Live data from Hacker News

“We have obtained fully functional JTAG for Intel CSME via USB DCI”

twitter.com

271–280 of 413 posts

Re: “We have obtained fully functional JTAG for Intel CSME via USB DCI”

#271

Earlier quoted context omitted.

The point of ME is that it's invisible. And until then, few people had access to it. Now I can't wait for rogue monero miners to use ME to propagate :)

It's never been secret. It's been advertised by Intel as a feature so enterprises can control the computers they own.

Secret no. But if somebody uses it to own you, you can't see it.

Re: “We have obtained fully functional JTAG for Intel CSME via USB DCI”

#272

Earlier quoted context omitted.

The point of ME is that it's invisible. And until then, few people had access to it. Now I can't wait for rogue monero miners to use ME to propagate :)

It doesn't matter if it's visible or invisible. The point is, it cannot go undetected while being used: - If it were to periodically "check in" with an external server to see if it needs to do any kind of spying -- admins would notice the network traffic. - If it needed to be contacted externally to "initiate" any kind of spying at all, that would mean anyone behind a NAT would be safe, and furthermore, the the momen…

You assume it would be used for mass spying.

Not at all.

When you have something that good, you use it for specific targeting. You get a guy with a work laptop at home, you infect him, then you use the machine to get one closer to your objective. Slowly. With time between the events. Without being a beacon in the network.

Or you just use it to spy on a guy you suspect.

Or to get access to secrets of somebody you wanna black mail.

Re: “We have obtained fully functional JTAG for Intel CSME via USB DCI”

#273

Earlier quoted context omitted.

The invisible hand of the market is sufficient to explain it, no nefarious conspiracy necessary. For servers far away in a data-center, there needs to be some sort of "oh shit" access for when the OS dies, and this is implemented in high-end servers as separate second computer inside the server with its own ethernet port (ILOM), however the extra hardware costs more to manufacture. Intel decided it wanted a piece of…

Yeah, I am not saying that the mere presence and integration of ME/PSP is indicative of a nefarious plot, these things have commercial merit which is obvious to anyone who knows anything. I'm saying that the specific way that both vendors are handling this is uncharacteristic at least for Intel, and suspicious because it leaves a lot of crucial ethical and technical questions completely unanswered. There are some obv…

> is uncharacteristic at least for Intel

Have you worked in large enterprise organizations that sold things to other large enterprise organizations? Did you go read the bit about how banks were pressuring Intel to include full blown JVMs into the ME and they resisted that?

> leaves a lot of crucial ethical and technical questions completely unanswered.

The truth is mundane which is that Intel wanted money from Banks, and a bunch of workers tried to split the difference between giving the Banks everything they wanted and trying not to engineer gaping security holes. They were operating with imperfect information and got that equation wrong.

And the truth is that no company in the world attempts to engineer for perfect security. When security runs up against economic concerns they try to balance the costs and benefits.

Assume that we (you the reader) can know perfectly which possible vulnerabilities are actually exploitable and which are not. If Intel spends any time on possible vulnerabilities which in practice are not exploitable or never exploitable, that is entirely wasted time. If AMD spends no time at all on those, AMD can focus on shipping features and get ahead of Intel doing useful work. Since Intel and AMD cannot have perfect information, they make guesses as to the impact of possible security holes. That naturally will always result in them "cutting corners" from the perspective of someone who measures them only on their security posture. Enterprise corporations like this are a complicated non-linear non-convex optimization algorithm that attempts to balance economic, security and other concerns against a complicated and shifting landscape in the face of imperfect information. Any company that tried to have always perfect security would largely fail in the marketplace.

This is related to the explanation of why the locks on the front door of your house or apartment can likely easily be picked.

Security concerns are sacrificed for economic concerns, commonly, everywhere around you.

Re: “We have obtained fully functional JTAG for Intel CSME via USB DCI”

#274

Earlier quoted context omitted.

It doesn't matter if it's visible or invisible. The point is, it cannot go undetected while being used: - If it were to periodically "check in" with an external server to see if it needs to do any kind of spying -- admins would notice the network traffic. - If it needed to be contacted externally to "initiate" any kind of spying at all, that would mean anyone behind a NAT would be safe, and furthermore, the the momen…

You assume it would be used for mass spying. Not at all. When you have something that good, you use it for specific targeting. You get a guy with a work laptop at home, you infect him, then you use the machine to get one closer to your objective. Slowly. With time between the events. Without being a beacon in the network. Or you just use it to spy on a guy you suspect. Or to get access to secrets of somebody you wann…

> You assume it would be used for mass spying. Not at all. When you have something that good, you use it for specific targeting.

