Live data from Hacker News

“We have obtained fully functional JTAG for Intel CSME via USB DCI”

twitter.com

281–290 of 413 posts

Re: “We have obtained fully functional JTAG for Intel CSME via USB DCI”

#281
post #275

Earlier quoted context omitted.

It doesn't matter if it's visible or invisible. The point is, it cannot go undetected while being used: - If it were to periodically "check in" with an external server to see if it needs to do any kind of spying -- admins would notice the network traffic. - If it needed to be contacted externally to "initiate" any kind of spying at all, that would mean anyone behind a NAT would be safe, and furthermore, the the momen…

You are not giving anywhere near enough credit to those who would be your adversary. The NSA routinely intercepted Google internal traffic. Did Google, who are presumably running the most advanced network on the planet and staffed by people who don't suck, notice the intrusion? They did not; they got informed via PowerPoint. While the sophistication of the attackers decreases as you move from NSA to random hackers, s…

> The NSA routinely intercepted Google internal traffic

How are these even similar? Did the NSA ever send traffic of their own on the Google network infrastructure? Citation needed if so, because I recall they merely listened in on existing traffic using external network equipment.

Re: “We have obtained fully functional JTAG for Intel CSME via USB DCI”

#282

Wait, the screenshot shows that they are using ITP/DAL.. I didn't think that was publicly available. Is this true? If so, then what they have done is only something an OEM, with appropriate permission from intel, could do.

Some motherboard vendors host downloads of it, whether they're allowed to or not is irrelevant at this stage, it's out in the wild.

Re: “We have obtained fully functional JTAG for Intel CSME via USB DCI”

#283

This is fantastic news. I expect to see some reliable and easy to apply (usb?) solution to wipe and tame ME. Greatest news is that it works for latest Intel processors so even if they change protection (they certainly will) we at least have very good processors that can work without spyware. All the previous tests I read about only tackled first few generations of Intel ME, for processors/boards over 8 or 10 years ol…

The core problem with this is that if you have debug access to the core running ME, you can put it back even if it was wiped - or replace it with anything you like.

Re: “We have obtained fully functional JTAG for Intel CSME via USB DCI”

#284
post #186

Earlier quoted context omitted.

Prior to the NSA contractor Edward Snowden's revelations in 2013, Room-641A had already been exposed by an AT&T employee-turned-whistleblower Mark Klein. The EFF sued the government in 2006 over it. Tape over laptop cameras isn't just a "parents-of-friends" thing, it's a good idea. Buy a set of stickers and support the EFF: https://supporters.eff.org/shop/laptop-camera-cover-set Anyone know somebody at Wired?

> Tape over laptop cameras isn't just a "parents-of-friends" thing, it's a good idea. Buy a set of stickers and support the EFF: https://supporters.eff.org/shop/laptop-camera-cover-set Support the EFF! But I hate the stickers. Everyone puts a sticker on their webcam and completely ignores the hot mic. But you get that false sense of security…

Exactly. I've given up on tape on camera. Frankly my mug just isn't that important compared to the key strokes I make.

Re: “We have obtained fully functional JTAG for Intel CSME via USB DCI”

#285

Earlier quoted context omitted.

> Intel ME and the (assumed [0]) partnership with CIA to design and build this system I worked at Intel on ME and the things that came before it until around 2013. I can tell you two things -- 1. No, Intel ME wasn't born out of a desire to spy on people nor was it -- to the best of my knowledge but I honestly believe I would know -- created at the request of the US government (or others). It was an honest attempt at…

Why doesn't Intel offer their chips without an ME, as an option? The mandatory nature makes it malicious.

Saves money to have only one assembly line of chips. Hell, the i5 chips they make now are just i7s with some of the features disabled. So if they make an i7 and there's an error in some part of the chip that's specific to the i7 features, they can disable the i7 parts and sell it as a working i5. At least this is what I recall from an article a year ago on here about that.

