Live data from Hacker News

“We have obtained fully functional JTAG for Intel CSME via USB DCI”

twitter.com

221–230 of 413 posts

Re: “We have obtained fully functional JTAG for Intel CSME via USB DCI”

#221

I worked on what became ME at Intel from the mid 2000s through around 2012 ou 2013. I completely agree that in retrospect, it wasn't the best idea. However, I really want to say that it was never a project for the CIA as some keep saying. This was a widely-marketed product at the time of its inception. It was the whole point of the Intel vPro line. I've been to a ton of roadshows between 2008 and 2009 where the marke…

>However, I really want to say that it was never a project for the CIA as some keep saying.

Probably not a rubber stamp with "CIA" on top of the project documentation, but someone on the team could have been talking to the intelligence community and relaying specs or meeting details.

It's an obvious target just because of Intel's ubiquity and they are based in the US. You're kind of a bad intelligence agency if you don't try for backdoors to this level on processors running millions of devices world-wide. And the intelligence community has actively tried to stop good encryption from spreading while promoting bad encryption/RNG (forgive me for not knowing the details), and so it's pretty clear they are willing to compromise worldwide standards in favor of gaining an edge.

Re: “We have obtained fully functional JTAG for Intel CSME via USB DCI”

#222
post #65

Earlier quoted context omitted.

me_cleaner already exists[1], and it takes advantage of several flaws in Intel ME's signing to remove large sections of the code thus neutering it. Some code still exists, but Intel ME cannot actually fully initialise on "cleaned" systems. Older machines used to have a bug where if you filled the first half of the Intel ME firmware with zeros the machine would boot but ME wouldn't start at all. But yes, I hope that w…

Is this enough to block this attack? That is, is a "cleaned" system vulnerable to a USB device?

> That is, is a "cleaned" system vulnerable to a USB device?

of course it is, because the USB DCI attack is one level below the Intel ME. Even if it is deactivated via HAP, which basically simply puts the ME code into an infinite loop or a CPU halt state - both can be reversed by JTAG.

Re: “We have obtained fully functional JTAG for Intel CSME via USB DCI”

#223
post #121

I worked on what became ME at Intel from the mid 2000s through around 2012 ou 2013. I completely agree that in retrospect, it wasn't the best idea. However, I really want to say that it was never a project for the CIA as some keep saying. This was a widely-marketed product at the time of its inception. It was the whole point of the Intel vPro line. I've been to a ton of roadshows between 2008 and 2009 where the marke…

I've never bought into the "NSA/CIA made Intel create this" line of reasoning because, as you say, there was a legitimate use for this technology (misguided as its implementation was). Of course, I have no doubt that the NSA/CIA may have added further backdoors, or are withholding vulnerabilities in ME. However, one thing that I've always felt conflicted about is why this feature is present in _all_ CPUs. Usually if…

The NSA added a option bit to the firmware to allow them to turn it off on their computers.

https://www.bleepingcomputer.com/news/hardware/researchers-f...

Re: “We have obtained fully functional JTAG for Intel CSME via USB DCI”

#225
post #36

Earlier quoted context omitted.

It's by far not the first time that a highly-priviledged "security" component turns out to actually reduce security, because it is a large and gainful attack surface. I can't help but to think of all those exploits that target anti-virus software.

"I know, let's examine some suspicious code in a highly-privileged process that the user explicitly trusts to keep them safe." When you think about it, "it seemed like a good idea at the time" can explain most tragedies in human histories.

Except it never seemed like a good idea to anyone with a clue of IT security.

Re: “We have obtained fully functional JTAG for Intel CSME via USB DCI”

#226
post #208

One way to think of ME is, we all woke up one day and discovered we have had high resolution night vision spy cams installed in our bedrooms. The next realization is there is no way to turn them off or remove them. It’s posisble even moving won’t help. And yet we really don’t seem to care much. Lesser issues generate national outrage and high volumes of press coverage. Why? HN may be uniquely positioned to show us th…

> And yet we really don’t seem to care much. I do care, a lot. I have decided to avoid Intel (and AMD) hardware like the pest. I will not buy any Core iSpyOnYou or AMD equivalent anymore. I'm an advocate of economic and judicial sanctions from the political level against Intel (and AMD). I tell people around me about the problems and explain how it is an issue of privacy, security, national sovereignty, and market po…

[deleted]

Re: “We have obtained fully functional JTAG for Intel CSME via USB DCI”

#227

Earlier quoted context omitted.

Most likely they will be quiet because Russia is 100% dependent on foreign technology.

Not the military.

They must be decades behind, then. I don't think in-house Russian engineering capabilities have been competitive let alone ahead of the consumer electronics curve going back at least a decade in the of fabrication. Maybe when it was 1997 and everything was DIP.

Re: “We have obtained fully functional JTAG for Intel CSME via USB DCI”

#228

Earlier quoted context omitted.

I don't think thats the right attitude. There's a difference between being able to open a machine to install malicious hardware / steal hdd's or just plugging in a generic USB stick to pawn it. I know some of you might argue that even generic USB sticks can do damage and, whilst I agree, this attack is still a degree worse than most of those. Thus far the most damage an unknown USB stick could do was type commands as…

From a technical perspective there is a difference now that this is public, but from a security stance, physical access is physical access. Why? Security knows there are always bugs in software, and assumes they exist. Thanks to @h0t_max, the rest of us know this particular bug exists, but this bug has been around for a while - who's to say evil hax0rs didn't find this bug years ago and have been exploiting it since?…

> From a technical perspective there is a difference now that this is public, but from a security stance, physical access is physical access.

Access to a USB port is not physical access. USB is a network interface that is commonly used to connect host computers to small portable embedded systems, often tiny NAS units of other people also known as USB flash drives.

Re: “We have obtained fully functional JTAG for Intel CSME via USB DCI”

#229

Earlier quoted context omitted.

> Intel ME and the (assumed [0]) partnership with CIA to design and build this system I worked at Intel on ME and the things that came before it until around 2013. I can tell you two things -- 1. No, Intel ME wasn't born out of a desire to spy on people nor was it -- to the best of my knowledge but I honestly believe I would know -- created at the request of the US government (or others). It was an honest attempt at…

Kudos for speaking up about it, understandably with a throwaway account - which unfortunately doesn't help prove what you say is in any way truthful. But you probably still work for them and enjoy a nice salary. So can't blame you at all there. But I do just wish more people would be willing to put their careers on the line to say the right thing. This is one of the underlying problems: when smart people go along wit…

> But you probably still work for them and enjoy a nice salary. So can't blame you at all there.

Why not? Is a salary a good ethical justification for mistreating other people?

Re: “We have obtained fully functional JTAG for Intel CSME via USB DCI”

#230
post #206

Earlier quoted context omitted.

How can you prove a vulnerability isn't deliberate? We've seen deliberate security vulnerabilities before (DUAL_EC).

You can't, but let me point out that DUAL_EC was a "nobody but us" backdoor that required their private key to use. (and yes, it backfired) If they're introducing regular vulnerabilities, they're also making themselves vulnerable, given that the US government is one of the biggest Intel customers.

I remember back in the good old days of cryptography export restrictions when the NSA had a much simpler "nobody but us" approach: you encrypted data with a xx-bit private key, half of which was shared with the NSA. Should they need to break content, the other half of the key could be brute-forced at costs that were economically feasible (for targeted use, not blanket suviellance) to the NSA but the full-length key would be unbreakable (in theory) by anyone without prior knowledge of that other half.
Post reply on HN