Live data from Hacker News

“We have obtained fully functional JTAG for Intel CSME via USB DCI”

twitter.com

231–240 of 413 posts

Re: “We have obtained fully functional JTAG for Intel CSME via USB DCI”

#231
post #208

One way to think of ME is, we all woke up one day and discovered we have had high resolution night vision spy cams installed in our bedrooms. The next realization is there is no way to turn them off or remove them. It’s posisble even moving won’t help. And yet we really don’t seem to care much. Lesser issues generate national outrage and high volumes of press coverage. Why? HN may be uniquely positioned to show us th…

> And yet we really don’t seem to care much. I do care, a lot. I have decided to avoid Intel (and AMD) hardware like the pest. I will not buy any Core iSpyOnYou or AMD equivalent anymore. I'm an advocate of economic and judicial sanctions from the political level against Intel (and AMD). I tell people around me about the problems and explain how it is an issue of privacy, security, national sovereignty, and market po…

I heard https://beagleboard.org/black can boot and run Linux w/o any blobs either in bootloader or kernel (provided you're OK with a sub-par screen resolution and not using the onboard GPU)

https://news.ycombinator.com/item?id=12584880 and others might have details on WiFi and such

Re: “We have obtained fully functional JTAG for Intel CSME via USB DCI”

#232
post #172

Earlier quoted context omitted.

We should start demanding physical shutters for laptop webcams. Does anyone make those yet?

Even better is a hardware kill switch, especially for the mic.

That's a very good point. We have it for wifi already, so...

Re: “We have obtained fully functional JTAG for Intel CSME via USB DCI”

#233
post #113

Earlier quoted context omitted.

Previously, explaining what the author of the tweet did months ago: https://www.digitaltrends.com/computing/intel-kaby-lake-skyl... "As shown in the presentation by security researchers Maxim Goryachy and Mark Ermolov, one way of accessing the JTAG debugging interface" "is to use a" "hardware implant" "running Godsurge" "which can exploit the JTAG debugging interface. Originally used by the National Security Agency -…

That we have one more person capable of exploiting this in the wild.

Who?

Re: “We have obtained fully functional JTAG for Intel CSME via USB DCI”

#234
post #125

Earlier quoted context omitted.

> Intel ME and the (assumed [0]) partnership with CIA to design and build this system I worked at Intel on ME and the things that came before it until around 2013. I can tell you two things -- 1. No, Intel ME wasn't born out of a desire to spy on people nor was it -- to the best of my knowledge but I honestly believe I would know -- created at the request of the US government (or others). It was an honest attempt at…

to the best of my knowledge but I honestly believe I would know Honestly, if a three letter agency was working with a tech company to produce a back door, the last people I would expect to know would be most of the engineers involved in the implementation.

> Honestly, if a three letter agency was working with a tech company to produce a back door, the last people I would expect to know would be most of the engineers involved in the implementation.

Who would the first people be then?

Re: “We have obtained fully functional JTAG for Intel CSME via USB DCI”

#235
post #125

Earlier quoted context omitted.

to the best of my knowledge but I honestly believe I would know Honestly, if a three letter agency was working with a tech company to produce a back door, the last people I would expect to know would be most of the engineers involved in the implementation.

> Honestly, if a three letter agency was working with a tech company to produce a back door, the last people I would expect to know would be most of the engineers involved in the implementation. Who would the first people be then?

[deleted]

Re: “We have obtained fully functional JTAG for Intel CSME via USB DCI”

#237

Earlier quoted context omitted.

Right. ME does make sense as a feature for sysadmins. Except . . . . Well, can you shed light on the following: 1. Why did your team deem it necessary to deny the end-user the capability to disable this feature? 2. Why did your team decide to enable ME on ALL consumer grade chips? You could have only enabled it on, say, Xeon, as a value-add - exactly like you do for ECC support. You could have made more money this wa…

Having been a sys-admin once upon a time (2006-2008), these answers are straight forward. Servers used to have discrete ME cards which were paid add-ons. Competition in the early 2000s drove these ME cards to be integrated in the motherboard in order to better compete on the low end of the market. I’ve had servers I was only able to remotely fix due to the out of band management interface (more than once). They pain…

> It’s expensive to produce chip variants, so doubtless that further cost pressures on Intel lead to them putting the ME their core shared across all products.

Would it be possible in future CPU designs to put a jumper in, e.g., the ME power path? Closed by default (and possibly forced closed in enterprise-targeted devices), but the option exists to disable the ME without requiring an additional CPU variant.

Re: “We have obtained fully functional JTAG for Intel CSME via USB DCI”

#240
post #208

One way to think of ME is, we all woke up one day and discovered we have had high resolution night vision spy cams installed in our bedrooms. The next realization is there is no way to turn them off or remove them. It’s posisble even moving won’t help. And yet we really don’t seem to care much. Lesser issues generate national outrage and high volumes of press coverage. Why? HN may be uniquely positioned to show us th…

> And yet we really don’t seem to care much. I do care, a lot. I have decided to avoid Intel (and AMD) hardware like the pest. I will not buy any Core iSpyOnYou or AMD equivalent anymore. I'm an advocate of economic and judicial sanctions from the political level against Intel (and AMD). I tell people around me about the problems and explain how it is an issue of privacy, security, national sovereignty, and market po…

Your best bet will be with NXP then. They still haven't released the i.MX8 cpus, but i.MX7 boards are available (up to dual core 1.2GHz), and, as far as I know, they are the only (decent, omap3 & 4 don't have enough power these days) with full opensource support for the entire SoC, even the GPU
Post reply on HN