Live data from Hacker News

“We have obtained fully functional JTAG for Intel CSME via USB DCI”

twitter.com

241–250 of 413 posts

Re: “We have obtained fully functional JTAG for Intel CSME via USB DCI”

#241

One way to think of ME is, we all woke up one day and discovered we have had high resolution night vision spy cams installed in our bedrooms. The next realization is there is no way to turn them off or remove them. It’s posisble even moving won’t help. And yet we really don’t seem to care much. Lesser issues generate national outrage and high volumes of press coverage. Why? HN may be uniquely positioned to show us th…

> I think HN is uniquely positioned to show us the answer. Take a community of people with generally above average interest and/or knowledge in this stuff, and the comments are filled with I think it's even more sinister: I would argue that a higher percentage of users on HN might be sworn to secrecy about any knowledge they might have anyway. So you end up with very smart people who're either sworn to secrecy or who…

[deleted]

Re: “We have obtained fully functional JTAG for Intel CSME via USB DCI”

#242
post #196
post #192

Earlier quoted context omitted.

Having worked for Intel (in the open source org) I trust you. I've seen first hand how a cool, small, simple feature is blossoming into something dr. Frankenstein would be proud of. Also, I think people here severely underestimate the red tape and huge efforts needed to implement something mildly complex, Intel scale. Developing ME under wraps with full CIA-like functionality is staggeringly difficult - I've seen the…

> I've seen first hand how a cool, small, simple feature is blossoming into something dr. Frankenstein would be proud of. Complete aside, but the whole story of Frankenstein is about how Dr. Frankenstein is repulsed by his actions the moment that he brings the monster to life. So he most certainly wasn't "proud" of his actions, he was horrified by them. But I agree that this is likely how some of the engineers who wo…

> So he most certainly wasn't "proud" of his actions, he was horrified by them.

In the end, yes. But the novel starts with him being so proud of the golem that he takes it home with disastrous results. Hmmm, maybe the comparison to ME isn't that far-fetched.

> I don't buy that they designed it

Yep, this is what I'm saying - it's unlikely that they ever told Intel "put this in there".

> it's very likely they sabotaged it in some manner. Or at the very least they have security vulnerabilities they are not disclosing

Absolutely, yes. They would be vastly incompetent not to have them, in fact. What I don't agree about with HN crowd is the threat profile of such an exploit.

I have trouble believing that they use them on a mass-scale. There are so many people looking at the ME, that using any exploit on a massive scale would disclose it almost immediately, and allow the 'enemy' to develop protections. Given the extraordinary capabilities of such an exploit giving it a very valuable status, they probably need to protect it, and will use it only when absolutely necessary; such as the vast, vast majority of the HN users would not ever be subjected to such an exploit.

On the other hand, if your person is interesting enough to NSA to deploy such an exploit against your devices, probably you have vastly more significant problems, like trying to stay outside the visual range of a Predator drone. If any Three Letter Agency will deploy such an exploit against your PC, you can be absolutely sure that they have already bugged your phones, and not with a Stinger device, but tapping directly into the data feed at the phone exchange. Probably you have to incinerate your trash because the garbage men are spooks - this is the kind of threat that I assume you're facing if a TLA is trying to bug your ME.

Re: “We have obtained fully functional JTAG for Intel CSME via USB DCI”

#243

One way to think of ME is, we all woke up one day and discovered we have had high resolution night vision spy cams installed in our bedrooms. The next realization is there is no way to turn them off or remove them. It’s posisble even moving won’t help. And yet we really don’t seem to care much. Lesser issues generate national outrage and high volumes of press coverage. Why? HN may be uniquely positioned to show us th…

> I think HN is uniquely positioned to show us the answer. Take a community of people with generally above average interest and/or knowledge in this stuff, and the comments are filled with I think it's even more sinister: I would argue that a higher percentage of users on HN might be sworn to secrecy about any knowledge they might have anyway. So you end up with very smart people who're either sworn to secrecy or who…

This is what I think, too. My professional knowledge doesn't encompass anything like ME, but occasionally areas I am expert in do come up. Unfortunately I can't honestly do much more than just watch -- I'm afraid that I might give away things I shouldn't without realizing it.

I'm sure that I'm far from the only one.

Re: “We have obtained fully functional JTAG for Intel CSME via USB DCI”

#246

One way to think of ME is, we all woke up one day and discovered we have had high resolution night vision spy cams installed in our bedrooms. The next realization is there is no way to turn them off or remove them. It’s posisble even moving won’t help. And yet we really don’t seem to care much. Lesser issues generate national outrage and high volumes of press coverage. Why? HN may be uniquely positioned to show us th…

> One way to think of ME is, we all woke up one day and discovered we have had high resolution night vision spy cams installed in our bedrooms.

