Live data from Hacker News

“We have obtained fully functional JTAG for Intel CSME via USB DCI”

twitter.com

171–180 of 413 posts

Re: “We have obtained fully functional JTAG for Intel CSME via USB DCI”

#171

One way to think of ME is, we all woke up one day and discovered we have had high resolution night vision spy cams installed in our bedrooms. The next realization is there is no way to turn them off or remove them. It’s posisble even moving won’t help. And yet we really don’t seem to care much. Lesser issues generate national outrage and high volumes of press coverage. Why? HN may be uniquely positioned to show us th…

>One way to think of ME is, we all woke up one day and discovered we have had high resolution night vision spy cams installed in our bedrooms.

Sure, if by one day you mean - for the past 10 years? And if by spy cams you mean - A product with official documentation from the vendor, and similar to other products from other vendors. And these products can be purchased by anyone.

You have some valid points, but they are clouded by your sweeping generalizations and needlessly polarizing language.

Re: “We have obtained fully functional JTAG for Intel CSME via USB DCI”

#172
post #120

Earlier quoted context omitted.

Plenty of people were still saying the Snowden revelations were old hat when they came out, we all knew it was happening just didn't have proof, etc. The novelty and seriousness tends to be out-of-whack with the amount of news coverage. It's a poor way to measure the importance of existing news coverage or lack of it for that reason. What matters is that it gets out and incentivizes developers, manufacturers, company…

Prior to the NSA contractor Edward Snowden's revelations in 2013, Room-641A had already been exposed by an AT&T employee-turned-whistleblower Mark Klein. The EFF sued the government in 2006 over it. Tape over laptop cameras isn't just a "parents-of-friends" thing, it's a good idea. Buy a set of stickers and support the EFF: https://supporters.eff.org/shop/laptop-camera-cover-set Anyone know somebody at Wired?

We should start demanding physical shutters for laptop webcams. Does anyone make those yet?

Re: “We have obtained fully functional JTAG for Intel CSME via USB DCI”

#173

Earlier quoted context omitted.

> Intel ME and the (assumed [0]) partnership with CIA to design and build this system I worked at Intel on ME and the things that came before it until around 2013. I can tell you two things -- 1. No, Intel ME wasn't born out of a desire to spy on people nor was it -- to the best of my knowledge but I honestly believe I would know -- created at the request of the US government (or others). It was an honest attempt at…

Why doesn't Intel offer their chips without an ME, as an option? The mandatory nature makes it malicious.

What percentage of people would really want that? The vast majority of consumers don’t know/care. Or it’s sold as a feature.

Most businesses probaby WANT the feature. See other comments in this discussion about lights-out management.

I’m guessing t wouldn’t be economically worth it.

Re: “We have obtained fully functional JTAG for Intel CSME via USB DCI”

#174
post #3

Can someone explain like I have a degree in computer science from a good university, but opted for a career as a software engineer in some relatively high level languages?

I'm going to assume "relatively high level languages" are for example Python, Ruby, C#, Javascript... Imagine that you have your high level program. When you execute it, it goes through a just-in-time compilation (whether that's script parsing or bytecode conversion, or actual compilation, or whatever) before reaching the CPU which actually executes your code. Now imagine that your interpreter has the capability of r…

> It allows a remote party to inject their own flow of execution into your program.

Thanks for your helpful explanation. This bit sounds particularly bad - is the really possible in practice or just theoretical? Is there any source that has shown this?

Re: “We have obtained fully functional JTAG for Intel CSME via USB DCI”

#175
post #144

One way to think of ME is, we all woke up one day and discovered we have had high resolution night vision spy cams installed in our bedrooms. The next realization is there is no way to turn them off or remove them. It’s posisble even moving won’t help. And yet we really don’t seem to care much. Lesser issues generate national outrage and high volumes of press coverage. Why? HN may be uniquely positioned to show us th…

It's not that "we really don't seem to care much" It's that even those of us that care vehemently, have no recourse. It is impossible to fight a secret police state.

