Live data from Hacker News

“We have obtained fully functional JTAG for Intel CSME via USB DCI”

twitter.com

181–190 of 413 posts

Re: “We have obtained fully functional JTAG for Intel CSME via USB DCI”

#181
post #65

Earlier quoted context omitted.

me_cleaner already exists[1], and it takes advantage of several flaws in Intel ME's signing to remove large sections of the code thus neutering it. Some code still exists, but Intel ME cannot actually fully initialise on "cleaned" systems. Older machines used to have a bug where if you filled the first half of the Intel ME firmware with zeros the machine would boot but ME wouldn't start at all. But yes, I hope that w…

Is this enough to block this attack? That is, is a "cleaned" system vulnerable to a USB device?

DMA/Firewire over USB makes pretty much every systen vulnerable to USB attacks (ME aside.)

Re: “We have obtained fully functional JTAG for Intel CSME via USB DCI”

#182

Companies like Intel, who are complicit in helping CIA or any intel agency (government, rogue or otherwise) infiltrate and exploit our systems - need to be held accountable by the market. Intel ME and the (assumed [0]) partnership with CIA to design and build this system - should be an absolute travesty blow to the integrity of their business long-term. Will you, as lead engineer or sys admin for your mission critica…

> Intel ME and the (assumed [0]) partnership with CIA to design and build this system I worked at Intel on ME and the things that came before it until around 2013. I can tell you two things -- 1. No, Intel ME wasn't born out of a desire to spy on people nor was it -- to the best of my knowledge but I honestly believe I would know -- created at the request of the US government (or others). It was an honest attempt at…

> > Intel ME and the (assumed [0]) partnership with CIA to design and build this system

Then why do you need security clearance to work on Intel ME?

Re: “We have obtained fully functional JTAG for Intel CSME via USB DCI”

#183
post #172

Earlier quoted context omitted.

Prior to the NSA contractor Edward Snowden's revelations in 2013, Room-641A had already been exposed by an AT&T employee-turned-whistleblower Mark Klein. The EFF sued the government in 2006 over it. Tape over laptop cameras isn't just a "parents-of-friends" thing, it's a good idea. Buy a set of stickers and support the EFF: https://supporters.eff.org/shop/laptop-camera-cover-set Anyone know somebody at Wired?

We should start demanding physical shutters for laptop webcams. Does anyone make those yet?

Even better is a hardware kill switch, especially for the mic.

Re: “We have obtained fully functional JTAG for Intel CSME via USB DCI”

#184
post #121

I worked on what became ME at Intel from the mid 2000s through around 2012 ou 2013. I completely agree that in retrospect, it wasn't the best idea. However, I really want to say that it was never a project for the CIA as some keep saying. This was a widely-marketed product at the time of its inception. It was the whole point of the Intel vPro line. I've been to a ton of roadshows between 2008 and 2009 where the marke…

I've never bought into the "NSA/CIA made Intel create this" line of reasoning because, as you say, there was a legitimate use for this technology (misguided as its implementation was). Of course, I have no doubt that the NSA/CIA may have added further backdoors, or are withholding vulnerabilities in ME. However, one thing that I've always felt conflicted about is why this feature is present in _all_ CPUs. Usually if…

I really don't understand why I have to pay out the nose for ECC memory support but I get this surveillance device "for free".

Re: “We have obtained fully functional JTAG for Intel CSME via USB DCI”

#185

Companies like Intel, who are complicit in helping CIA or any intel agency (government, rogue or otherwise) infiltrate and exploit our systems - need to be held accountable by the market. Intel ME and the (assumed [0]) partnership with CIA to design and build this system - should be an absolute travesty blow to the integrity of their business long-term. Will you, as lead engineer or sys admin for your mission critica…

> Intel ME and the (assumed [0]) partnership with CIA to design and build this system I worked at Intel on ME and the things that came before it until around 2013. I can tell you two things -- 1. No, Intel ME wasn't born out of a desire to spy on people nor was it -- to the best of my knowledge but I honestly believe I would know -- created at the request of the US government (or others). It was an honest attempt at…

Why not make a physical turn off switch on motherboard to disable it?

Re: “We have obtained fully functional JTAG for Intel CSME via USB DCI”

#186
post #120

Earlier quoted context omitted.

