Live data from Hacker News

“We have obtained fully functional JTAG for Intel CSME via USB DCI”

twitter.com

401–410 of 413 posts

Re: “We have obtained fully functional JTAG for Intel CSME via USB DCI”

#401
post #90

Earlier quoted context omitted.

"opaque, obtuse, and obscure" is a red herring. Imagine, Intel were a Russian company. Tomorrow, there would be a simple and clear [screaming] headline similar to "Russians hacked the election" (general public doesn't need to know or understand how the network, computers or elections actually work). The day after tomorrow it would be illegal to buy anything Intel.

Elections have almost certainly been hacked - the security on electronic voting machines is abysmal - and no one seems to care, so I think your 'Russians hacked the elections' example doesn't say what you meant.

A successful SQL injection probe that does not intentionally or otherwise result in data modification would be unusual, beyond the simple 1 == 1 methods.

The DREs don't seem to have been a target, though the physical and OPSEC vectors are quite well known at this point.

I'm not commenting on the information operations or the loose and ambiguous langauge that has been used to describe these events.

Re: “We have obtained fully functional JTAG for Intel CSME via USB DCI”

#402

Earlier quoted context omitted.

It's still possible to monitor that traffic, especially at the corporate firewall level, or use a Raspberry Pi, or use an old, pre-ME computer. Until there is evidence, this is technically just a government conspiracy theory.

It isn't a conspiracy when the feared idea has been confirmed. There is a separate os running on the cpu to monitor and control each and every single one of new intel machines.

Right, but there's no confirmation of any remote access or spying going on.

Re: “We have obtained fully functional JTAG for Intel CSME via USB DCI”

#403
post #311
post #186

Earlier quoted context omitted.

> Tape over laptop cameras isn't just a "parents-of-friends" thing, it's a good idea. Buy a set of stickers and support the EFF: https://supporters.eff.org/shop/laptop-camera-cover-set Support the EFF! But I hate the stickers. Everyone puts a sticker on their webcam and completely ignores the hot mic. But you get that false sense of security…

audio only nudies are usually slightly less exciting.

Most people’s hacked nudes will come from pictures they take themselves, not webcam snaps.

Re: “We have obtained fully functional JTAG for Intel CSME via USB DCI”

#404
post #333

Earlier quoted context omitted.

> And yet we really don’t seem to care much. I know we're used to "Internet speed" and the tweet happened an entire 24 hours ago, but give it a bit of time before declaring it dead. Wired and Vice need a second to write it up, and see if it hits the mainstream before declaring the issue ignored. Not saying it will get picked up, though I sure hope it does, but as you point out, it's a bit obscure and takes some expla…

Can you use an ARM Chromebook without it constantly leaking data to Google? I tried to use the C201 without Chrome OS, but with libreboot, and Debian with mainline Linux. I didn't succeed.

A little late to the party, but I also have a libreboot C201, and have successfully installed mainline Debian on a USB drive connected to it. I'm going to put up a comprehensive guide + shell scripts in December when I'm on break from school, but until then, check out these links:

https://github.com/atopuzov/c201/blob/master/debian-install....

https://archlinuxarm.org/platforms/armv7/rockchip/asus-chrom...

The main thing I haven't gotten working yet is the touchpad. For wifi, I'm using an atheros dongle with open firmware.

Re: “We have obtained fully functional JTAG for Intel CSME via USB DCI”

#405
post #297
post #32

At first it looks nice "oh now we can get rid of it" but it also opens up a very scary near future security-wise. We've now entered a realm where an attacker could simply plug a device on an usb port of your computer for a few seconds to have it access your cpu's ME through USB JTAG and take over it, allowing him to have full access and control over what you do/read/open/type over the network, without you ever knowin…

Is it still true that USB devices can be used to execute code on a target's system without user interaction? I thought this behavior disappeared ~10 years ago.