Not really how I think of it. Seems more similar to waking up one day and realizing Tesla controls your Tesla car remotely. Or Microsoft can push bad updates Windows. Or Google can push bad updates to Chrome.

> And yet we really don’t seem to care much. Lesser issues generate national outrage and high volumes of press coverage. Why?

On my end it's because I have not seen a single shred of evidence that it has been used for spying, and because I figure the moment anyone becomes aware of that happening, people would probably find a way to block the network traffic at the router or somewhere else.

Re: “We have obtained fully functional JTAG for Intel CSME via USB DCI”

#247

One way to think of ME is, we all woke up one day and discovered we have had high resolution night vision spy cams installed in our bedrooms. The next realization is there is no way to turn them off or remove them. It’s posisble even moving won’t help. And yet we really don’t seem to care much. Lesser issues generate national outrage and high volumes of press coverage. Why? HN may be uniquely positioned to show us th…

> One way to think of ME is, we all woke up one day and discovered we have had high resolution night vision spy cams installed in our bedrooms. Not really how I think of it. Seems more similar to waking up one day and realizing Tesla controls your Tesla car remotely. Or Microsoft can push bad updates Windows. Or Google can push bad updates to Chrome. > And yet we really don’t seem to care much. Lesser issues generate…

The point of ME is that it's invisible. And until then, few people had access to it.

Now I can't wait for rogue monero miners to use ME to propagate :)

Re: “We have obtained fully functional JTAG for Intel CSME via USB DCI”

#248
post #18

On an unrelated note, did anyone hear about any answer from Intel to Prof. Tanenbaum's open letter? It's high time they pulled their heads out of the sand and started explaining the whole issue.

Why do you think would they have to answer him anything? He published something, using a license saying you could use it without telling anyone nor giving back changes, and that's exactly what Intel did. And in his letter he acknowledged that. There was no call nor need for an answer...

It's an interesting question. Legally, they don't owe him anything. But from the point of view of social interaction, it's just extremely weird. Imagine someone using the project of your life in something huge, contacting you about some minor details - and then disappearing, so that you learn about it by accident from someone else. It's just strange. Not to mention that if you contact them about it, they should respond. In whatever way. Like, "we're sorry but it was an internal project that we weren't allowed to disclose" kind of way. (Intel guys reading this, it's a good hint!)

Re: “We have obtained fully functional JTAG for Intel CSME via USB DCI”

#249

Earlier quoted context omitted.

> I think HN is uniquely positioned to show us the answer. Take a community of people with generally above average interest and/or knowledge in this stuff, and the comments are filled with I think it's even more sinister: I would argue that a higher percentage of users on HN might be sworn to secrecy about any knowledge they might have anyway. So you end up with very smart people who're either sworn to secrecy or who…

This is what I think, too. My professional knowledge doesn't encompass anything like ME, but occasionally areas I am expert in do come up. Unfortunately I can't honestly do much more than just watch -- I'm afraid that I might give away things I shouldn't without realizing it. I'm sure that I'm far from the only one.

If you are in this position, you may be able to take secretly actions:

- create tools to help fight what you deem contrary to things that are important to you

- dispatch leaks in subtitle ways so that humanity is not left in the dark

- lead anonymous and discrete community of people sharing your believes, your skills and passion to improve things

Be careful. And best of luck.

Re: “We have obtained fully functional JTAG for Intel CSME via USB DCI”

#250

Earlier quoted context omitted.

> One way to think of ME is, we all woke up one day and discovered we have had high resolution night vision spy cams installed in our bedrooms. Not really how I think of it. Seems more similar to waking up one day and realizing Tesla controls your Tesla car remotely. Or Microsoft can push bad updates Windows. Or Google can push bad updates to Chrome. > And yet we really don’t seem to care much. Lesser issues generate…

The point of ME is that it's invisible. And until then, few people had access to it. Now I can't wait for rogue monero miners to use ME to propagate :)

It doesn't matter if it's visible or invisible. The point is, it cannot go undetected while being used:

- If it were to periodically "check in" with an external server to see if it needs to do any kind of spying -- admins would notice the network traffic.

- If it needed to be contacted externally to "initiate" any kind of spying at all, that would mean anyone behind a NAT would be safe, and furthermore, the the moment anybody notices such a thing, it would make the headlines and get blocked on networks, so this capability would need to be kept secret and turned off except for ultra-high-value targets... which most people do not view themselves as.

Post reply on HN