Live data from Hacker News

“We have obtained fully functional JTAG for Intel CSME via USB DCI”

twitter.com

121–130 of 413 posts

Re: “We have obtained fully functional JTAG for Intel CSME via USB DCI”

#121

I worked on what became ME at Intel from the mid 2000s through around 2012 ou 2013. I completely agree that in retrospect, it wasn't the best idea. However, I really want to say that it was never a project for the CIA as some keep saying. This was a widely-marketed product at the time of its inception. It was the whole point of the Intel vPro line. I've been to a ton of roadshows between 2008 and 2009 where the marke…

I've never bought into the "NSA/CIA made Intel create this" line of reasoning because, as you say, there was a legitimate use for this technology (misguided as its implementation was). Of course, I have no doubt that the NSA/CIA may have added further backdoors, or are withholding vulnerabilities in ME.

However, one thing that I've always felt conflicted about is why this feature is present in _all_ CPUs. Usually if someone wants to use Intel's AMT then they have a giant support contract with specialty hardware, so it seems odd that the core CPU feature necessary is present on all CPUs despite no user actually using outside of enterprise.

Is it because the bring-up, other low-level stuff, and things like PASP (DRM) were implemented on top of ME, and so it was not considered viable to re-do that on chips that didn't have ME (though I was under the impression that very early ME was not used for anything else)? Or was it just a matter of "it's easier to just use what we have for every chip"?

Re: “We have obtained fully functional JTAG for Intel CSME via USB DCI”

#122

Earlier quoted context omitted.

> Intel ME and the (assumed [0]) partnership with CIA to design and build this system I worked at Intel on ME and the things that came before it until around 2013. I can tell you two things -- 1. No, Intel ME wasn't born out of a desire to spy on people nor was it -- to the best of my knowledge but I honestly believe I would know -- created at the request of the US government (or others). It was an honest attempt at…

Why would they do something as ridiculous as telling you its true purpose?

They wouldn't. As I said, this is to the best of my knowledge.

However, I believe I would know because it's not like one day the CEO came to us with a folder filled with requirements to be implemented. This is something that started very small ("find a way to force reboot a PC remotely if it's non-responsive") and evolved from there over months/years. I endured way too many meetings were design decisions were made. Unless there were secret CIA agents disguised as my colleagues, I really believe it was designed by Intel engineers all the way through.

I have no issues with people criticizing the product for its failures. I agree with them. But every time I see someone claiming this was a CIA thing, it actually hits me personally.

Then again, I'll never be able to convince anyone of anything. I just felt like saying something this time.

I guess I'm having a bad morning :)

Re: “We have obtained fully functional JTAG for Intel CSME via USB DCI”

#124
post #99
post #95

Earlier quoted context omitted.

> The concern with the Intel ME is that it has a native network adapter. Yep, this is the big deal. After I "discovered" the ME, my first stop on my home network was the switch, to block all that crap. (And I found my storage server, equipped with a Supermicro all-in-one motherboard, helpfully grabbed an IP for the ME to listen on with an 'admin/admin' password.) I just wish the empire builders at the NSA would care…

Am curious how and what exactly you blocked?! What precautions can be taken to make systems more secure?!

As usual, it depends on what exactly you have. Not all chips have the AMT enabled, for instance.

This is a useful document for understanding what exactly you're dealing with and what to do about it:

https://www.blackhat.com/docs/us-17/thursday/us-17-Evdokimov...

Re: “We have obtained fully functional JTAG for Intel CSME via USB DCI”

#125

Companies like Intel, who are complicit in helping CIA or any intel agency (government, rogue or otherwise) infiltrate and exploit our systems - need to be held accountable by the market. Intel ME and the (assumed [0]) partnership with CIA to design and build this system - should be an absolute travesty blow to the integrity of their business long-term. Will you, as lead engineer or sys admin for your mission critica…

> Intel ME and the (assumed [0]) partnership with CIA to design and build this system I worked at Intel on ME and the things that came before it until around 2013. I can tell you two things -- 1. No, Intel ME wasn't born out of a desire to spy on people nor was it -- to the best of my knowledge but I honestly believe I would know -- created at the request of the US government (or others). It was an honest attempt at…

  to the best of my knowledge but I honestly believe I would know
Honestly, if a three letter agency was working with a tech company to produce a back door, the last people I would expect to know would be most of the engineers involved in the implementation.

Re: “We have obtained fully functional JTAG for Intel CSME via USB DCI”

#126
post #21

Earlier quoted context omitted.

It's such a pity that there is no real competition in that area. (Unless you go the totally different architectures such as ARM or RISC-V.) AMD had the chance to differentiate from Intel here, instead they blindly immitate the same customer-hostile stunt.

I don't want to get too deep into imagination, but the details of the ME/PSP story make it seem like an outside force of some sort is compelling them to add this stuff to their platforms.

