Live data from Hacker News

MINIX: ​Intel's hidden in-chip operating system

zdnet.com

101–110 of 113 posts

Re: MINIX: ​Intel's hidden in-chip operating system

#101

So if switching to AMD is NOT the solution, what is? ARM? For your portable needs there is: https://puri.sm/posts/purism-librem-laptops-completely-disab...

Maybe this:

https://minifree.org/product/libreboot-t400/

However, I assume any chip released after they added the backdoors also has the backdoors. So, you'd be looking for pre-2007, Pentium-class chips in SMP configuration. Maybe Pentium 4 Prescot-2M or Cedar Mill. Wikipedia shows the latter was on same node as Core Duo with 3-3.6GHz plus 2MB cache.

Far as non-Intel, both PPC and SPARC used Open Firmware. Plenty of them on eBay. Gaisler also made GPL versions of Leon3 you could build yourself or buy as a development board for who knows what price.

https://en.wikipedia.org/wiki/Open_Firmware

In high-assurance security, I remember BootSafe tech letting someone write firmware in Java to benefit from all its testing and verification tech that was then translated into Open Firmware's Forth in a way that preserved the properties. That tech went proprietary but still exists. Something similar could be done in FOSS with a Rust or SPARK to Forth converter leveraging hard work already done by compiler/verification teams of source languages.

http://www.cs.cornell.edu/~kozen/papers/acsac.pdf

Re: MINIX: ​Intel's hidden in-chip operating system

#102
post #23

While I am unsure if switchting to Linux for ME is a good solution, open sourcing whatever runs ME is a very important step towards user/customer security. And that is not because we all want to know intels secrets about 'how to make the fastest CPU' but because ME can change the product on a fundamental level while we use the product. The reason I doubt that Linux is a good solution is that linux wasn't built to run…

A shrunk version of Linux can run on 8088 CPUs too. https://github.com/jbruchon/elks But the problem here isn't to put this or that OS in place of Minix but rather to get rid of that completely for good. Different licensing also wouldn't help at all: behind those people are the ones who actually write the laws; it would require 10 minutes of their time to make an exception for terrorism or child porn motivated surveillance.

Re: MINIX: ​Intel's hidden in-chip operating system

#104
post #62

Earlier quoted context omitted.

> — Some Intel processors and a Raspberry Pi: much better performance but you have to ME_Clean the firmware, hence the Pi. The Pi also has a binary blob requirement and a Trustzone implementation (which is however open to tinkering).

It’s just inexpensive flasher for the firmware.

The PocketBeagle is competitive on price (<$25), and the chip has a complete 5000+ page, no-NDA datasheet/programming manual freely available from TI.

Re: MINIX: ​Intel's hidden in-chip operating system

#105
post #97

While the backdoor and surveillance arguments are good, and the chips are very likely backdoored (if not deliberately then by undetected bugs) there are other issues with this closed source firmware. Let's say another bug [1] is found that lets anyone remotely control your computer, but Intel becomes bankrupt, or just doesn't see it as a big enough threat to roll out a firmware update. You then essentially have a com…

Moreover, Intel could selectively release patches for only the newer chips, providing an incentive to upgrade. Intel deliberately creating such holes and then only fixing them on more expensive models would be possible as well, but the PR from that one might be distasteful enough to hurt Intel.

So like the way apple security updates gimp the performance of your device?

These kind of business practises are Apple's biggest contribution to the computing industry. Didn't invent them but made them absolutely "the norm" and everyone, even hardware manufacturers want to emulate Apple's stunning success. I used to hate Microsoft business practises, Apple are far, far worse the only reason they didn't seem it was because they had such a pathetic market share. Only one thing has changed. Think different. Think critically about what Apple are.

If Intel copy apple here, can you object to intel doing it but not Apple with a straight face?

Re: MINIX: ​Intel's hidden in-chip operating system

#106
post #81

Earlier quoted context omitted.

This article is not FUD and crap. The source of the numbers quoted is here: https://schd.ws/hosted_files/osseu17/84/Replace%20UEFI%20wit... I know Ron Minnich. He is one of the founders of the coreboot project. He's been at this (replacing proprietary firmware with a free software alternative) for a very long time and he knows what he is talking about.

But... replacing Minix with Linux wouldn't be replacing proprietary code with a free alternative. It would be replacing free software with a less free alternative.

Your use of 'free' here is correct from the perspective of a developer working for intel, but as a user with a cpu running modified and previously opensource, but now closedsource, software it isn't applicable to me. GPL would have protected more of my freedom, provided they didn't just violate the GPL.

Re: MINIX: ​Intel's hidden in-chip operating system

#107
post #81

Earlier quoted context omitted.

This article is not FUD and crap. The source of the numbers quoted is here: https://schd.ws/hosted_files/osseu17/84/Replace%20UEFI%20wit... I know Ron Minnich. He is one of the founders of the coreboot project. He's been at this (replacing proprietary firmware with a free software alternative) for a very long time and he knows what he is talking about.

But... replacing Minix with Linux wouldn't be replacing proprietary code with a free alternative. It would be replacing free software with a less free alternative.

None of the four freedoms are available in this context, Minix as part of the Intel ME.

cf.

  https://www.gnu.org/philosophy/free-sw.en.html

Re: MINIX: ​Intel's hidden in-chip operating system

#108

While the backdoor and surveillance arguments are good, and the chips are very likely backdoored (if not deliberately then by undetected bugs) there are other issues with this closed source firmware. Let's say another bug [1] is found that lets anyone remotely control your computer, but Intel becomes bankrupt, or just doesn't see it as a big enough threat to roll out a firmware update. You then essentially have a com…

That security bug you're talking about can be patched the same way it's exploited. No source code doesn't mean "all is lost". Instead of writing a payload that steals your private keys you just write one that patches out the vulnerability.

Re: MINIX: ​Intel's hidden in-chip operating system

#109
I had a question about this passage:

>"There's no reason not to make this improvement. Minnich noted, "There are probably 30 million-plus Chromebooks out there and when your Chromebook gets a new BIOS, a new Linux image is flashed to firmware and I haven't heard of any problems."

Didn't or don't some generations of Chromebooks use Intel chips? Or is he not referring to the ring -2 and ring -3 Intel ME/UEFI stuff here?

Re: MINIX: ​Intel's hidden in-chip operating system

#110

" What Minnich would like to see happen is for Intel to dump its MINIX code and use an open-source Linux-based firmware. This would be much more secure. The current software is only secured by "security by obscurity". Changing to Linux would also enable servers to boot much faster. According to Minnich, booting an Open Compute Project (OCP) Server takes eight minutes thanks to MINIX's primitive drivers. With Linux it…

I know Ron, he used to work at Sandia National Laboratories in Livermore, running Plan 9 on IBM's Deep Blue among other things. e.g. running 1 million Linux kernel at once https://share-ng.sandia.gov/news/resources/news_releases/san... He's also one of the people behind CoreBoot or whatever its called now

Holy cow, I just realized that I met him at a backyard barbecue... Very sharp guy.
Post reply on HN