Live data from Hacker News

“We have obtained fully functional JTAG for Intel CSME via USB DCI”

twitter.com

291–300 of 413 posts

Re: “We have obtained fully functional JTAG for Intel CSME via USB DCI”

#291

Earlier quoted context omitted.

Why would they do something as ridiculous as telling you its true purpose?

They wouldn't. As I said, this is to the best of my knowledge. However, I believe I would know because it's not like one day the CEO came to us with a folder filled with requirements to be implemented. This is something that started very small ("find a way to force reboot a PC remotely if it's non-responsive") and evolved from there over months/years. I endured way too many meetings were design decisions were made. U…

> a folder filled with requirements

That's not how the intelligence agencies operate.

> evolved from there over months/years

THIS is how they influence standards and design choices. We know that in 2013 the NSA budgeted at least $250M to programs such as "BULLRUN" that which intended to "Insert vulnerabilities into commercial encryption networks, IT systems, and endpoint communication devices..."[1].

For an example of how this works, see John Gilmore's description[2] of how the NSA influenced IPSEC. They don't use a folder of requirements; instead they gain influence over enough people to complain about "efficiency" or other distractions and occasionally add a confusing or complicated requirement that just happens to weaken security.

PHK gave an outstanding talk[3] that everyone should see about the broader subject of how the common model most people have about how the NSA works is obsolete.

[1] http://www.nytimes.com/interactive/2013/09/05/us/documents-r...

[2] https://www.mail-archive.com/cryptography@metzdowd.com/msg12...

[3] https://archive.fosdem.org/2014/schedule/event/nsa_operation...

Re: “We have obtained fully functional JTAG for Intel CSME via USB DCI”

#292

One way to think of ME is, we all woke up one day and discovered we have had high resolution night vision spy cams installed in our bedrooms. The next realization is there is no way to turn them off or remove them. It’s posisble even moving won’t help. And yet we really don’t seem to care much. Lesser issues generate national outrage and high volumes of press coverage. Why? HN may be uniquely positioned to show us th…

> And yet we really don’t seem to care much. I know we're used to "Internet speed" and the tweet happened an entire 24 hours ago, but give it a bit of time before declaring it dead. Wired and Vice need a second to write it up, and see if it hits the mainstream before declaring the issue ignored. Not saying it will get picked up, though I sure hope it does, but as you point out, it's a bit obscure and takes some expla…

The most basic analysis will show that Facebook isn't listening to everything you say, even just at the level of realising that either doing speech recognition of everything you say or uploading an audio stream would be both impractical and easily detected by anyone with the inclination.

Re: “We have obtained fully functional JTAG for Intel CSME via USB DCI”

#293
post #172

Earlier quoted context omitted.

Prior to the NSA contractor Edward Snowden's revelations in 2013, Room-641A had already been exposed by an AT&T employee-turned-whistleblower Mark Klein. The EFF sued the government in 2006 over it. Tape over laptop cameras isn't just a "parents-of-friends" thing, it's a good idea. Buy a set of stickers and support the EFF: https://supporters.eff.org/shop/laptop-camera-cover-set Anyone know somebody at Wired?

We should start demanding physical shutters for laptop webcams. Does anyone make those yet?

Indeed, bags of lens stick on lens covers (that allow you to open when you need the camera) is a product idea I thought of ages ago, but too lazy to actually do.

Re: “We have obtained fully functional JTAG for Intel CSME via USB DCI”

#294

Earlier quoted context omitted.

Even better is a hardware kill switch, especially for the mic.

But now you have to trust the switch to really deactivate the mic. I'm a recursive paranoiac !

At least you only need to verify a switch once, it won't be compromised by software changes.

Re: “We have obtained fully functional JTAG for Intel CSME via USB DCI”

#295
post #200

Earlier quoted context omitted.

I managed to unplug the mic in my Thinkpad and my Dell XPS laptop with about 5min of work for each. It's still possible to do at the moment if you don't mind relying on plugging in headphones w/ a mic to use one. Of course a switch would be nice, similar to the older Thinkpads which had a hardware switch for the network devices on the front, originally for use on airplanes.

