Live data from Hacker News

“We have obtained fully functional JTAG for Intel CSME via USB DCI”

twitter.com

211–220 of 413 posts

Re: “We have obtained fully functional JTAG for Intel CSME via USB DCI”

#211
post #120

Earlier quoted context omitted.

Plenty of people were still saying the Snowden revelations were old hat when they came out, we all knew it was happening just didn't have proof, etc. The novelty and seriousness tends to be out-of-whack with the amount of news coverage. It's a poor way to measure the importance of existing news coverage or lack of it for that reason. What matters is that it gets out and incentivizes developers, manufacturers, company…

Prior to the NSA contractor Edward Snowden's revelations in 2013, Room-641A had already been exposed by an AT&T employee-turned-whistleblower Mark Klein. The EFF sued the government in 2006 over it. Tape over laptop cameras isn't just a "parents-of-friends" thing, it's a good idea. Buy a set of stickers and support the EFF: https://supporters.eff.org/shop/laptop-camera-cover-set Anyone know somebody at Wired?

I definitely agree about tapeing the camera. Zuckerberg does it too

https://www.theverge.com/2016/6/21/11995032/mark-zuckerberg-...

Re: “We have obtained fully functional JTAG for Intel CSME via USB DCI”

#212
post #27
post #3

Can someone explain like I have a degree in computer science from a good university, but opted for a career as a software engineer in some relatively high level languages?

There's a computer in your computer so your computer can computer while you computer. These guys just found the keyboard.

It needed to be done: https://i.imgflip.com/1z5rcw.jpg

Re: “We have obtained fully functional JTAG for Intel CSME via USB DCI”

#213
post #148
post #95

Earlier quoted context omitted.

> The concern with the Intel ME is that it has a native network adapter. Yep, this is the big deal. After I "discovered" the ME, my first stop on my home network was the switch, to block all that crap. (And I found my storage server, equipped with a Supermicro all-in-one motherboard, helpfully grabbed an IP for the ME to listen on with an 'admin/admin' password.) I just wish the empire builders at the NSA would care…

The BMC is listening on that IP, not the ME.

https://www.supermicro.com/products/nfo/IPMI.cfm IPMI / BMC != ME. Intel’s is basically the version of this that you can’t disable, that works through the same PHY (most BMCs have their own), that you’re not allowed to use. https://en.m.wikipedia.org/wiki/Intel_Management_Engine

Re: “We have obtained fully functional JTAG for Intel CSME via USB DCI”

#214
post #76

Companies like Intel, who are complicit in helping CIA or any intel agency (government, rogue or otherwise) infiltrate and exploit our systems - need to be held accountable by the market. Intel ME and the (assumed [0]) partnership with CIA to design and build this system - should be an absolute travesty blow to the integrity of their business long-term. Will you, as lead engineer or sys admin for your mission critica…

"The market" is only going to "punish" you if.. - The masses actually care - There is an alternative Neither is the case here. Most people couldn't care less about things like ME and AMD and Intel are a oligopoly. If you want a modern x86-64 CPU you only have those two choices and both do this. That is the problem here, not fiat currency.

I'd say that there's a weird dependence between your two points; people often seem to care because there is an alternative.

Examples of this might be Fair Trade coffee, or energy saving light bulbs. Prior to their marketing, I doubt that vague ethical considerations were on the 'top 10' list of consumer wants from a new product, if they registered at all.

But when people are presented with a choice, if you can, why not get the better stuff?

Another analogy might be something like the TPM chips on iPhones. I very much doubt that focus groups or surveys at Apple found TPMs in the list of requested new features. However, things like TPMs get written up, and add to the things that journalists can describe around the vague theme of relative security and relative privacy; important concepts to consumers. Once this is internalized, when making a comparison between phones, a motivated consumer might consider the absence of a TPM a problem.

I doubt that Intel would start marketing _No Backdoor™_ chips, but I could imagine a consumer-facing hardware vendor coming up with some kind of comparison-based branding for avoiding the ME. There's a reasonable chance that Apple may continue to integrate vertically and get away from Intel over the next few years. And I was extremely surprised that Purism (a company basically founded on resentment towards the ME) could crowd-fund millions of dollars in the way it has.

