Live data from Hacker News

“We have obtained fully functional JTAG for Intel CSME via USB DCI”

twitter.com

131–140 of 413 posts

Re: “We have obtained fully functional JTAG for Intel CSME via USB DCI”

#131
post #29

Earlier quoted context omitted.

I don't want to get too deep into imagination, but the details of the ME/PSP story make it seem like an outside force of some sort is compelling them to add this stuff to their platforms.

It's indeed nice to imagine that the people behind Intel are relieved that somebody finally found the kill-switch they left behind in the monster they had to create. And the AMD people now thinking hard how they can leak hints to their kill-switch in an inconspicuous way, too. But that's indeed imagination. Unforunately, we don't (yet) know much about their motivations.

I love this Intel redemption arc!

Re: “We have obtained fully functional JTAG for Intel CSME via USB DCI”

#132

Companies like Intel, who are complicit in helping CIA or any intel agency (government, rogue or otherwise) infiltrate and exploit our systems - need to be held accountable by the market. Intel ME and the (assumed [0]) partnership with CIA to design and build this system - should be an absolute travesty blow to the integrity of their business long-term. Will you, as lead engineer or sys admin for your mission critica…

> Intel ME and the (assumed [0]) partnership with CIA to design and build this system I worked at Intel on ME and the things that came before it until around 2013. I can tell you two things -- 1. No, Intel ME wasn't born out of a desire to spy on people nor was it -- to the best of my knowledge but I honestly believe I would know -- created at the request of the US government (or others). It was an honest attempt at…

Right. ME does make sense as a feature for sysadmins. Except . . . . Well, can you shed light on the following:

1. Why did your team deem it necessary to deny the end-user the capability to disable this feature?

2. Why did your team decide to enable ME on ALL consumer grade chips? You could have only enabled it on, say, Xeon, as a value-add - exactly like you do for ECC support. You could have made more money this way. But . . . you didn't.

Without legitimate, sensical answers to the above questions, there is no reason for anyone to believe your team did anything other than design a backdoor for the Feds. Sorry.

Re: “We have obtained fully functional JTAG for Intel CSME via USB DCI”

#133

Earlier quoted context omitted.

Why would they do something as ridiculous as telling you its true purpose?

They wouldn't. As I said, this is to the best of my knowledge. However, I believe I would know because it's not like one day the CEO came to us with a folder filled with requirements to be implemented. This is something that started very small ("find a way to force reboot a PC remotely if it's non-responsive") and evolved from there over months/years. I endured way too many meetings were design decisions were made. U…

> Unless there were secret CIA agents disguised as my colleagues

That's a thing actually.

> I'll never be able to convince anyone of anything.

I believe you. Conspiracy theories are fun but ultimately I know that secrets are hard to keep secret.

Re: “We have obtained fully functional JTAG for Intel CSME via USB DCI”

#134

I worked on what became ME at Intel from the mid 2000s through around 2012 ou 2013. I completely agree that in retrospect, it wasn't the best idea. However, I really want to say that it was never a project for the CIA as some keep saying. This was a widely-marketed product at the time of its inception. It was the whole point of the Intel vPro line. I've been to a ton of roadshows between 2008 and 2009 where the marke…

It makes perfect sense in the enterprise space to facilitate the illusion of management control (there is a good reason the IT dept trope is so widespread). LOM has been a thing on servers since forever. And absent some enormous financial incentive, it's absurd to think that Intel would go through this much trouble to architect something like this with a primary goal of providing American three letter agencies a backdoor. On the other hand, the magic killswitch you guys put in equally obviously was requested by them, this thing basically makes anything with an Intel desktop CPU unusuable in a high-security context.

But given the already well-known threat model at the time this thing was conceived of self-propagating malware, creating a technology that is embedded in every single device with a desktop CPU that can't be turned off, makes the device unusable without it, and has remote compromise bugs that can succeed while the target is "off" was certainly a bad idea.

Re: “We have obtained fully functional JTAG for Intel CSME via USB DCI”

#135
post #83

Earlier quoted context omitted.