Did you even read what I wrote? Specifically the last sentence?

Re: “We have obtained fully functional JTAG for Intel CSME via USB DCI”

#275

Earlier quoted context omitted.

The point of ME is that it's invisible. And until then, few people had access to it. Now I can't wait for rogue monero miners to use ME to propagate :)

It doesn't matter if it's visible or invisible. The point is, it cannot go undetected while being used: - If it were to periodically "check in" with an external server to see if it needs to do any kind of spying -- admins would notice the network traffic. - If it needed to be contacted externally to "initiate" any kind of spying at all, that would mean anyone behind a NAT would be safe, and furthermore, the the momen…

You are not giving anywhere near enough credit to those who would be your adversary.

The NSA routinely intercepted Google internal traffic. Did Google, who are presumably running the most advanced network on the planet and staffed by people who don't suck, notice the intrusion? They did not; they got informed via PowerPoint.

While the sophistication of the attackers decreases as you move from NSA to random hackers, so does the sophistication of the network as you move from Google to mid-sized businesses.

Re: “We have obtained fully functional JTAG for Intel CSME via USB DCI”

#276
If you are finding the jargon in that tweet too dense (JTAG? ME?), these articles cover the same with more explanation

https://thenextweb.com/security/2017/11/09/researchers-find-...

https://www.theregister.co.uk/2017/11/09/chipzilla_come_clos...

Re: “We have obtained fully functional JTAG for Intel CSME via USB DCI”

#277
post #208

Earlier quoted context omitted.

> And yet we really don’t seem to care much. I do care, a lot. I have decided to avoid Intel (and AMD) hardware like the pest. I will not buy any Core iSpyOnYou or AMD equivalent anymore. I'm an advocate of economic and judicial sanctions from the political level against Intel (and AMD). I tell people around me about the problems and explain how it is an issue of privacy, security, national sovereignty, and market po…

Librem laptop is reasonable powerful, and they have effectively neutered the ME. Libreboot replaces firmware for some decade-old server machines lacking a ME (although noisy, they work quite well as a desktop).

For more details on this, see https://puri.sm/posts/purism-librem-laptops-completely-disab...

Re: “We have obtained fully functional JTAG for Intel CSME via USB DCI”

#278

Companies like Intel, who are complicit in helping CIA or any intel agency (government, rogue or otherwise) infiltrate and exploit our systems - need to be held accountable by the market. Intel ME and the (assumed [0]) partnership with CIA to design and build this system - should be an absolute travesty blow to the integrity of their business long-term. Will you, as lead engineer or sys admin for your mission critica…

> Intel ME and the (assumed [0]) partnership with CIA to design and build this system I worked at Intel on ME and the things that came before it until around 2013. I can tell you two things -- 1. No, Intel ME wasn't born out of a desire to spy on people nor was it -- to the best of my knowledge but I honestly believe I would know -- created at the request of the US government (or others). It was an honest attempt at…

It should've only been sold on a special "business class" series of CPUs. Intel already loves having dozens of variants, as evidenced by recent market offerings; and it's not like they don't already have dedicated business-class CPUs for workstations. Simply only sell ME as an "addon" tier, and that limits the potential damage.

Incidentally, did you hear about Silent Bob is Silent? What are your thoughts on that vuln?

Re: “We have obtained fully functional JTAG for Intel CSME via USB DCI”

#279
post #184
post #121

Earlier quoted context omitted.

I've never bought into the "NSA/CIA made Intel create this" line of reasoning because, as you say, there was a legitimate use for this technology (misguided as its implementation was). Of course, I have no doubt that the NSA/CIA may have added further backdoors, or are withholding vulnerabilities in ME. However, one thing that I've always felt conflicted about is why this feature is present in _all_ CPUs. Usually if…

I really don't understand why I have to pay out the nose for ECC memory support but I get this surveillance device "for free".

Officially, you still need to pay extra to enable the remote management capabilities of ME...

Re: “We have obtained fully functional JTAG for Intel CSME via USB DCI”

#280

Earlier quoted context omitted.

You assume it would be used for mass spying. Not at all. When you have something that good, you use it for specific targeting. You get a guy with a work laptop at home, you infect him, then you use the machine to get one closer to your objective. Slowly. With time between the events. Without being a beacon in the network. Or you just use it to spy on a guy you suspect. Or to get access to secrets of somebody you wann…

> You assume it would be used for mass spying. Not at all. When you have something that good, you use it for specific targeting. Did you even read what I wrote? Specifically the last sentence?

Woops
Post reply on HN