Well with that attitude it is...

Part of winning is to even begin to believe you can fight...

Re: “We have obtained fully functional JTAG for Intel CSME via USB DCI”

#176
post #65

Earlier quoted context omitted.

Many people will now start to dig in. War is started and I hope somebody will find a way to totally remove/replace(with a stub) Intel ME before some critical vulnerability will be discovered in the Intel ME's network stack. In white hats we trust :)

me_cleaner already exists[1], and it takes advantage of several flaws in Intel ME's signing to remove large sections of the code thus neutering it. Some code still exists, but Intel ME cannot actually fully initialise on "cleaned" systems. Older machines used to have a bug where if you filled the first half of the Intel ME firmware with zeros the machine would boot but ME wouldn't start at all. But yes, I hope that w…

Is this enough to block this attack? That is, is a "cleaned" system vulnerable to a USB device?

Re: “We have obtained fully functional JTAG for Intel CSME via USB DCI”

#177
post #152
post #149

Earlier quoted context omitted.

4chan has been popular for leaks/reverse engineering because of its anonymity and the fact that it's seen as (whether or not this is true, and I would wager that it isn't) as a "hacker haven". For example, a guy on 4chan reverse engineered Google's new captcha system almost as soon as it came out, leading Google to eventually hire him in exchange for his deleting the GitHub repo he was using.

4chan is also well known to fabricate evidence, and everything in the post (minus the alleged backdoors) has been publicly known.

Some diamonds, lots of rubble. Some land mines:)

Re: “We have obtained fully functional JTAG for Intel CSME via USB DCI”

#178
post #172

Earlier quoted context omitted.

Prior to the NSA contractor Edward Snowden's revelations in 2013, Room-641A had already been exposed by an AT&T employee-turned-whistleblower Mark Klein. The EFF sued the government in 2006 over it. Tape over laptop cameras isn't just a "parents-of-friends" thing, it's a good idea. Buy a set of stickers and support the EFF: https://supporters.eff.org/shop/laptop-camera-cover-set Anyone know somebody at Wired?

We should start demanding physical shutters for laptop webcams. Does anyone make those yet?

C-slide dot com, the iPad one (round with a pivot) is my favourite

Re: “We have obtained fully functional JTAG for Intel CSME via USB DCI”

#179

Earlier quoted context omitted.

> Intel ME and the (assumed [0]) partnership with CIA to design and build this system I worked at Intel on ME and the things that came before it until around 2013. I can tell you two things -- 1. No, Intel ME wasn't born out of a desire to spy on people nor was it -- to the best of my knowledge but I honestly believe I would know -- created at the request of the US government (or others). It was an honest attempt at…

Right. ME does make sense as a feature for sysadmins. Except . . . . Well, can you shed light on the following: 1. Why did your team deem it necessary to deny the end-user the capability to disable this feature? 2. Why did your team decide to enable ME on ALL consumer grade chips? You could have only enabled it on, say, Xeon, as a value-add - exactly like you do for ECC support. You could have made more money this wa…

> Why did your team decide to enable ME on ALL consumer grade chips?

Can you please provide a reference? I've been trying to enable ME forever for my consumer-grade i7 with Intel motherboard for remote management, and I can't seem to be able to.

Re: “We have obtained fully functional JTAG for Intel CSME via USB DCI”

#180
post #32

At first it looks nice "oh now we can get rid of it" but it also opens up a very scary near future security-wise. We've now entered a realm where an attacker could simply plug a device on an usb port of your computer for a few seconds to have it access your cpu's ME through USB JTAG and take over it, allowing him to have full access and control over what you do/read/open/type over the network, without you ever knowin…

The vulnerability exists, wether someone reveals it to the public or not. These people found it with Intel keeping the working of the system under wraps as much as possible. You can imagine the kind of access available to people who did get to see the source code. At least now that everyone can see the problem people can make informed decisions.

I would think those people are under constant threat of being kidnapped for their information
Post reply on HN