Re: “We have obtained fully functional JTAG for Intel CSME via USB DCI”

#286
post #208

One way to think of ME is, we all woke up one day and discovered we have had high resolution night vision spy cams installed in our bedrooms. The next realization is there is no way to turn them off or remove them. It’s posisble even moving won’t help. And yet we really don’t seem to care much. Lesser issues generate national outrage and high volumes of press coverage. Why? HN may be uniquely positioned to show us th…

> And yet we really don’t seem to care much. I do care, a lot. I have decided to avoid Intel (and AMD) hardware like the pest. I will not buy any Core iSpyOnYou or AMD equivalent anymore. I'm an advocate of economic and judicial sanctions from the political level against Intel (and AMD). I tell people around me about the problems and explain how it is an issue of privacy, security, national sovereignty, and market po…

Could you not just buy a Macintosh? Macs lack the AMT chip so the ME in the CPU can't do anything.

Re: “We have obtained fully functional JTAG for Intel CSME via USB DCI”

#287
post #172

Earlier quoted context omitted.

Prior to the NSA contractor Edward Snowden's revelations in 2013, Room-641A had already been exposed by an AT&T employee-turned-whistleblower Mark Klein. The EFF sued the government in 2006 over it. Tape over laptop cameras isn't just a "parents-of-friends" thing, it's a good idea. Buy a set of stickers and support the EFF: https://supporters.eff.org/shop/laptop-camera-cover-set Anyone know somebody at Wired?

We should start demanding physical shutters for laptop webcams. Does anyone make those yet?

My Asus EEEPC has one.

Re: “We have obtained fully functional JTAG for Intel CSME via USB DCI”

#288
post #242
post #196

Earlier quoted context omitted.

> I've seen first hand how a cool, small, simple feature is blossoming into something dr. Frankenstein would be proud of. Complete aside, but the whole story of Frankenstein is about how Dr. Frankenstein is repulsed by his actions the moment that he brings the monster to life. So he most certainly wasn't "proud" of his actions, he was horrified by them. But I agree that this is likely how some of the engineers who wo…

> So he most certainly wasn't "proud" of his actions, he was horrified by them. In the end, yes. But the novel starts with him being so proud of the golem that he takes it home with disastrous results. Hmmm, maybe the comparison to ME isn't that far-fetched. > I don't buy that they designed it Yep, this is what I'm saying - it's unlikely that they ever told Intel "put this in there". > it's very likely they sabotaged…

The concern isn't so much that the CIA will use it, but that someone else will find it and use it before the CIA does--a problem that is avoided by having the CIA disclose the vulnerability instead of keeping it for a rainy day.

Re: “We have obtained fully functional JTAG for Intel CSME via USB DCI”

#289
post #32

At first it looks nice "oh now we can get rid of it" but it also opens up a very scary near future security-wise. We've now entered a realm where an attacker could simply plug a device on an usb port of your computer for a few seconds to have it access your cpu's ME through USB JTAG and take over it, allowing him to have full access and control over what you do/read/open/type over the network, without you ever knowin…

The 'evil maid' attack is well known, and states that once someone has physical access to your computer, all bets are off. Anything that has DMA enabled (e.g. Firewire or Thunderbolt) offers an external device direct access to the system RAM that is very difficult to defend against, or they could attach a keylogger or modify your bootloader, basically unleash all manner of havok. USB JTAG is really no different from…

The physical access required for an evil maid attack is very different from the "physical access" required to give you a malicious USB device. In that sense this is a lot more scary. As are aforementioned Thunderbolt and Firewire attacks; without an IOMMU, those are a security nightmare too.

Re: “We have obtained fully functional JTAG for Intel CSME via USB DCI”

#290
post #36
post #32

At first it looks nice "oh now we can get rid of it" but it also opens up a very scary near future security-wise. We've now entered a realm where an attacker could simply plug a device on an usb port of your computer for a few seconds to have it access your cpu's ME through USB JTAG and take over it, allowing him to have full access and control over what you do/read/open/type over the network, without you ever knowin…

It's by far not the first time that a highly-priviledged "security" component turns out to actually reduce security, because it is a large and gainful attack surface. I can't help but to think of all those exploits that target anti-virus software.

From what I understand, the justification wasn't about security, but rather about remote administration. Which is even worse, because that is ACTUALLY a backdoor, just one that is supposed to only be used by the legitimate owner of the machine.
Post reply on HN