Live data from Hacker News

“We have obtained fully functional JTAG for Intel CSME via USB DCI”

twitter.com

101–110 of 413 posts

Re: “We have obtained fully functional JTAG for Intel CSME via USB DCI”

#101
post #33

Earlier quoted context omitted.

I think you're being overly paranoid. If the attacker has physical access to the machine, chances are you're compromised anyway, even before this vulnerability.

I don't think thats the right attitude. There's a difference between being able to open a machine to install malicious hardware / steal hdd's or just plugging in a generic USB stick to pawn it. I know some of you might argue that even generic USB sticks can do damage and, whilst I agree, this attack is still a degree worse than most of those. Thus far the most damage an unknown USB stick could do was type commands as…

From a technical perspective there is a difference now that this is public, but from a security stance, physical access is physical access.

Why? Security knows there are always bugs in software, and assumes they exist. Thanks to @h0t_max, the rest of us know this particular bug exists, but this bug has been around for a while - who's to say evil hax0rs didn't find this bug years ago and have been exploiting it since?

Or put another way - you say an unknown USB stick could exploit a driver vulnerability to silently cause mischief, and then claim that this is easily stopped if an administrator sets a security policy to disallow unknown USB devices. (I assume you mean a Windows GPO enforced policy or similar, and not a written social policy.) Who's to say the code that enforces the policy doesn't have bugs that's exploitable? What if the driver for a known USB stick has exploits?

Physical access is physical access, and while there are mitigations for the evil maid attack (like an encrypted drive and shutting down -not just suspending, when the machine is out of sight), there simply is no way around the fact that physical access is game over.

Re: “We have obtained fully functional JTAG for Intel CSME via USB DCI”

#102

Earlier quoted context omitted.

ME is a useful part of the system. It is in charge of watchdog timers (I think) and mid-level power management. The problem is that it is persistent and opaque. If the operating system were responsible for configuring and managing ME, it would allow it to perform these tasks without being so odious.

Why does it need access to all RAM for watchdog timers and mid-level power management?

It also facilitates some hardware bring-up, and has management (hence the name) functionalities. So it's not really surprising that it has access to everything. That's not to say that it's at all acceptable that modern machines have such a gigantic security flaw.

Re: “We have obtained fully functional JTAG for Intel CSME via USB DCI”

#103

Companies like Intel, who are complicit in helping CIA or any intel agency (government, rogue or otherwise) infiltrate and exploit our systems - need to be held accountable by the market. Intel ME and the (assumed [0]) partnership with CIA to design and build this system - should be an absolute travesty blow to the integrity of their business long-term. Will you, as lead engineer or sys admin for your mission critica…

> Intel ME and the (assumed [0]) partnership with CIA to design and build this system I worked at Intel on ME and the things that came before it until around 2013. I can tell you two things -- 1. No, Intel ME wasn't born out of a desire to spy on people nor was it -- to the best of my knowledge but I honestly believe I would know -- created at the request of the US government (or others). It was an honest attempt at…

regarding 1): hiding in plain sight is sometimes a valid strategy. So is heavy compartmentalization.

Re: “We have obtained fully functional JTAG for Intel CSME via USB DCI”

#104

Companies like Intel, who are complicit in helping CIA or any intel agency (government, rogue or otherwise) infiltrate and exploit our systems - need to be held accountable by the market. Intel ME and the (assumed [0]) partnership with CIA to design and build this system - should be an absolute travesty blow to the integrity of their business long-term. Will you, as lead engineer or sys admin for your mission critica…

> Intel ME and the (assumed [0]) partnership with CIA to design and build this system I worked at Intel on ME and the things that came before it until around 2013. I can tell you two things -- 1. No, Intel ME wasn't born out of a desire to spy on people nor was it -- to the best of my knowledge but I honestly believe I would know -- created at the request of the US government (or others). It was an honest attempt at…

Kudos for speaking up about it, understandably with a throwaway account - which unfortunately doesn't help prove what you say is in any way truthful. But you probably still work for them and enjoy a nice salary. So can't blame you at all there. But I do just wish more people would be willing to put their careers on the line to say the right thing. This is one of the underlying problems: when smart people go along with bad things, very bad things can and will happen - if on the contrary smart people speak out about bad things then those bad things will be less likely to unfold on a large scale as we see them happening so often in SV.

To your points though, I mean it is a great perspective and helps to illustrate a sliver of possibility of innocence here on Intel's part but it's a little weak given that the operation would have been compartmentalized and political objectives/partnerships therof obviously not part of the system's technical development.

Re: “We have obtained fully functional JTAG for Intel CSME via USB DCI”

#105

One way to think of ME is, we all woke up one day and discovered we have had high resolution night vision spy cams installed in our bedrooms. The next realization is there is no way to turn them off or remove them. It’s posisble even moving won’t help. And yet we really don’t seem to care much. Lesser issues generate national outrage and high volumes of press coverage. Why? HN may be uniquely positioned to show us th…

[deleted]

Re: “We have obtained fully functional JTAG for Intel CSME via USB DCI”

#106
post #91

Earlier quoted context omitted.

Seriously? A 4chan post? While the ME is worrying for many reasons, there's absolutely zero evidence that the Intel ME contains a backdoor. Backdoors don't stay hidden forever.

Some would argue the entire design of ME is evidence that it IS a backdoor.

AMT (server grade ME) is definitely a door of some sort, but as an advertised feature, I don't know that Intel is hiding it in the back.

https://www.intel.com/content/www/us/en/architecture-and-tec...

Re: “We have obtained fully functional JTAG for Intel CSME via USB DCI”

#107
Ah, I’m so glad and proud of the hacker community now. The nasty and opaque backdoor is now out in the open So the researchers can now find a way to close the hole. I have a feeling the current gen intel processors are going to be in demand amongst the security community and privacy conscious users because the newer ones will definitely have an even shittier backdoor in place of the now bust ME.

Re: “We have obtained fully functional JTAG for Intel CSME via USB DCI”

#109

One way to think of ME is, we all woke up one day and discovered we have had high resolution night vision spy cams installed in our bedrooms. The next realization is there is no way to turn them off or remove them. It’s posisble even moving won’t help. And yet we really don’t seem to care much. Lesser issues generate national outrage and high volumes of press coverage. Why? HN may be uniquely positioned to show us th…

To be fair, many of us noticed the giant camera in the corner a long time ago. ME has been a holy grail in the security researcher community for a long time, frequently the subject of presentations at conventions. And we have been pestering Intel about this since its inception. But the fact is that it doesn't matter how much outrage you or I may have. It will take enterprise-level shifts away from Intel products to get them to offer chips without ME.

Re: “We have obtained fully functional JTAG for Intel CSME via USB DCI”

#110

Companies like Intel, who are complicit in helping CIA or any intel agency (government, rogue or otherwise) infiltrate and exploit our systems - need to be held accountable by the market. Intel ME and the (assumed [0]) partnership with CIA to design and build this system - should be an absolute travesty blow to the integrity of their business long-term. Will you, as lead engineer or sys admin for your mission critica…

> Intel ME and the (assumed [0]) partnership with CIA to design and build this system I worked at Intel on ME and the things that came before it until around 2013. I can tell you two things -- 1. No, Intel ME wasn't born out of a desire to spy on people nor was it -- to the best of my knowledge but I honestly believe I would know -- created at the request of the US government (or others). It was an honest attempt at…

> No, Intel ME wasn't born out of a desire to spy on people

This is utterly impossible to believe

Post reply on HN