Live data from Hacker News

“We have obtained fully functional JTAG for Intel CSME via USB DCI”

twitter.com

331–340 of 413 posts

Re: “We have obtained fully functional JTAG for Intel CSME via USB DCI”

#331

Earlier quoted context omitted.

Do you have a citation for that? That sounds interesting

The "citation" is a Twitter post [0] that included a screenshot of an anonymous post to 4chan by a supposed Intel employee who claims to have worked on the Management Engine team for the last three years. It was linked upthread. [0]: https://twitter.com/9th_prestige/status/928740294090285057

Thank you. That is worrisome.

Re: “We have obtained fully functional JTAG for Intel CSME via USB DCI”

#332
post #215
post #208

Earlier quoted context omitted.

> And yet we really don’t seem to care much. I do care, a lot. I have decided to avoid Intel (and AMD) hardware like the pest. I will not buy any Core iSpyOnYou or AMD equivalent anymore. I'm an advocate of economic and judicial sanctions from the political level against Intel (and AMD). I tell people around me about the problems and explain how it is an issue of privacy, security, national sovereignty, and market po…

Your best bet is probably a tablet or smartphone with a fast ARM processor. Those don't have the management engine and can run surprisingly fast.

Should not trust a phone or tablet. Are the radios off? Are you sure?

Re: “We have obtained fully functional JTAG for Intel CSME via USB DCI”

#333

One way to think of ME is, we all woke up one day and discovered we have had high resolution night vision spy cams installed in our bedrooms. The next realization is there is no way to turn them off or remove them. It’s posisble even moving won’t help. And yet we really don’t seem to care much. Lesser issues generate national outrage and high volumes of press coverage. Why? HN may be uniquely positioned to show us th…

> And yet we really don’t seem to care much. I know we're used to "Internet speed" and the tweet happened an entire 24 hours ago, but give it a bit of time before declaring it dead. Wired and Vice need a second to write it up, and see if it hits the mainstream before declaring the issue ignored. Not saying it will get picked up, though I sure hope it does, but as you point out, it's a bit obscure and takes some expla…

Can you use an ARM Chromebook without it constantly leaking data to Google? I tried to use the C201 without Chrome OS, but with libreboot, and Debian with mainline Linux. I didn't succeed.

Re: “We have obtained fully functional JTAG for Intel CSME via USB DCI”

#334
post #321
post #293

Earlier quoted context omitted.

Indeed, bags of lens stick on lens covers (that allow you to open when you need the camera) is a product idea I thought of ages ago, but too lazy to actually do.

it exists already, got one as swag at a conference from Nvidia (???). strange gift, I like the sentiment though.

Yes, got mine as a swag too (not Nvidia), works perfectly. Can be found by looking for "webcam cover slider" on Amazon or I assume any web store that deals with such things.

Re: “We have obtained fully functional JTAG for Intel CSME via USB DCI”

#335

Earlier quoted context omitted.

Why doesn't Intel offer their chips without an ME, as an option? The mandatory nature makes it malicious.

Saves money to have only one assembly line of chips. Hell, the i5 chips they make now are just i7s with some of the features disabled. So if they make an i7 and there's an error in some part of the chip that's specific to the i7 features, they can disable the i7 parts and sell it as a working i5. At least this is what I recall from an article a year ago on here about that.

This is known as the “Silicon Lottery”

Re: “We have obtained fully functional JTAG for Intel CSME via USB DCI”

#336
post #21
post #15

Earlier quoted context omitted.

"AMD have something similar so no help there" It's probably worse for AMD. For Intel now at least we'll probably get the ability to securely disable everything below ring -1.

It's such a pity that there is no real competition in that area. (Unless you go the totally different architectures such as ARM or RISC-V.) AMD had the chance to differentiate from Intel here, instead they blindly immitate the same customer-hostile stunt.

ARM has TrustZone, though I have no idea what that's capable of or how it differs from ME/AMT/PSP/etc or how prevalent it is.

Re: “We have obtained fully functional JTAG for Intel CSME via USB DCI”

#338

Now that we know for sure people who have worked on or are working on Intel ME actually read and post here, I'd like to take the opportunity to refer those of you to a previous post of mine about it: https://news.ycombinator.com/item?id=15120207 If you choose to defect and leak all the information you can, you will almost certainly be greatly praised for it by many. Of course there will be negative consequences, but…

While a leak would make the situation much better, the problem with Intel would still be there. They would change the keys for the next generation of chips, harden their backdoor and keep on rolling. Intel itself is a problem here.

Re: “We have obtained fully functional JTAG for Intel CSME via USB DCI”

#339

Now that we know for sure people who have worked on or are working on Intel ME actually read and post here, I'd like to take the opportunity to refer those of you to a previous post of mine about it: https://news.ycombinator.com/item?id=15120207 If you choose to defect and leak all the information you can, you will almost certainly be greatly praised for it by many. Of course there will be negative consequences, but…

Andy Glew had a post: http://blog.andy.glew.ca/2017/05/intel-iamt-bug-strncmptrust...

Re: “We have obtained fully functional JTAG for Intel CSME via USB DCI”

#340
post #90

One way to think of ME is, we all woke up one day and discovered we have had high resolution night vision spy cams installed in our bedrooms. The next realization is there is no way to turn them off or remove them. It’s posisble even moving won’t help. And yet we really don’t seem to care much. Lesser issues generate national outrage and high volumes of press coverage. Why? HN may be uniquely positioned to show us th…

"opaque, obtuse, and obscure" is a red herring. Imagine, Intel were a Russian company. Tomorrow, there would be a simple and clear [screaming] headline similar to "Russians hacked the election" (general public doesn't need to know or understand how the network, computers or elections actually work). The day after tomorrow it would be illegal to buy anything Intel.

Elections have almost certainly been hacked - the security on electronic voting machines is abysmal - and no one seems to care, so I think your 'Russians hacked the elections' example doesn't say what you meant.
Post reply on HN