Live data from Hacker News

“We have obtained fully functional JTAG for Intel CSME via USB DCI”

twitter.com

361–370 of 413 posts

Re: “We have obtained fully functional JTAG for Intel CSME via USB DCI”

#361
post #208

Earlier quoted context omitted.

> And yet we really don’t seem to care much. I do care, a lot. I have decided to avoid Intel (and AMD) hardware like the pest. I will not buy any Core iSpyOnYou or AMD equivalent anymore. I'm an advocate of economic and judicial sanctions from the political level against Intel (and AMD). I tell people around me about the problems and explain how it is an issue of privacy, security, national sovereignty, and market po…

Could you not just buy a Macintosh? Macs lack the AMT chip so the ME in the CPU can't do anything.

What’s AMT? Is ME on Macs innocuous?

Re: “We have obtained fully functional JTAG for Intel CSME via USB DCI”

#362
post #58

But ... Perhaps Intel has a second ME installed on the processor. The first one was just a decoy.

That would be a hilarious waste of silicon

A ME can be as simple as just another thread context, that is shared with the rest of the CPU. Basically, just a bunch of registers, and some simple logic to activate it.

Re: “We have obtained fully functional JTAG for Intel CSME via USB DCI”

#363
post #186

Earlier quoted context omitted.

> Tape over laptop cameras isn't just a "parents-of-friends" thing, it's a good idea. Buy a set of stickers and support the EFF: https://supporters.eff.org/shop/laptop-camera-cover-set Support the EFF! But I hate the stickers. Everyone puts a sticker on their webcam and completely ignores the hot mic. But you get that false sense of security…

I unplugged the microphone on my daughter's iMac years ago. She did not use it, and was ok with that. I did not break her phone in that way. Her phone is more dangerous.

> I unplugged the microphone on my daughter's iMac years ago.

Please note that a speaker may also act as a microphone if configured so (at software level). This is especially true for speakers/headphones connected via the jack.

Re: “We have obtained fully functional JTAG for Intel CSME via USB DCI”

#364

Companies like Intel, who are complicit in helping CIA or any intel agency (government, rogue or otherwise) infiltrate and exploit our systems - need to be held accountable by the market. Intel ME and the (assumed [0]) partnership with CIA to design and build this system - should be an absolute travesty blow to the integrity of their business long-term. Will you, as lead engineer or sys admin for your mission critica…

> Intel ME and the (assumed [0]) partnership with CIA to design and build this system I worked at Intel on ME and the things that came before it until around 2013. I can tell you two things -- 1. No, Intel ME wasn't born out of a desire to spy on people nor was it -- to the best of my knowledge but I honestly believe I would know -- created at the request of the US government (or others). It was an honest attempt at…

> If it was something done for the CIA, I believe it would probably have been kept secret instead of marketed.

If that is the case, we would have doubted about this too much early than it would otherwise (because there is a dedicated hardware).

So some people friendly feature have to be dubbed along with the anti-features. This may not be the real case though, but one of the possibilities.

Re: “We have obtained fully functional JTAG for Intel CSME via USB DCI”

#365

Earlier quoted context omitted.

> Intel ME and the (assumed [0]) partnership with CIA to design and build this system I worked at Intel on ME and the things that came before it until around 2013. I can tell you two things -- 1. No, Intel ME wasn't born out of a desire to spy on people nor was it -- to the best of my knowledge but I honestly believe I would know -- created at the request of the US government (or others). It was an honest attempt at…

Man, anybody with a remote idea of how IT works would have said it was a very bad idea. I can't believe in genuineness here. Nobody smart enough to design that system is dumb enough no not understand the consequences. So it's been knowingly decided to create this monster and ship it to the entire world.

> Nobody smart enough to design that system is dumb enough no not understand the consequences.

Do you remember the plain text password leaks from Yahoo? In the real world nothing has to be true/good/secure. All it has to be is that users should be felt so, doesn't matter what the reality is.

