Live data from Hacker News

“We have obtained fully functional JTAG for Intel CSME via USB DCI”

twitter.com

251–260 of 413 posts

Re: “We have obtained fully functional JTAG for Intel CSME via USB DCI”

#251

Earlier quoted context omitted.

> And yet we really don’t seem to care much. I know we're used to "Internet speed" and the tweet happened an entire 24 hours ago, but give it a bit of time before declaring it dead. Wired and Vice need a second to write it up, and see if it hits the mainstream before declaring the issue ignored. Not saying it will get picked up, though I sure hope it does, but as you point out, it's a bit obscure and takes some expla…

> A Facebook exec's claim doesn't count as proof. How about an official statement from Facebook itself over a year ago[1]? If it was true, people could find out by decompiling the app and make Facebook look absolutely horrible. [1] https://newsroom.fb.com/news/h/facebook-does-not-use-your-ph...

> How about an official statement from Facebook itself over a year ago

That also doesn't count as proof; it carries barely more weight than the Facebook exec's statement.

However, you're quite right about the decompiling argument. And chances are that security researchers have done just that.

Re: “We have obtained fully functional JTAG for Intel CSME via USB DCI”

#252
post #36

Earlier quoted context omitted.

It's by far not the first time that a highly-priviledged "security" component turns out to actually reduce security, because it is a large and gainful attack surface. I can't help but to think of all those exploits that target anti-virus software.

"I know, let's examine some suspicious code in a highly-privileged process that the user explicitly trusts to keep them safe." When you think about it, "it seemed like a good idea at the time" can explain most tragedies in human histories.

Well, a few hours ago we had a thread on HN about eradicating a whole specy of insects. And we had in comments intelligent educated people that though that "it seems like a good idea".

So if mass disruption of the very system that support your life can have supporters among a community composed of smart and actively debating people, "it seemed like a good idea at the time" probably happens every week at gov agencies.

Re: “We have obtained fully functional JTAG for Intel CSME via USB DCI”

#253

Earlier quoted context omitted.

The point of ME is that it's invisible. And until then, few people had access to it. Now I can't wait for rogue monero miners to use ME to propagate :)

It doesn't matter if it's visible or invisible. The point is, it cannot go undetected while being used: - If it were to periodically "check in" with an external server to see if it needs to do any kind of spying -- admins would notice the network traffic. - If it needed to be contacted externally to "initiate" any kind of spying at all, that would mean anyone behind a NAT would be safe, and furthermore, the the momen…

Are you so sure about point 1?

Re: “We have obtained fully functional JTAG for Intel CSME via USB DCI”

#254
post #215
post #208

Earlier quoted context omitted.

> And yet we really don’t seem to care much. I do care, a lot. I have decided to avoid Intel (and AMD) hardware like the pest. I will not buy any Core iSpyOnYou or AMD equivalent anymore. I'm an advocate of economic and judicial sanctions from the political level against Intel (and AMD). I tell people around me about the problems and explain how it is an issue of privacy, security, national sovereignty, and market po…

Your best bet is probably a tablet or smartphone with a fast ARM processor. Those don't have the management engine and can run surprisingly fast.

While it's true that they don't have MEs, the basebands in smartphones almost always have direct memory access, and their own proprietary firmware, so the same problems apply :-(

Re: “We have obtained fully functional JTAG for Intel CSME via USB DCI”

#255
post #253

Earlier quoted context omitted.

It doesn't matter if it's visible or invisible. The point is, it cannot go undetected while being used: - If it were to periodically "check in" with an external server to see if it needs to do any kind of spying -- admins would notice the network traffic. - If it needed to be contacted externally to "initiate" any kind of spying at all, that would mean anyone behind a NAT would be safe, and furthermore, the the momen…

Are you so sure about point 1?

Yes? I'm not claiming every single admin would notice it, I'm just saying some competent admins somewhere would notice it. I hope I'm not proven wrong, but I don't expect to wake up one morning and read "Breaking news: No admin has noticed this strange this IP traffic to Intel/NSA/whatever for the past decade".

Re: “We have obtained fully functional JTAG for Intel CSME via USB DCI”

#256

Earlier quoted context omitted.

The vulnerability exists, wether someone reveals it to the public or not. These people found it with Intel keeping the working of the system under wraps as much as possible. You can imagine the kind of access available to people who did get to see the source code. At least now that everyone can see the problem people can make informed decisions.

I would think those people are under constant threat of being kidnapped for their information

Given the complexity of the thing, they need a LOT of high profile people to create such a stuff. It's very unlikely none of them have been either:

- bribed

- threaten

- felt guilty about it and decided to make amend

My money is that exploits have been on the blacks market for a while now. We just have an official public demo now.

Rule of thumb: when something that catastrophic is made public, the worst already happened and you are late to the party.

Re: “We have obtained fully functional JTAG for Intel CSME via USB DCI”

#257
post #32

At first it looks nice "oh now we can get rid of it" but it also opens up a very scary near future security-wise. We've now entered a realm where an attacker could simply plug a device on an usb port of your computer for a few seconds to have it access your cpu's ME through USB JTAG and take over it, allowing him to have full access and control over what you do/read/open/type over the network, without you ever knowin…

Many people will now start to dig in. War is started and I hope somebody will find a way to totally remove/replace(with a stub) Intel ME before some critical vulnerability will be discovered in the Intel ME's network stack. In white hats we trust :)

Until they fix it. Or use something else.

Huge corporations backed up by gov agencies with a lot of time, money and skilled people VS a few people working for free because they believe they should. Not a fair fight.

Re: “We have obtained fully functional JTAG for Intel CSME via USB DCI”

#258
post #172

Earlier quoted context omitted.

We should start demanding physical shutters for laptop webcams. Does anyone make those yet?

Even better is a hardware kill switch, especially for the mic.

Librem Purism labtop has hadware kill switches.

Re: “We have obtained fully functional JTAG for Intel CSME via USB DCI”

#259

Earlier quoted context omitted.

Here's hoping. Intel did a great job hiding the thing and making it all but impossible to remove (at present if you nuke the firmware, the CPU will totally fail to initialise. Thanks Intel!). That said, we're talking about an embedded device with very low-level code, and any 'disabling' code is probably going to be distributed in binary form. Stands to reason somewhere along the lines, someone is going to turn that a…

I just get tired of being ridiculed and then 10 years later vindicated. In Faraday cages we trust.

You'd think after being right again and again people would start to trust you. Or at least distrust entity that have a track record of behaving badly.

And yet...

Re: “We have obtained fully functional JTAG for Intel CSME via USB DCI”

#260
post #125

Earlier quoted context omitted.

to the best of my knowledge but I honestly believe I would know Honestly, if a three letter agency was working with a tech company to produce a back door, the last people I would expect to know would be most of the engineers involved in the implementation.

> Honestly, if a three letter agency was working with a tech company to produce a back door, the last people I would expect to know would be most of the engineers involved in the implementation. Who would the first people be then?

If I were a 3 letter agency with a large budget, I would insert someone as a project manager at the target company. If I couldn't do that, I would work with their C level folks.
Post reply on HN