Re: “We have obtained fully functional JTAG for Intel CSME via USB DCI”

#215
post #208

One way to think of ME is, we all woke up one day and discovered we have had high resolution night vision spy cams installed in our bedrooms. The next realization is there is no way to turn them off or remove them. It’s posisble even moving won’t help. And yet we really don’t seem to care much. Lesser issues generate national outrage and high volumes of press coverage. Why? HN may be uniquely positioned to show us th…

> And yet we really don’t seem to care much. I do care, a lot. I have decided to avoid Intel (and AMD) hardware like the pest. I will not buy any Core iSpyOnYou or AMD equivalent anymore. I'm an advocate of economic and judicial sanctions from the political level against Intel (and AMD). I tell people around me about the problems and explain how it is an issue of privacy, security, national sovereignty, and market po…

Your best bet is probably a tablet or smartphone with a fast ARM processor. Those don't have the management engine and can run surprisingly fast.

Re: “We have obtained fully functional JTAG for Intel CSME via USB DCI”

#216
post #113

One way to think of ME is, we all woke up one day and discovered we have had high resolution night vision spy cams installed in our bedrooms. The next realization is there is no way to turn them off or remove them. It’s posisble even moving won’t help. And yet we really don’t seem to care much. Lesser issues generate national outrage and high volumes of press coverage. Why? HN may be uniquely positioned to show us th…

Previously, explaining what the author of the tweet did months ago: https://www.digitaltrends.com/computing/intel-kaby-lake-skyl... "As shown in the presentation by security researchers Maxim Goryachy and Mark Ermolov, one way of accessing the JTAG debugging interface" "is to use a" "hardware implant" "running Godsurge" "which can exploit the JTAG debugging interface. Originally used by the National Security Agency -…

That we have one more person capable of exploiting this in the wild.

Re: “We have obtained fully functional JTAG for Intel CSME via USB DCI”

#217

One way to think of ME is, we all woke up one day and discovered we have had high resolution night vision spy cams installed in our bedrooms. The next realization is there is no way to turn them off or remove them. It’s posisble even moving won’t help. And yet we really don’t seem to care much. Lesser issues generate national outrage and high volumes of press coverage. Why? HN may be uniquely positioned to show us th…

> And yet we really don’t seem to care much.

Most people do not have any concrete notion about what management engines are. People weren't that skeeved out by Alexa, and that was a pretty easy-to-understand system. There's no way that people will have any kind of personal connection to something that they barely are aware of and don't understand.

Re: “We have obtained fully functional JTAG for Intel CSME via USB DCI”

#218

Earlier quoted context omitted.

> Intel ME and the (assumed [0]) partnership with CIA to design and build this system I worked at Intel on ME and the things that came before it until around 2013. I can tell you two things -- 1. No, Intel ME wasn't born out of a desire to spy on people nor was it -- to the best of my knowledge but I honestly believe I would know -- created at the request of the US government (or others). It was an honest attempt at…

> > Intel ME and the (assumed [0]) partnership with CIA to design and build this system Then why do you need security clearance to work on Intel ME?

Do you have a citation for that? That sounds interesting

Re: “We have obtained fully functional JTAG for Intel CSME via USB DCI”

#219
post #12

Earlier quoted context omitted.

Intel CPUs have an embedded supervisory CPU called the Management Engine. It can read all of memory, control power states on the main CPU, and generally has super-root privileges on everything. You, an end-user, aren't allowed to program it. The current MEs run a form of Minix. They represent an incredible security and privacy risk, because we don't know what code they run and it is widely believed that the NSA or ot…

Also that since they have JTAG debugging access, they have unrestricted access to the normally hidden processor, meaning they can disassemble it, peer into memory, and probably find a method of permanently disabling the ME.

And if they can access it without hardware modifications it means any USB device has super-root access to the machine. And then it would mean you can't block it unless you don't connect USB device.

I suspect they fiddled with something to get access, however. Attached something to motherboard or similar.

Re: “We have obtained fully functional JTAG for Intel CSME via USB DCI”

#220
post #200

Earlier quoted context omitted.

I managed to unplug the mic in my Thinkpad and my Dell XPS laptop with about 5min of work for each. It's still possible to do at the moment if you don't mind relying on plugging in headphones w/ a mic to use one. Of course a switch would be nice, similar to the older Thinkpads which had a hardware switch for the network devices on the front, originally for use on airplanes.

> I managed to unplug the mic in my Thinkpad Any chance you documented the procedure or have links to relevant documentation?

This is easy in almost all laptops: the microphone is attached to the mobo via a 2-wire tiny plug. Disassemble your laptop, look at the other side of the keyboard pane, a bit away from the speakers. Some laptops might also carry mikes in the screen bezel or multiple mikes, so check all cables that go away from the mobo.
Post reply on HN