As long as the focus is on earning more money/power/control, this is always going to happen.

Re: “We have obtained fully functional JTAG for Intel CSME via USB DCI”

#366
post #125

Earlier quoted context omitted.

to the best of my knowledge but I honestly believe I would know Honestly, if a three letter agency was working with a tech company to produce a back door, the last people I would expect to know would be most of the engineers involved in the implementation.

> Honestly, if a three letter agency was working with a tech company to produce a back door, the last people I would expect to know would be most of the engineers involved in the implementation. Who would the first people be then?

Preferably no one in the implementing company. Work using customer pressure, say an important bank. And later you swoop in and get exclusive access during a nice and cozy dinner with one of the Cs. It's more like judo than brute force arm twisting.

Re: “We have obtained fully functional JTAG for Intel CSME via USB DCI”

#367
post #300

Earlier quoted context omitted.

Could you not just buy a Macintosh? Macs lack the AMT chip so the ME in the CPU can't do anything.

It's still Intel hardware. But besides that, does the Macintosh work without blobs and mainline Linux? Can I install Debian on it and have stuff working? I'm just tired of uncooperative manufactures.

> Can I install Debian on it and have stuff working?

Depends on the kind of Mac you buy. I can only comment on their mobile offerings:

- Best supported are the current MacBook Airs. Everything except the Webcam should work out-of-the-box. The webcam needs the out-of-tree bcwc_pcie driver (https://github.com/patjak/bcwc_pcie)).

- The Retina MacBooks need some manual work before being usable (e.g. need to compile out-of-tree keyboard & touchpad driver (https://github.com/cb22/macbook12-spi-driver)), but should work fine as well.

- The MacBook Pros before October 2016 are also quite good supported, the support for newer ones is still quite incomplete (check out https://github.com/Dunedan/mbp-2016-linux for details), although it's possible to use them as daily driver if you're aware of the limitations.

Re: “We have obtained fully functional JTAG for Intel CSME via USB DCI”

#368

Earlier quoted context omitted.

I unplugged the microphone on my daughter's iMac years ago. She did not use it, and was ok with that. I did not break her phone in that way. Her phone is more dangerous.

> I unplugged the microphone on my daughter's iMac years ago. Please note that a speaker may also act as a microphone if configured so (at software level). This is especially true for speakers/headphones connected via the jack.

It's likely an internal microphone and speaker; the sound card may not support input through that interface. What you're saying can be true for many other modern computers, though.

Re: “We have obtained fully functional JTAG for Intel CSME via USB DCI”

#369
post #360

Earlier quoted context omitted.

It doesn't matter if it's visible or invisible. The point is, it cannot go undetected while being used: - If it were to periodically "check in" with an external server to see if it needs to do any kind of spying -- admins would notice the network traffic. - If it needed to be contacted externally to "initiate" any kind of spying at all, that would mean anyone behind a NAT would be safe, and furthermore, the the momen…

Given that the ME has full access to the NIC, outbound traffic could be concealed onboard traffic that is already outbound. If the adversary has also compromised network routers, the traffic could be observed and decoded without explicitly being sent anywhere. Similarly inbound control signals could be delivered by modifying inbound traffic that the ME observed and decided. Depending on your throughput needs the sign…

It's still possible to monitor that traffic, especially at the corporate firewall level, or use a Raspberry Pi, or use an old, pre-ME computer.

Until there is evidence, this is technically just a government conspiracy theory.

Re: “We have obtained fully functional JTAG for Intel CSME via USB DCI”

#370
post #253

Earlier quoted context omitted.

Are you so sure about point 1?

Yes? I'm not claiming every single admin would notice it, I'm just saying some competent admins somewhere would notice it. I hope I'm not proven wrong, but I don't expect to wake up one morning and read "Breaking news: No admin has noticed this strange this IP traffic to Intel/NSA/whatever for the past decade".

I agree. No one has ever observed ME sending unexpected traffic. (Feel free, anyone, to point to a counter example.)
Post reply on HN