Live data from Hacker News

“We have obtained fully functional JTAG for Intel CSME via USB DCI”

twitter.com

151–160 of 413 posts

Re: “We have obtained fully functional JTAG for Intel CSME via USB DCI”

#151
post #83

Earlier quoted context omitted.

In the past discussions of the ME here and elsewhere, there have always been people making self-assured poo-pooing noises about what a trivial nonissue it is, make deceptive claims about exposure, and then dumb claims about how you can't trust any hardware. They never reply to particular questions that might point out how deceptive the arguments are.

I'm one of the people that claims you can't trust hardware. Care to elaborate why that's not the case. How does one trust a chip with 14nm transistors? Are you claiming that one can 'simply' decap the chip and examine it with a microscope on a Saturday night? How do I then trust that the chip I have in hand is of the same architecture as the one you decapped and examined?

You are of course correct that in the general case for threat models above a risk threshold, one cannot trust hardware. But that is not the argument under discussion. The argument being made is that it doesn't matter if the ME is a big fat target, because (f'instance) your NIC could also be a big fat target we just don't know about.

That is the argument I am asserting is dumb. And it is obviously dumb; in adversarial contests, you don't leave weaknesses exposed just because you might have other weaknesses[1]. It also ignores the presence of differential threats; I may not care about hypothetical compromised NICs because my use case my not require a network, but need anti-evil-maid defenses.

Bottom line: in the context of discussing whether or not the ME is dangerous in the general case, other potential hardware threats are irrelevant, and I believe the argument is one used to intentionally muddy the waters.

[1] Putting aside deeper strategies; I'm not going to argue about game theory here.

Re: “We have obtained fully functional JTAG for Intel CSME via USB DCI”

#152
post #149
post #91

Earlier quoted context omitted.

Seriously? A 4chan post? While the ME is worrying for many reasons, there's absolutely zero evidence that the Intel ME contains a backdoor. Backdoors don't stay hidden forever.

4chan has been popular for leaks/reverse engineering because of its anonymity and the fact that it's seen as (whether or not this is true, and I would wager that it isn't) as a "hacker haven". For example, a guy on 4chan reverse engineered Google's new captcha system almost as soon as it came out, leading Google to eventually hire him in exchange for his deleting the GitHub repo he was using.

4chan is also well known to fabricate evidence, and everything in the post (minus the alleged backdoors) has been publicly known.

Re: “We have obtained fully functional JTAG for Intel CSME via USB DCI”

#153

Earlier quoted context omitted.

What do you think the headline about Intel be in Russian media?

Most likely they will be quiet because Russia is 100% dependent on foreign technology.

Not the military.

Re: “We have obtained fully functional JTAG for Intel CSME via USB DCI”

#154

Earlier quoted context omitted.

Why would they do something as ridiculous as telling you its true purpose?

They wouldn't. As I said, this is to the best of my knowledge. However, I believe I would know because it's not like one day the CEO came to us with a folder filled with requirements to be implemented. This is something that started very small ("find a way to force reboot a PC remotely if it's non-responsive") and evolved from there over months/years. I endured way too many meetings were design decisions were made. U…

[deleted]

Re: “We have obtained fully functional JTAG for Intel CSME via USB DCI”

#155

Earlier quoted context omitted.

> Intel ME and the (assumed [0]) partnership with CIA to design and build this system I worked at Intel on ME and the things that came before it until around 2013. I can tell you two things -- 1. No, Intel ME wasn't born out of a desire to spy on people nor was it -- to the best of my knowledge but I honestly believe I would know -- created at the request of the US government (or others). It was an honest attempt at…

Right. ME does make sense as a feature for sysadmins. Except . . . . Well, can you shed light on the following: 1. Why did your team deem it necessary to deny the end-user the capability to disable this feature? 2. Why did your team decide to enable ME on ALL consumer grade chips? You could have only enabled it on, say, Xeon, as a value-add - exactly like you do for ECC support. You could have made more money this wa…

I'm not OP, but to respond to question 1, allowing users to disable the feature would also allow attackers to disable the feature. If you're relying on ME to provide remote access so that you can clean and repair infected machines, then it's game over for you if the attacker can disable ME.

It would have made much more sense to require you to enable it before first use, and ship it as disabled from the factory. Enablement should work like blowing an eFuse where it's never off once it's turned on, but if you never turn it on it doesn't exist. Then I don't have to worry about the feature unless I know exactly what it is and how to use it.

Re: “We have obtained fully functional JTAG for Intel CSME via USB DCI”

#156

One way to think of ME is, we all woke up one day and discovered we have had high resolution night vision spy cams installed in our bedrooms. The next realization is there is no way to turn them off or remove them. It’s posisble even moving won’t help. And yet we really don’t seem to care much. Lesser issues generate national outrage and high volumes of press coverage. Why? HN may be uniquely positioned to show us th…

>And yet we really don’t seem to care much. Lesser issues generate national outrage and high volumes of press coverage. Why?

From what I noticed recently, issues only generate outrage if they can be blamed on Trump or republicans. Nobody cared about ISPs collecting user data since the early 2010s until republicans reverted a plan to forbid that in the future.

Maybe the story would pick up traction if it was peppered with the photos of Trump meeting with Intel's CEO.

Re: “We have obtained fully functional JTAG for Intel CSME via USB DCI”

#157

Earlier quoted context omitted.

To be fair, many of us noticed the giant camera in the corner a long time ago. ME has been a holy grail in the security researcher community for a long time, frequently the subject of presentations at conventions. And we have been pestering Intel about this since its inception. But the fact is that it doesn't matter how much outrage you or I may have. It will take enterprise-level shifts away from Intel products to g…

What about AMD? Which chips does the sec-comm recommend for not getting pwnd

AMD and ARM have 'TrustZone', which is not the same, but if you don't trust it maybe you're in trouble.

Re: “We have obtained fully functional JTAG for Intel CSME via USB DCI”

#159
This is fantastic news. I expect to see some reliable and easy to apply (usb?) solution to wipe and tame ME.

Greatest news is that it works for latest Intel processors so even if they change protection (they certainly will) we at least have very good processors that can work without spyware. All the previous tests I read about only tackled first few generations of Intel ME, for processors/boards over 8 or 10 years old.

Re: “We have obtained fully functional JTAG for Intel CSME via USB DCI”

#160
post #90

Earlier quoted context omitted.

"opaque, obtuse, and obscure" is a red herring. Imagine, Intel were a Russian company. Tomorrow, there would be a simple and clear [screaming] headline similar to "Russians hacked the election" (general public doesn't need to know or understand how the network, computers or elections actually work). The day after tomorrow it would be illegal to buy anything Intel.

What do you think the headline about Intel be in Russian media?

Intel ME is not new. You don't need to imagine it, you could google it.
Post reply on HN