future similar problems) or go to prison.
Post reply on HN