Live data from Hacker News

“We have obtained fully functional JTAG for Intel CSME via USB DCI”

twitter.com

201–210 of 413 posts

Re: “We have obtained fully functional JTAG for Intel CSME via USB DCI”

#201
post #65

Earlier quoted context omitted.

me_cleaner already exists[1], and it takes advantage of several flaws in Intel ME's signing to remove large sections of the code thus neutering it. Some code still exists, but Intel ME cannot actually fully initialise on "cleaned" systems. Older machines used to have a bug where if you filled the first half of the Intel ME firmware with zeros the machine would boot but ME wouldn't start at all. But yes, I hope that w…

Is this enough to block this attack? That is, is a "cleaned" system vulnerable to a USB device?

I don't know, because there is very little detail about what this attack is and how it works. It looks like they managed to thwart whatever protections exist in the USB DCI (Direct Connect Interface)[1] which is a debugging system for Intel chips.

If they have full debugger access to what's running in Intel ME then removing the code from the firmware probably doesn't make a difference (assuming they can run un-trusted code in that context). If they cannot write their own code and so an attack requires ROP gadgets then removing the code might make it harder (or impossible) to do, but I doubt it.

[1]: http://www2.lauterbach.com/pdf/directory.pdf#M8.newlink.DIR6...

Re: “We have obtained fully functional JTAG for Intel CSME via USB DCI”

#202
post #167

Earlier quoted context omitted.

That's a bad argument. Firstly, it's my understanding that there have already been root-access 0 days discovered in the ME (and since patched since exposed). AND The USB jtag backdoor is the whole point of this post. Secondly, a security hole and a backdoor are interchangeable these days. So we'll never be able to prove which new 0-days are deliberate, and as far as impact it kinda doesn't matter if they're deliberat…

We're talking about deliberate government backdoors, and it's my opinion that those are highly unlikely. The ME is a really bad idea because it introduces massive, unnecessary attack surface and vulnerabilities are inevitable, but no conspiracy.

How can you prove a vulnerability isn't deliberate?

We've seen deliberate security vulnerabilities before (DUAL_EC).

Re: “We have obtained fully functional JTAG for Intel CSME via USB DCI”

#203
post #120

Earlier quoted context omitted.

Plenty of people were still saying the Snowden revelations were old hat when they came out, we all knew it was happening just didn't have proof, etc. The novelty and seriousness tends to be out-of-whack with the amount of news coverage. It's a poor way to measure the importance of existing news coverage or lack of it for that reason. What matters is that it gets out and incentivizes developers, manufacturers, company…

Prior to the NSA contractor Edward Snowden's revelations in 2013, Room-641A had already been exposed by an AT&T employee-turned-whistleblower Mark Klein. The EFF sued the government in 2006 over it. Tape over laptop cameras isn't just a "parents-of-friends" thing, it's a good idea. Buy a set of stickers and support the EFF: https://supporters.eff.org/shop/laptop-camera-cover-set Anyone know somebody at Wired?

> Tape over laptop cameras isn't just a "parents-of-friends" thing

Not sure why you took that statement as deriding the practice because some older people are doing it? I noted it merely as an indication of how far the behavioural change has spread as a result of news stories... Of course it's good security hygiene. Not an ideal solution though, as others have already mentioned, compared to a hardware switch or built-in cover.

Re: “We have obtained fully functional JTAG for Intel CSME via USB DCI”

#204

One way to think of ME is, we all woke up one day and discovered we have had high resolution night vision spy cams installed in our bedrooms. The next realization is there is no way to turn them off or remove them. It’s posisble even moving won’t help. And yet we really don’t seem to care much. Lesser issues generate national outrage and high volumes of press coverage. Why? HN may be uniquely positioned to show us th…

> And yet we really don’t seem to care much. I know we're used to "Internet speed" and the tweet happened an entire 24 hours ago, but give it a bit of time before declaring it dead. Wired and Vice need a second to write it up, and see if it hits the mainstream before declaring the issue ignored. Not saying it will get picked up, though I sure hope it does, but as you point out, it's a bit obscure and takes some expla…

> A Facebook exec's claim doesn't count as proof.

How about an official statement from Facebook itself over a year ago[1]? If it was true, people could find out by decompiling the app and make Facebook look absolutely horrible.

[1] https://newsroom.fb.com/news/h/facebook-does-not-use-your-ph...

