Live data from Hacker News

“We have obtained fully functional JTAG for Intel CSME via USB DCI”

twitter.com

381–390 of 413 posts

Re: “We have obtained fully functional JTAG for Intel CSME via USB DCI”

#381
post #378
post #333

Earlier quoted context omitted.

Can you use an ARM Chromebook without it constantly leaking data to Google? I tried to use the C201 without Chrome OS, but with libreboot, and Debian with mainline Linux. I didn't succeed.

See https://johnlewis.ie/custom-chromebook-firmware/rom-download... Doesn't work for every Chromebook, but it does for many. Working fine on my Chrome Box.

I already had flashed libreboot onto the device. That wasn't hard. The problem was and is mainline Linux support.

Re: “We have obtained fully functional JTAG for Intel CSME via USB DCI”

#382
post #381
post #378

Earlier quoted context omitted.

See https://johnlewis.ie/custom-chromebook-firmware/rom-download... Doesn't work for every Chromebook, but it does for many. Working fine on my Chrome Box.

I already had flashed libreboot onto the device. That wasn't hard. The problem was and is mainline Linux support.

Ahh. Maybe this? https://github.com/altreact/archbk

Re: “We have obtained fully functional JTAG for Intel CSME via USB DCI”

#383

Earlier quoted context omitted.

Could you not just buy a Macintosh? Macs lack the AMT chip so the ME in the CPU can't do anything.

What’s AMT? Is ME on Macs innocuous?

Active Management Technology is the backdoor that's sold as a feature.

> https://en.wikipedia.org/wiki/Intel_Active_Management_Techno...

Not innocuous, but probably less dangerous.

Re: “We have obtained fully functional JTAG for Intel CSME via USB DCI”

#384

Earlier quoted context omitted.

"I know, let's examine some suspicious code in a highly-privileged process that the user explicitly trusts to keep them safe." When you think about it, "it seemed like a good idea at the time" can explain most tragedies in human histories.

Well, a few hours ago we had a thread on HN about eradicating a whole specy of insects. And we had in comments intelligent educated people that though that "it seems like a good idea". So if mass disruption of the very system that support your life can have supporters among a community composed of smart and actively debating people, "it seemed like a good idea at the time" probably happens every week at gov agencies.

Lots of things are done because there's a broad consensus opinion that it's a good idea. There is nothing intrinsically bad about that, and needless or baseless skepticism is often counterproductive and paralyzing, leading to inaction even in the face of widespread consensus.

What leads to failures, and I suspect happened at Intel, was that they mistook a very localized consensus for a broader one. There's a word for this, it's called "groupthink". A group of people can talk themselves into doing something very stupid (or evil) while still thinking they're doing the right thing, given enough time and motivation.

There was no widespread consensus, outside of Intel, that the IME was a good idea. If they had solicited opinions from outside their organization, they would doubtless have gotten horrified reactions. But they didn't, or if they did they must have dismissed those concerns, because they went through with the bad idea anyway.

The apparent secrecy with which they developed the IME is also a cause for alarm; groups of people who operate in isolation are particularly prone to groupthink, and so even if their motivations are good ones, the fact that they are working without continuous feedback from anyone on the outside raises the chances of a perverse outcome.

Re: “We have obtained fully functional JTAG for Intel CSME via USB DCI”

#385

Earlier quoted context omitted.

It doesn't matter if it's visible or invisible. The point is, it cannot go undetected while being used: - If it were to periodically "check in" with an external server to see if it needs to do any kind of spying -- admins would notice the network traffic. - If it needed to be contacted externally to "initiate" any kind of spying at all, that would mean anyone behind a NAT would be safe, and furthermore, the the momen…

You assume it would be used for mass spying. Not at all. When you have something that good, you use it for specific targeting. You get a guy with a work laptop at home, you infect him, then you use the machine to get one closer to your objective. Slowly. With time between the events. Without being a beacon in the network. Or you just use it to spy on a guy you suspect. Or to get access to secrets of somebody you wann…

[deleted]

Re: “We have obtained fully functional JTAG for Intel CSME via USB DCI”

#386
post #120

Earlier quoted context omitted.