> I managed to unplug the mic in my Thinkpad Any chance you documented the procedure or have links to relevant documentation?

For Thinkpads the documentation you're looking for is the "Hardware Maintenance Manual" (HMM). E.g. here is one for the X260, it clearly describes where the camera/microphone assembly is, how to get to it and where its wire connections go: https://ok2.de/ThinkPad/HMM/x260_hmm_en_sp40j72016.pdf I haven't taken apart one of the more Ultrabook-style ones, so not sure how accessible those are, but the traditional ones are very serviceable.

I wouldn't be surprised if the better Dell models have similar documentation available.

Re: “We have obtained fully functional JTAG for Intel CSME via USB DCI”

#296

Earlier quoted context omitted.

Here's hoping. Intel did a great job hiding the thing and making it all but impossible to remove (at present if you nuke the firmware, the CPU will totally fail to initialise. Thanks Intel!). That said, we're talking about an embedded device with very low-level code, and any 'disabling' code is probably going to be distributed in binary form. Stands to reason somewhere along the lines, someone is going to turn that a…

I just get tired of being ridiculed and then 10 years later vindicated. In Faraday cages we trust.

Imagine how Stallman feels.

Re: “We have obtained fully functional JTAG for Intel CSME via USB DCI”

#297
post #32

At first it looks nice "oh now we can get rid of it" but it also opens up a very scary near future security-wise. We've now entered a realm where an attacker could simply plug a device on an usb port of your computer for a few seconds to have it access your cpu's ME through USB JTAG and take over it, allowing him to have full access and control over what you do/read/open/type over the network, without you ever knowin…

Is it still true that USB devices can be used to execute code on a target's system without user interaction?

I thought this behavior disappeared ~10 years ago.

Re: “We have obtained fully functional JTAG for Intel CSME via USB DCI”

#298
post #208

Earlier quoted context omitted.

> And yet we really don’t seem to care much. I do care, a lot. I have decided to avoid Intel (and AMD) hardware like the pest. I will not buy any Core iSpyOnYou or AMD equivalent anymore. I'm an advocate of economic and judicial sanctions from the political level against Intel (and AMD). I tell people around me about the problems and explain how it is an issue of privacy, security, national sovereignty, and market po…

Librem laptop is reasonable powerful, and they have effectively neutered the ME. Libreboot replaces firmware for some decade-old server machines lacking a ME (although noisy, they work quite well as a desktop).

The Librem laptop are not an option because they use Intel chips. Buying Intel products supports and finances their current way. They did not even address the grave accusations. There is no way I can give them money.

Re: “We have obtained fully functional JTAG for Intel CSME via USB DCI”

#299
post #36

Earlier quoted context omitted.

It's by far not the first time that a highly-priviledged "security" component turns out to actually reduce security, because it is a large and gainful attack surface. I can't help but to think of all those exploits that target anti-virus software.

"I know, let's examine some suspicious code in a highly-privileged process that the user explicitly trusts to keep them safe." When you think about it, "it seemed like a good idea at the time" can explain most tragedies in human histories.

People usually won’t do something if they think it’s a bad idea. Tragedies begin with “it seemed like a good idea at the time” because everything does.

Re: “We have obtained fully functional JTAG for Intel CSME via USB DCI”

#300
post #208

Earlier quoted context omitted.

> And yet we really don’t seem to care much. I do care, a lot. I have decided to avoid Intel (and AMD) hardware like the pest. I will not buy any Core iSpyOnYou or AMD equivalent anymore. I'm an advocate of economic and judicial sanctions from the political level against Intel (and AMD). I tell people around me about the problems and explain how it is an issue of privacy, security, national sovereignty, and market po…

Could you not just buy a Macintosh? Macs lack the AMT chip so the ME in the CPU can't do anything.

It's still Intel hardware. But besides that, does the Macintosh work without blobs and mainline Linux? Can I install Debian on it and have stuff working? I'm just tired of uncooperative manufactures.
Post reply on HN