Live data from Hacker News

“We have obtained fully functional JTAG for Intel CSME via USB DCI”

twitter.com

71–80 of 413 posts

Re: “We have obtained fully functional JTAG for Intel CSME via USB DCI”

#71
post #63

Earlier quoted context omitted.

The 'evil maid' attack is well known, and states that once someone has physical access to your computer, all bets are off. Anything that has DMA enabled (e.g. Firewire or Thunderbolt) offers an external device direct access to the system RAM that is very difficult to defend against, or they could attach a keylogger or modify your bootloader, basically unleash all manner of havok. USB JTAG is really no different from…

> Anything that has DMA enabled (e.g. Firewire or Thunderbolt) offers an external device direct access to the system RAM that is very difficult to defend against IOMMU effectively solves the "DMA is completely broken" problem, as far as I'm aware. Evil Maid attacks are mostly worrisome because even UEFI cannot protect you against some bootloader attacks (what if you disable UEFI or reflash the firmware and then have…

The problem is hard mostly because the entire architecture of the personal computer made absolutely no provision for security. Everything is patches upon patches to add superficial security. Fundamentally, a computer is dumb, it will perform whatever task it is told to do, and all our security measures revolve around stopping a malicious actor from telling the computer to do something 'bad'. Eventually, someone gets around the bouncer or in through an open window and here we are.

Re: “We have obtained fully functional JTAG for Intel CSME via USB DCI”

#72
post #2

Any reason Intel doesn't just offer IME-free CPUs too? There's obviously interest considering the lengths organisations like Google go to to disable it and Intel supposedly already has such offers for governments.

The govt may have forced them into putting it there.

Re: “We have obtained fully functional JTAG for Intel CSME via USB DCI”

#74
post #2

Any reason Intel doesn't just offer IME-free CPUs too? There's obviously interest considering the lengths organisations like Google go to to disable it and Intel supposedly already has such offers for governments.

ME is a useful part of the system. It is in charge of watchdog timers (I think) and mid-level power management. The problem is that it is persistent and opaque. If the operating system were responsible for configuring and managing ME, it would allow it to perform these tasks without being so odious.

Why does it need access to all RAM for watchdog timers and mid-level power management?

Re: “We have obtained fully functional JTAG for Intel CSME via USB DCI”

#75
post #68
post #12

Earlier quoted context omitted.

Intel CPUs have an embedded supervisory CPU called the Management Engine. It can read all of memory, control power states on the main CPU, and generally has super-root privileges on everything. You, an end-user, aren't allowed to program it. The current MEs run a form of Minix. They represent an incredible security and privacy risk, because we don't know what code they run and it is widely believed that the NSA or ot…

Is it known/suspected that AMD have an equivalent?

Yes, the AMD PSP[1] chip.

[1]: http://www.amd.com/en-us/innovations/software-technologies/s...

Re: “We have obtained fully functional JTAG for Intel CSME via USB DCI”

#76

Companies like Intel, who are complicit in helping CIA or any intel agency (government, rogue or otherwise) infiltrate and exploit our systems - need to be held accountable by the market. Intel ME and the (assumed [0]) partnership with CIA to design and build this system - should be an absolute travesty blow to the integrity of their business long-term. Will you, as lead engineer or sys admin for your mission critica…

"The market" is only going to "punish" you if..

- The masses actually care

- There is an alternative

Neither is the case here. Most people couldn't care less about things like ME and AMD and Intel are a oligopoly. If you want a modern x86-64 CPU you only have those two choices and both do this. That is the problem here, not fiat currency.

Re: “We have obtained fully functional JTAG for Intel CSME via USB DCI”

#77
post #68
post #12

Earlier quoted context omitted.

Intel CPUs have an embedded supervisory CPU called the Management Engine. It can read all of memory, control power states on the main CPU, and generally has super-root privileges on everything. You, an end-user, aren't allowed to program it. The current MEs run a form of Minix. They represent an incredible security and privacy risk, because we don't know what code they run and it is widely believed that the NSA or ot…

Is it known/suspected that AMD have an equivalent?

AMD Platform Security Processor

Re: “We have obtained fully functional JTAG for Intel CSME via USB DCI”

#78
post #32

At first it looks nice "oh now we can get rid of it" but it also opens up a very scary near future security-wise. We've now entered a realm where an attacker could simply plug a device on an usb port of your computer for a few seconds to have it access your cpu's ME through USB JTAG and take over it, allowing him to have full access and control over what you do/read/open/type over the network, without you ever knowin…

The 'evil maid' attack is well known, and states that once someone has physical access to your computer, all bets are off. Anything that has DMA enabled (e.g. Firewire or Thunderbolt) offers an external device direct access to the system RAM that is very difficult to defend against, or they could attach a keylogger or modify your bootloader, basically unleash all manner of havok. USB JTAG is really no different from…

My point here was not about it coming from a USB JTAG, but by it targeting ME AND having full debugger access, meaning it isn't limited to reading nor to RAM/volatile memory.

Through this attack, they could compromise the ME longterm, which means the long accepted "nuke it from orbit" solution to security breach (unplug everything, format everything, start from scratch) still wouldn't be enough; that entire chip is done for. And 'using a hack to cleanup the hack' is still in the realm of cleaning up rather than start from scratch, it's not a solution for the same reason than cleaning up your comprised linux box is not one and you need to start from scratch.

Re: “We have obtained fully functional JTAG for Intel CSME via USB DCI”

#79
post #68
post #12

Earlier quoted context omitted.

Intel CPUs have an embedded supervisory CPU called the Management Engine. It can read all of memory, control power states on the main CPU, and generally has super-root privileges on everything. You, an end-user, aren't allowed to program it. The current MEs run a form of Minix. They represent an incredible security and privacy risk, because we don't know what code they run and it is widely believed that the NSA or ot…

Is it known/suspected that AMD have an equivalent?

Yes they do: https://www.reddit.com/r/security/comments/4ot223/do_amdproc...

Re: “We have obtained fully functional JTAG for Intel CSME via USB DCI”

#80
post #32

At first it looks nice "oh now we can get rid of it" but it also opens up a very scary near future security-wise. We've now entered a realm where an attacker could simply plug a device on an usb port of your computer for a few seconds to have it access your cpu's ME through USB JTAG and take over it, allowing him to have full access and control over what you do/read/open/type over the network, without you ever knowin…

Many people will now start to dig in. War is started and I hope somebody will find a way to totally remove/replace(with a stub) Intel ME before some critical vulnerability will be discovered in the Intel ME's network stack. In white hats we trust :)

[deleted]
Post reply on HN