Plenty of people were still saying the Snowden revelations were old hat when they came out, we all knew it was happening just didn't have proof, etc. The novelty and seriousness tends to be out-of-whack with the amount of news coverage. It's a poor way to measure the importance of existing news coverage or lack of it for that reason. What matters is that it gets out and incentivizes developers, manufacturers, company…

Prior to the NSA contractor Edward Snowden's revelations in 2013, Room-641A had already been exposed by an AT&T employee-turned-whistleblower Mark Klein. The EFF sued the government in 2006 over it. Tape over laptop cameras isn't just a "parents-of-friends" thing, it's a good idea. Buy a set of stickers and support the EFF: https://supporters.eff.org/shop/laptop-camera-cover-set Anyone know somebody at Wired?

[deleted]

Re: “We have obtained fully functional JTAG for Intel CSME via USB DCI”

#387
post #382
post #381

Earlier quoted context omitted.

I already had flashed libreboot onto the device. That wasn't hard. The problem was and is mainline Linux support.

Ahh. Maybe this? https://github.com/altreact/archbk

Thanks for the link. The C201 is listed as work-in-progress.

Re: “We have obtained fully functional JTAG for Intel CSME via USB DCI”

#388
post #224

You can disable all the phone home stuff by not plugging in the ethernet port it uses, eg. using wireless or an add-on card. Or in some motherboards, the secondary ethernet.

Would the downvoter care to state any reasons for disagreeing? The IME only has drivers for a specific ethernet port. They also don't use the secondary ports if equipped, though I imagine that's just a configuration setting.

Re: “We have obtained fully functional JTAG for Intel CSME via USB DCI”

#389

Earlier quoted context omitted.

Kudos for speaking up about it, understandably with a throwaway account - which unfortunately doesn't help prove what you say is in any way truthful. But you probably still work for them and enjoy a nice salary. So can't blame you at all there. But I do just wish more people would be willing to put their careers on the line to say the right thing. This is one of the underlying problems: when smart people go along wit…

> But you probably still work for them and enjoy a nice salary. So can't blame you at all there. Why not? Is a salary a good ethical justification for mistreating other people?

OP's explanation is that this was a shitty decision, made for decent reasons. So... no? But that's not a relevant question?

Re: “We have obtained fully functional JTAG for Intel CSME via USB DCI”

#390
post #379

Earlier quoted context omitted.

When Librem was first announced, I had grave concerns too, and I stuck with my Libreboot computers. However, it was just this past month when they showed proof of concept for their Purism phone running KDE plasma on an ARM board without any firmware/driver blob concerns and also showed how they isolated and disabled the Intel ME that I took them seriously, at which point I ordered a labtop and have been very happy. T…

I don't get how their work on the Purism phone makes their laptop any better. Care to explain the relation? That one can maybe fix a hardware backdoor in Intel chips does not make buying them any better. Intel does not get my money but should instead get clear-worded, sanctioned letter from the authorities. I think they should be banned from trading and selling their backdoored stuff. I will not buy even old products…

"how their work on the Purism phone makes their laptop any better"

So you are obviously right that proof of concept of fully FLOSS ARM phone doesn't directly translate to x86.

But it does show that they know how and want to build fully FLOSS systems. Whether they don't quite succeed 100% with the x86 system (as the management engine is still in my computer, albeit isolated and disabled), they have been making great strides in getting close to %100 and I am willing to reward them for that.

Regarding the morality of buying Intel chips, I do share the reluctance to support Intel. I hadn't bought a new Intel computer or CPU since 2007 with Core2Duo for that reason. But sometimes morality decision can't be made in a binary all or nothing manner. In this case I am aware of the damage done by purchasing an x86 system, but it makes up for in being able to have a productive labtop which I can more effectively work to make FLOSS applications with.

Post reply on HN