In the past discussions of the ME here and elsewhere, there have always been people making self-assured poo-pooing noises about what a trivial nonissue it is, make deceptive claims about exposure, and then dumb claims about how you can't trust any hardware. They never reply to particular questions that might point out how deceptive the arguments are.

I'm one of the people that claims you can't trust hardware. Care to elaborate why that's not the case. How does one trust a chip with 14nm transistors? Are you claiming that one can 'simply' decap the chip and examine it with a microscope on a Saturday night? How do I then trust that the chip I have in hand is of the same architecture as the one you decapped and examined?

This is how I feel -> I've treated every device I've had for the last decade as if it were compromised, because who can prove to me otherwise? I certainly don't have the expertise to verify for myself.

Re: “We have obtained fully functional JTAG for Intel CSME via USB DCI”

#136

One way to think of ME is, we all woke up one day and discovered we have had high resolution night vision spy cams installed in our bedrooms. The next realization is there is no way to turn them off or remove them. It’s posisble even moving won’t help. And yet we really don’t seem to care much. Lesser issues generate national outrage and high volumes of press coverage. Why? HN may be uniquely positioned to show us th…

To be fair, many of us noticed the giant camera in the corner a long time ago. ME has been a holy grail in the security researcher community for a long time, frequently the subject of presentations at conventions. And we have been pestering Intel about this since its inception. But the fact is that it doesn't matter how much outrage you or I may have. It will take enterprise-level shifts away from Intel products to g…

What about AMD? Which chips does the sec-comm recommend for not getting pwnd

Re: “We have obtained fully functional JTAG for Intel CSME via USB DCI”

#137
post #63

Earlier quoted context omitted.

The 'evil maid' attack is well known, and states that once someone has physical access to your computer, all bets are off. Anything that has DMA enabled (e.g. Firewire or Thunderbolt) offers an external device direct access to the system RAM that is very difficult to defend against, or they could attach a keylogger or modify your bootloader, basically unleash all manner of havok. USB JTAG is really no different from…

> Anything that has DMA enabled (e.g. Firewire or Thunderbolt) offers an external device direct access to the system RAM that is very difficult to defend against IOMMU effectively solves the "DMA is completely broken" problem, as far as I'm aware. Evil Maid attacks are mostly worrisome because even UEFI cannot protect you against some bootloader attacks (what if you disable UEFI or reflash the firmware and then have…

Oh so....every port on my laptop? Fuck Apple

Re: “We have obtained fully functional JTAG for Intel CSME via USB DCI”

#139
post #3

Can someone explain like I have a degree in computer science from a good university, but opted for a career as a software engineer in some relatively high level languages?

I'll give a try. Someone else can correct me later. These guys have used a JTAG f debugging dongle to access the Intel management engine. They can now read every bit of code. Which means that secrets stored within the code including keys and bugs are available to them and anyone who can replicate their work. Since the management engine is in nearly all of Intel chips, we're screwed. AMD have something similar so no h…

Is this seen in ARM?

Re: “We have obtained fully functional JTAG for Intel CSME via USB DCI”

#140

Earlier quoted context omitted.

Why would they do something as ridiculous as telling you its true purpose?

They wouldn't. As I said, this is to the best of my knowledge. However, I believe I would know because it's not like one day the CEO came to us with a folder filled with requirements to be implemented. This is something that started very small ("find a way to force reboot a PC remotely if it's non-responsive") and evolved from there over months/years. I endured way too many meetings were design decisions were made. U…

I believe you.

But looking at the International Obfuscated C Code Contest (http://www.ioccc.org/) entries, and knowing how much I have to force my eyes not to glaze over whenever a college sends me a 700 line pull-request, if one of your colleagues waited until the deadline to send a massive pull-request for their part of the project, can you say that the deadline is pushed back until every single line is meticulously analyzed by hand, to assert that nothing nefarious could possibly happen with their code?

Just one of your coworkers would need to believe in a greater purpose, for king and country, and grown up in a large family with a brother or cousin who's a part of the intelligence community.

It sounds far-fetched, but so does the Bay of Pigs.

Post reply on HN