Live data from Hacker News

“We have obtained fully functional JTAG for Intel CSME via USB DCI”

twitter.com

261–270 of 413 posts

Re: “We have obtained fully functional JTAG for Intel CSME via USB DCI”

#261
post #33
post #32

At first it looks nice "oh now we can get rid of it" but it also opens up a very scary near future security-wise. We've now entered a realm where an attacker could simply plug a device on an usb port of your computer for a few seconds to have it access your cpu's ME through USB JTAG and take over it, allowing him to have full access and control over what you do/read/open/type over the network, without you ever knowin…

I think you're being overly paranoid. If the attacker has physical access to the machine, chances are you're compromised anyway, even before this vulnerability.

For now. You need a first step before the next. I'm waiting for them to own ME remotely now. It's unlikely they won't succeed.

Re: “We have obtained fully functional JTAG for Intel CSME via USB DCI”

#262
post #208

One way to think of ME is, we all woke up one day and discovered we have had high resolution night vision spy cams installed in our bedrooms. The next realization is there is no way to turn them off or remove them. It’s posisble even moving won’t help. And yet we really don’t seem to care much. Lesser issues generate national outrage and high volumes of press coverage. Why? HN may be uniquely positioned to show us th…

> And yet we really don’t seem to care much. I do care, a lot. I have decided to avoid Intel (and AMD) hardware like the pest. I will not buy any Core iSpyOnYou or AMD equivalent anymore. I'm an advocate of economic and judicial sanctions from the political level against Intel (and AMD). I tell people around me about the problems and explain how it is an issue of privacy, security, national sovereignty, and market po…

Librem laptop is reasonable powerful, and they have effectively neutered the ME.

Libreboot replaces firmware for some decade-old server machines lacking a ME (although noisy, they work quite well as a desktop).

Re: “We have obtained fully functional JTAG for Intel CSME via USB DCI”

#263

Earlier quoted context omitted.

Having been a sys-admin once upon a time (2006-2008), these answers are straight forward. Servers used to have discrete ME cards which were paid add-ons. Competition in the early 2000s drove these ME cards to be integrated in the motherboard in order to better compete on the low end of the market. I’ve had servers I was only able to remotely fix due to the out of band management interface (more than once). They pain…

> It’s expensive to produce chip variants, so doubtless that further cost pressures on Intel lead to them putting the ME their core shared across all products. Would it be possible in future CPU designs to put a jumper in, e.g., the ME power path? Closed by default (and possibly forced closed in enterprise-targeted devices), but the option exists to disable the ME without requiring an additional CPU variant.

From a hardware perspective, it’s an easy problem to solve. This is a wetware problem, however.

Back when ME’s were discrete, you would inevitably have some with, some without. Someone would order a bunch of machines without them to “save money” or they bought a model that just didn’t have an ME add on offered by the OEM.

That meant that occasionally you had to actually have the machine in your presence to service it. You end up designing two processes/procedures based on whether you are remote or not. Lack of ME’s actually increased labor costs by reducing the number of machines a tech could manage (on average).

Having an CPU fuse essentially winds the clock back to the discrete ME days. Someone will place an order order for SKU ENCH-81-U instead of EMCH-81-U and you end up with 500 machines with the ME fuse blown. Inevitably there will be a big enough restock fee that someone in accounting will say “just use them.”

(The same applies to things like having/not having a TPM module, etc.)

Re: “We have obtained fully functional JTAG for Intel CSME via USB DCI”

#264
post #33

Earlier quoted context omitted.

I think you're being overly paranoid. If the attacker has physical access to the machine, chances are you're compromised anyway, even before this vulnerability.

So you're saying things are so bad anyway that this one vulnerability probably doesn't make any difference? This interpretation of "you're being overly paranoid" is new to me ;)

Come on, you can already catch aids, why do you worry about cancer ?