Re: “We have obtained fully functional JTAG for Intel CSME via USB DCI”

#205

I worked on what became ME at Intel from the mid 2000s through around 2012 ou 2013. I completely agree that in retrospect, it wasn't the best idea. However, I really want to say that it was never a project for the CIA as some keep saying. This was a widely-marketed product at the time of its inception. It was the whole point of the Intel vPro line. I've been to a ton of roadshows between 2008 and 2009 where the marke…

Three questions if you don't mind (and feel free to speculate yourself or anyone else): 1. Many features have options to be disabled (e.g. bios settings). Why doesn't this, even to this day? 2. You may have been involved in implementation, but do you know why it still exists on every board regardless of backlash? 3. I am a bit ignorant, does the chip fabbing process justify putting this on every board instead of just…

I can answer 2 and 3. 2. IMHO I don’t think there is enough backlash yet. The average consumer is not informed about this yet. I guess this will change over the next couple of months since I’ve been reading a lot more about ME. 3. The chipset is fabbed irrespective of the SKU. Creating a separate floor plan for non enterprise parts is not cost effective , it’s easier to fab every SKU alike and then fuse out features based on the SKU.

Re: “We have obtained fully functional JTAG for Intel CSME via USB DCI”

#206
post #167

Earlier quoted context omitted.

We're talking about deliberate government backdoors, and it's my opinion that those are highly unlikely. The ME is a really bad idea because it introduces massive, unnecessary attack surface and vulnerabilities are inevitable, but no conspiracy.

How can you prove a vulnerability isn't deliberate? We've seen deliberate security vulnerabilities before (DUAL_EC).

You can't, but let me point out that DUAL_EC was a "nobody but us" backdoor that required their private key to use.

(and yes, it backfired)

If they're introducing regular vulnerabilities, they're also making themselves vulnerable, given that the US government is one of the biggest Intel customers.

Re: “We have obtained fully functional JTAG for Intel CSME via USB DCI”

#207
post #200

Earlier quoted context omitted.

Even better is a hardware kill switch, especially for the mic.

I managed to unplug the mic in my Thinkpad and my Dell XPS laptop with about 5min of work for each. It's still possible to do at the moment if you don't mind relying on plugging in headphones w/ a mic to use one. Of course a switch would be nice, similar to the older Thinkpads which had a hardware switch for the network devices on the front, originally for use on airplanes.

> I managed to unplug the mic in my Thinkpad

Any chance you documented the procedure or have links to relevant documentation?

Re: “We have obtained fully functional JTAG for Intel CSME via USB DCI”

#208

One way to think of ME is, we all woke up one day and discovered we have had high resolution night vision spy cams installed in our bedrooms. The next realization is there is no way to turn them off or remove them. It’s posisble even moving won’t help. And yet we really don’t seem to care much. Lesser issues generate national outrage and high volumes of press coverage. Why? HN may be uniquely positioned to show us th…

> And yet we really don’t seem to care much.

I do care, a lot. I have decided to avoid Intel (and AMD) hardware like the pest. I will not buy any Core iSpyOnYou or AMD equivalent anymore. I'm an advocate of economic and judicial sanctions from the political level against Intel (and AMD). I tell people around me about the problems and explain how it is an issue of privacy, security, national sovereignty, and market power abuse.

I'm looking for a desktop computer for my day to day use that comes without compromised hardware. The Raspberry Pi 3 works quite well, but doesnt work without non-free software. I successfully installed Debian onto my A20-OLinuXino-MICRO, but the GUI doesn't start. I'm looking for Hardware without Intel Hardware, without non-free software, mainline Linux support and preferable Debian compatible. The OpenPower system by raptor engineering is simply too expensive. I cannot afford it. Any ideas?

Re: “We have obtained fully functional JTAG for Intel CSME via USB DCI”

#209
post #188
post #162

Earlier quoted context omitted.

The TPM is actually implemented as an Intel ME applet on a lot of PCs... >.<

Right, but there is a TPM pin-out standard -- so theoretically you could swap out the TPM of any device (which has a physical TPM obviously) with any other manufacturer's TPM and it would still "just work". While it might be implemented in Intel ME, there are a lot of laptops that have physical TPM chips.

Some manufacturers just don't pay more for an LPC or SPI-based TPM, and just use the fTPM one running as an ME applet (my Kaby Lake laptop does this)

Re: “We have obtained fully functional JTAG for Intel CSME via USB DCI”

#210
post #172

Earlier quoted context omitted.

We should start demanding physical shutters for laptop webcams. Does anyone make those yet?

Even better is a hardware kill switch, especially for the mic.

But now you have to trust the switch to really deactivate the mic. I'm a recursive paranoiac !
Post reply on HN