The invisible hand of the market is sufficient to explain it, no nefarious conspiracy necessary. For servers far away in a data-center, there needs to be some sort of "oh shit" access for when the OS dies, and this is implemented in high-end servers as separate second computer inside the server with its own ethernet port (ILOM), however the extra hardware costs more to manufacture.

Intel decided it wanted a piece of that pie, and in an effort to improve margins, and sell more CPUs, Intel thought: "what if we offer the same feature, but use less hardware?" and made it part of their chipset.

As a feature that businesses actually want, and they buy CPUs in the 10,000's/year, compared to maybe 1/year I might buy for personal use. AMD implemented similar in order to keep up and remain competitive in the market.

Intel desktop chipsets aren't wholly different from their server chipsets, and they share some internals. Intel also realized that, since they already paid for development of the technology that it would be useful for administrators of a computer lab to be able to have remote admin access, and made it a requisite part of all systems.

Again, AMD implemented the same to keep up.

It could also be part of an NSA plot (it is part of their mission, after all), but "the market" where individuals don't count as much as corporate buyers, is sufficient to explain the situation.

Re: “We have obtained fully functional JTAG for Intel CSME via USB DCI”

#127
post #55

Earlier quoted context omitted.

Any clue as to why they chose not to differentiate? Is it too costly to build a separate non-remote CPU for non-enterprise? Does it provide some useful functionality for regular consumers? The answer is probably they do not think there's a market for it, but still makes me wonder.

Enterprise motherboards had IPMI forever. None complained until laymen found out the same thing sits inside -their- computers.

IPMI is supposed to be a tiny computer that listens for authorized network requests to turn on the main machine, reboot it, and connect a serial session to the console so you have a hope of recovering access when somebody has screwed up the main networking configuration.

Loads of us (sysadmins) complained that IPMI (DRAC, LOM...) had frequent security issues, wasn't running open-source code that we could inspect, and kept growing new features without any sense of responsibility. We were especially irked when a dedicated IPMI ethernet port got shared with a micro switch to a normal system ethernet port, and it was not possible to turn that behavior off.

Don't say we didn't complain. Say that we were not successful in having motherboard manufacturers implement the features we want in a secure and controllable manner.

Re: “We have obtained fully functional JTAG for Intel CSME via USB DCI”

#128
post #92

One way to think of ME is, we all woke up one day and discovered we have had high resolution night vision spy cams installed in our bedrooms. The next realization is there is no way to turn them off or remove them. It’s posisble even moving won’t help. And yet we really don’t seem to care much. Lesser issues generate national outrage and high volumes of press coverage. Why? HN may be uniquely positioned to show us th…

> "Apparently, ME is the perfect combination of opaque, obtuse, and obscure. It’s not rocket science, but complicated enough it’s hard to explain well quickly." The way I see it is Intel ME is a processor-level application that has full control of all computer activity and cannot be blocked or disabled and can be accessed and controlled remotely. Would like to hear other people's opinions of what it is.

It's a pretty big thing and parts are necessary, parts are useful, parts are scary, and too much of it is shrouded in secrecy.

Re: “We have obtained fully functional JTAG for Intel CSME via USB DCI”

#129
post #83

Earlier quoted context omitted.

> I think HN is uniquely positioned to show us the answer. Take a community of people with generally above average interest and/or knowledge in this stuff, and the comments are filled with I think it's even more sinister: I would argue that a higher percentage of users on HN might be sworn to secrecy about any knowledge they might have anyway. So you end up with very smart people who're either sworn to secrecy or who…

In the past discussions of the ME here and elsewhere, there have always been people making self-assured poo-pooing noises about what a trivial nonissue it is, make deceptive claims about exposure, and then dumb claims about how you can't trust any hardware. They never reply to particular questions that might point out how deceptive the arguments are.

I'm one of the people that claims you can't trust hardware. Care to elaborate why that's not the case. How does one trust a chip with 14nm transistors? Are you claiming that one can 'simply' decap the chip and examine it with a microscope on a Saturday night? How do I then trust that the chip I have in hand is of the same architecture as the one you decapped and examined?

Re: “We have obtained fully functional JTAG for Intel CSME via USB DCI”

#130

One way to think of ME is, we all woke up one day and discovered we have had high resolution night vision spy cams installed in our bedrooms. The next realization is there is no way to turn them off or remove them. It’s posisble even moving won’t help. And yet we really don’t seem to care much. Lesser issues generate national outrage and high volumes of press coverage. Why? HN may be uniquely positioned to show us th…

Let's be pragmatic. Does anyone know if ME blockers work? Can you please post one if it does? Can we start a list? Are the destination ips it can be controlled from hard coded, can it be blocked via simple firewall rules?

EG tool: https://github.com/corna/me_cleaner

List? https://github.com/ransom1538/intel_me_cleaners/

Post reply on HN