Re: “We have obtained fully functional JTAG for Intel CSME via USB DCI”

#265

Companies like Intel, who are complicit in helping CIA or any intel agency (government, rogue or otherwise) infiltrate and exploit our systems - need to be held accountable by the market. Intel ME and the (assumed [0]) partnership with CIA to design and build this system - should be an absolute travesty blow to the integrity of their business long-term. Will you, as lead engineer or sys admin for your mission critica…

> Intel ME and the (assumed [0]) partnership with CIA to design and build this system I worked at Intel on ME and the things that came before it until around 2013. I can tell you two things -- 1. No, Intel ME wasn't born out of a desire to spy on people nor was it -- to the best of my knowledge but I honestly believe I would know -- created at the request of the US government (or others). It was an honest attempt at…

Man, anybody with a remote idea of how IT works would have said it was a very bad idea. I can't believe in genuineness here. Nobody smart enough to design that system is dumb enough no not understand the consequences. So it's been knowingly decided to create this monster and ship it to the entire world.

Re: “We have obtained fully functional JTAG for Intel CSME via USB DCI”

#266

Earlier quoted context omitted.

Not the military.

They must be decades behind, then. I don't think in-house Russian engineering capabilities have been competitive let alone ahead of the consumer electronics curve going back at least a decade in the of fabrication. Maybe when it was 1997 and everything was DIP.

I'll negate this by taking the opposite position, and similarly having no facts or references.

Re: “We have obtained fully functional JTAG for Intel CSME via USB DCI”

#267
post #148

Earlier quoted context omitted.

The BMC is listening on that IP, not the ME.

https://www.supermicro.com/products/nfo/IPMI.cfm IPMI / BMC != ME. Intel’s is basically the version of this that you can’t disable, that works through the same PHY (most BMCs have their own), that you’re not allowed to use. https://en.m.wikipedia.org/wiki/Intel_Management_Engine

I know that the BMC isn't the same as the ME, but in his case that's the BMC getting an IP and default web login for admin/admin. It's not the ME.

BMC doesn't always use a dedicated physical port, and it's commonly bridged in sideband to the other NICs on a server.

Re: “We have obtained fully functional JTAG for Intel CSME via USB DCI”

#268

Earlier quoted context omitted.

> A Facebook exec's claim doesn't count as proof. How about an official statement from Facebook itself over a year ago[1]? If it was true, people could find out by decompiling the app and make Facebook look absolutely horrible. [1] https://newsroom.fb.com/news/h/facebook-does-not-use-your-ph...

> How about an official statement from Facebook itself over a year ago That also doesn't count as proof; it carries barely more weight than the Facebook exec's statement. However, you're quite right about the decompiling argument. And chances are that security researchers have done just that.

It's one thing to lie, it's another thing to lie about something that could easily be found out and possibly get them sued. The risk/reward ratio seems way too high for Facebook to lie (unless they were forced to.) That's obviously not proof, but it seems like pretty strong evidence.

Re: “We have obtained fully functional JTAG for Intel CSME via USB DCI”

#269
post #172

Earlier quoted context omitted.

Prior to the NSA contractor Edward Snowden's revelations in 2013, Room-641A had already been exposed by an AT&T employee-turned-whistleblower Mark Klein. The EFF sued the government in 2006 over it. Tape over laptop cameras isn't just a "parents-of-friends" thing, it's a good idea. Buy a set of stickers and support the EFF: https://supporters.eff.org/shop/laptop-camera-cover-set Anyone know somebody at Wired?

We should start demanding physical shutters for laptop webcams. Does anyone make those yet?

I 3d-printed a crude shutter and super-glued it to the bezel: https://youtube.com/watch?v=oOkPP_5bjhs

I think it would be about as easy to make a cardboard one.

Re: “We have obtained fully functional JTAG for Intel CSME via USB DCI”

#270

Earlier quoted context omitted.

> One way to think of ME is, we all woke up one day and discovered we have had high resolution night vision spy cams installed in our bedrooms. Not really how I think of it. Seems more similar to waking up one day and realizing Tesla controls your Tesla car remotely. Or Microsoft can push bad updates Windows. Or Google can push bad updates to Chrome. > And yet we really don’t seem to care much. Lesser issues generate…

The point of ME is that it's invisible. And until then, few people had access to it. Now I can't wait for rogue monero miners to use ME to propagate :)

It's never been secret. It's been advertised by Intel as a feature so enterprises can control the computers they own.
Post reply on HN