They shouldn't be able to. Firewire devices can because they used DMA without memory protection. I don't think Thunderbolt has the same flaw.

However there are bugs in USB stacks, especially now you can do so many alternate protocols over USB-C.

https://www.jefftk.com/p/malicious-usb-sticks

There's nothing fundamental in the USB spec that lets devices execute code on the host.

Re: “We have obtained fully functional JTAG for Intel CSME via USB DCI”

#406
post #333

Earlier quoted context omitted.

Can you use an ARM Chromebook without it constantly leaking data to Google? I tried to use the C201 without Chrome OS, but with libreboot, and Debian with mainline Linux. I didn't succeed.

A little late to the party, but I also have a libreboot C201, and have successfully installed mainline Debian on a USB drive connected to it. I'm going to put up a comprehensive guide + shell scripts in December when I'm on break from school, but until then, check out these links: https://github.com/atopuzov/c201/blob/master/debian-install.... https://archlinuxarm.org/platforms/armv7/rockchip/asus-chrom... The main t…

The gallium os guys have everything working perfectly on my asus chromebook.

Re: “We have obtained fully functional JTAG for Intel CSME via USB DCI”

#407

Earlier quoted context omitted.

A little late to the party, but I also have a libreboot C201, and have successfully installed mainline Debian on a USB drive connected to it. I'm going to put up a comprehensive guide + shell scripts in December when I'm on break from school, but until then, check out these links: https://github.com/atopuzov/c201/blob/master/debian-install.... https://archlinuxarm.org/platforms/armv7/rockchip/asus-chrom... The main t…

The gallium os guys have everything working perfectly on my asus chromebook.

Yes, but gallium doesn't support arm [1]

[1] https://wiki.galliumos.org/Support/ARM

Re: “We have obtained fully functional JTAG for Intel CSME via USB DCI”

#408

Companies like Intel, who are complicit in helping CIA or any intel agency (government, rogue or otherwise) infiltrate and exploit our systems - need to be held accountable by the market. Intel ME and the (assumed [0]) partnership with CIA to design and build this system - should be an absolute travesty blow to the integrity of their business long-term. Will you, as lead engineer or sys admin for your mission critica…

The landscape is of course complex... but I think that companies exposing their clients to such risk will only learn to protect their clients rights to privacy and to self-determination once organized groups of clients fight back on the court against this kind of practice. This is a question of human rights, not just a technical feature. Companies need to take legal responsibility over their decisions in any case where the security, freedom and free will of clients are at risk.

Re: “We have obtained fully functional JTAG for Intel CSME via USB DCI”

#409

Earlier quoted context omitted.

> > Intel ME and the (assumed [0]) partnership with CIA to design and build this system Then why do you need security clearance to work on Intel ME?

Think about it logically for a second. Regardless of the decisions that led up to the inclusion of Intel ME in Intel CPUs (i.e. regardless of whether the CIA was involved or not), compromising Intel ME is still a security risk for Intel customers, so of course they're going to limit access to a select few that they trust, and that the government can trust. I'm fairly certain similar restrictions will also apply to th…

Security though obscurity doesn't work.

Re: “We have obtained fully functional JTAG for Intel CSME via USB DCI”

#410
post #400

Earlier quoted context omitted.

The usual* way to handle this is to have a small LED next to the mic/camera that shows when it's on -- and have it wired up to the device in series, such that it's software-impossible for the device to be powered without the light being on. *: it's what we did on the One Laptop Per Child laptop, and I'm sure others have too.

Thank you for inventing the netbook and showing the ODMs how to make low cost PC notebooks. Any idea where to get a CLI-from-boot notebook for teaching kids programming and encouraging a hacker ethic?

Thanks for the kind words! I haven't used it personally, but a programmer in my Twitter feed recommended this one that they've been using with their kids recently. (I don't think there's a heavy emphasis on CLI.)

https://tksstgiftguide.tumblr.com/post/167274832422/our-kids...

Post reply on HN