Live data from Hacker News

“We have obtained fully functional JTAG for Intel CSME via USB DCI”

twitter.com

301–310 of 413 posts

Re: “We have obtained fully functional JTAG for Intel CSME via USB DCI”

#301

Earlier quoted context omitted.

> Intel ME and the (assumed [0]) partnership with CIA to design and build this system I worked at Intel on ME and the things that came before it until around 2013. I can tell you two things -- 1. No, Intel ME wasn't born out of a desire to spy on people nor was it -- to the best of my knowledge but I honestly believe I would know -- created at the request of the US government (or others). It was an honest attempt at…

Why doesn't Intel offer their chips without an ME, as an option? The mandatory nature makes it malicious.

There are parts of ME that you need (like the BUP module for configuring on boot).

Re: “We have obtained fully functional JTAG for Intel CSME via USB DCI”

#302

One way to think of ME is, we all woke up one day and discovered we have had high resolution night vision spy cams installed in our bedrooms. The next realization is there is no way to turn them off or remove them. It’s posisble even moving won’t help. And yet we really don’t seem to care much. Lesser issues generate national outrage and high volumes of press coverage. Why? HN may be uniquely positioned to show us th…

Let's be pragmatic. Does anyone know if ME blockers work? Can you please post one if it does? Can we start a list? Are the destination ips it can be controlled from hard coded, can it be blocked via simple firewall rules? EG tool: https://github.com/corna/me_cleaner List? https://github.com/ransom1538/intel_me_cleaners/

You can use me_cleaner, and it's better than nothing, but the ME is still required for booting the motherboard.

Re: “We have obtained fully functional JTAG for Intel CSME via USB DCI”

#303

Earlier quoted context omitted.

I just get tired of being ridiculed and then 10 years later vindicated. In Faraday cages we trust.

Imagine how Stallman feels.

There's a whole subreddit dedicated to this https://www.reddit.com/r/StallmanWasRight/

Re: “We have obtained fully functional JTAG for Intel CSME via USB DCI”

#304
post #215
post #208

Earlier quoted context omitted.

> And yet we really don’t seem to care much. I do care, a lot. I have decided to avoid Intel (and AMD) hardware like the pest. I will not buy any Core iSpyOnYou or AMD equivalent anymore. I'm an advocate of economic and judicial sanctions from the political level against Intel (and AMD). I tell people around me about the problems and explain how it is an issue of privacy, security, national sovereignty, and market po…

Your best bet is probably a tablet or smartphone with a fast ARM processor. Those don't have the management engine and can run surprisingly fast.

As a desktop computer for day to day use? Can I run it without non-free software? Can I natively install Debian with mainline Linux to actually get work done? Can I connect a monitor and other accessory?

Re: “We have obtained fully functional JTAG for Intel CSME via USB DCI”

#305
post #139

Earlier quoted context omitted.

I'll give a try. Someone else can correct me later. These guys have used a JTAG f debugging dongle to access the Intel management engine. They can now read every bit of code. Which means that secrets stored within the code including keys and bugs are available to them and anyone who can replicate their work. Since the management engine is in nearly all of Intel chips, we're screwed. AMD have something similar so no h…

Is this seen in ARM?

Some of them have ARM TrustZone.

I'm pretty sure that i.MX6 chips are relatively clean. Modern chips are becoming less so.

Re: “We have obtained fully functional JTAG for Intel CSME via USB DCI”

#306
post #36

Earlier quoted context omitted.

It's by far not the first time that a highly-priviledged "security" component turns out to actually reduce security, because it is a large and gainful attack surface. I can't help but to think of all those exploits that target anti-virus software.

From what I understand, the justification wasn't about security, but rather about remote administration. Which is even worse, because that is ACTUALLY a backdoor, just one that is supposed to only be used by the legitimate owner of the machine.

It enables DRM technologies, too.

Re: “We have obtained fully functional JTAG for Intel CSME via USB DCI”

#307

Earlier quoted context omitted.

Prior to the NSA contractor Edward Snowden's revelations in 2013, Room-641A had already been exposed by an AT&T employee-turned-whistleblower Mark Klein. The EFF sued the government in 2006 over it. Tape over laptop cameras isn't just a "parents-of-friends" thing, it's a good idea. Buy a set of stickers and support the EFF: https://supporters.eff.org/shop/laptop-camera-cover-set Anyone know somebody at Wired?

I definitely agree about tapeing the camera. Zuckerberg does it too https://www.theverge.com/2016/6/21/11995032/mark-zuckerberg-...

While I don't care one way or another what people choose to do to their own devices and am happy to accept that it's probably a good practice, it does always cause me to chuckle when the "Zuckerburg does it" argument is thrown out.

I think the threat profile faced by "the rest of us" is probably just a little less intense than someone as well known, wealthy, famous and influential as the CEO of Facebook, but perhaps that's just me.

Re: “We have obtained fully functional JTAG for Intel CSME via USB DCI”

#308
post #300

Earlier quoted context omitted.

Could you not just buy a Macintosh? Macs lack the AMT chip so the ME in the CPU can't do anything.

It's still Intel hardware. But besides that, does the Macintosh work without blobs and mainline Linux? Can I install Debian on it and have stuff working? I'm just tired of uncooperative manufactures.

I've never tried but Debian has a lengthy (if out of date?) wiki page about running it on Macbooks:

https://wiki.debian.org/MacBook

https://wiki.debian.org/MacBookPro

Re: “We have obtained fully functional JTAG for Intel CSME via USB DCI”

#309
post #203

Earlier quoted context omitted.

Prior to the NSA contractor Edward Snowden's revelations in 2013, Room-641A had already been exposed by an AT&T employee-turned-whistleblower Mark Klein. The EFF sued the government in 2006 over it. Tape over laptop cameras isn't just a "parents-of-friends" thing, it's a good idea. Buy a set of stickers and support the EFF: https://supporters.eff.org/shop/laptop-camera-cover-set Anyone know somebody at Wired?

> Tape over laptop cameras isn't just a "parents-of-friends" thing Not sure why you took that statement as deriding the practice because some older people are doing it? I noted it merely as an indication of how far the behavioural change has spread as a result of news stories... Of course it's good security hygiene. Not an ideal solution though, as others have already mentioned, compared to a hardware switch or built…

Ah, apologies; The way I read it was that your friends don't but their parents do.

Re: “We have obtained fully functional JTAG for Intel CSME via USB DCI”

#310

Companies like Intel, who are complicit in helping CIA or any intel agency (government, rogue or otherwise) infiltrate and exploit our systems - need to be held accountable by the market. Intel ME and the (assumed [0]) partnership with CIA to design and build this system - should be an absolute travesty blow to the integrity of their business long-term. Will you, as lead engineer or sys admin for your mission critica…

> Intel ME and the (assumed [0]) partnership with CIA to design and build this system I worked at Intel on ME and the things that came before it until around 2013. I can tell you two things -- 1. No, Intel ME wasn't born out of a desire to spy on people nor was it -- to the best of my knowledge but I honestly believe I would know -- created at the request of the US government (or others). It was an honest attempt at…

> were going to run a lot more stuff -- think a full JVM

Is a JVM really a lot more stuff than Minix OS?

Post reply on HN