Plenty of people were still saying the Snowden revelations were old hat when they came out, we all knew it was happening just didn't have proof, etc. The novelty and seriousness tends to be out-of-whack with the amount of news coverage. It's a poor way to measure the importance of existing news coverage or lack of it for that reason. What matters is that it gets out and incentivizes developers, manufacturers, company…

Prior to the NSA contractor Edward Snowden's revelations in 2013, Room-641A had already been exposed by an AT&T employee-turned-whistleblower Mark Klein. The EFF sued the government in 2006 over it. Tape over laptop cameras isn't just a "parents-of-friends" thing, it's a good idea. Buy a set of stickers and support the EFF: https://supporters.eff.org/shop/laptop-camera-cover-set Anyone know somebody at Wired?

> Tape over laptop cameras isn't just a "parents-of-friends" thing, it's a good idea. Buy a set of stickers and support the EFF: https://supporters.eff.org/shop/laptop-camera-cover-set

Support the EFF! But I hate the stickers.

Everyone puts a sticker on their webcam and completely ignores the hot mic. But you get that false sense of security…

Re: “We have obtained fully functional JTAG for Intel CSME via USB DCI”

#187
post #164

Earlier quoted context omitted.

To add, and maybe the others can correct me if I'm wrong: Intel ME can be controlled remotely if you have an Intel lan card, even if the main cpu is off, but the motherboard is powered on. It goes from there and gets worse is my understanding.

Yup, that's AMT, enabled on vPro-series and Xeon chips only though

Ah, thanks for the clarification.

Re: “We have obtained fully functional JTAG for Intel CSME via USB DCI”

#188
post #162
post #118

Earlier quoted context omitted.

> while there are mitigations for the evil maid attack (like an encrypted drive and shutting down -not just suspending, when the machine is out of sight), That mitigation is useless against Evil Maid. There are much more sophisticated mitigations (using a TPM to measure the boot, and then do something akin to TOTP in order to allow the user to actually verify the state of the machine) which actually could protect aga…

The TPM is actually implemented as an Intel ME applet on a lot of PCs... >.<

Right, but there is a TPM pin-out standard -- so theoretically you could swap out the TPM of any device (which has a physical TPM obviously) with any other manufacturer's TPM and it would still "just work". While it might be implemented in Intel ME, there are a lot of laptops that have physical TPM chips.

Re: “We have obtained fully functional JTAG for Intel CSME via USB DCI”

#189
post #173

Earlier quoted context omitted.

Why doesn't Intel offer their chips without an ME, as an option? The mandatory nature makes it malicious.

What percentage of people would really want that? The vast majority of consumers don’t know/care. Or it’s sold as a feature. Most businesses probaby WANT the feature. See other comments in this discussion about lights-out management. I’m guessing t wouldn’t be economically worth it.

If you’re not using it, then it’s a big unpatched vulnerability. I’ve never worked anywhere that uses it, although I’m sure a few places do.

Re: “We have obtained fully functional JTAG for Intel CSME via USB DCI”

#190

Earlier quoted context omitted.

Right. ME does make sense as a feature for sysadmins. Except . . . . Well, can you shed light on the following: 1. Why did your team deem it necessary to deny the end-user the capability to disable this feature? 2. Why did your team decide to enable ME on ALL consumer grade chips? You could have only enabled it on, say, Xeon, as a value-add - exactly like you do for ECC support. You could have made more money this wa…

I'm not OP, but to respond to question 1, allowing users to disable the feature would also allow attackers to disable the feature. If you're relying on ME to provide remote access so that you can clean and repair infected machines, then it's game over for you if the attacker can disable ME. It would have made much more sense to require you to enable it before first use, and ship it as disabled from the factory. Enabl…

"I'm not OP, but to respond to question 1, allowing users to disable the feature would also allow attackers to disable the feature."

Older products had jumpers, physical switches, or software mechanisms for securely updating firmware. The first two are immune to most types of remote attacks if done in hardware. Intel already uses signed updates for microcode which people aren't compromising remotely left and right. Intel supporting a mechanism like those that already existed in the market for disabling the backdoor would not give widespread, remote access to systems. If anything, it would block it by having less privileged, 0-day-ridden software running.

I'll also note that the non-Intel market, from OpenPOWER to embedded, has options ranging from open firmware (incl Open Firmware itself) to physical mechanisms to 3rd-party-software. Intel is ignoring those on purpose for reasons they aren't disclosing to the users that also probably don't benefit them.

Post reply on HN