"The weakness of "security through obscurity" is so well known as to be obvious. Yet major hardware manufacturers, citing the need to protect intellectual property, often require a non-disclosure agreement (NDA) before allowing access to technical documentation. " I believe the actual reason for "security through obscurity" is that it's a delay tactic used against well-funded adversaries. There's an inherent problem…
Intel ME Manufacturing Mode: obscured dangers and MacBook vulnerability
21–30 of 85 posts
Re: Intel ME Manufacturing Mode: obscured dangers and MacBook vulnerability
#22Earlier quoted context omitted.
Exactly. Remember Intel ME is a great utility and has some awesome abilities. The issue that people have is not the fact there is a CPU running another CPU that looks after the main one. It's that it's closed source and has remote control capabilities that can not be controlled by the user. If Intel would just allow an owner to build and flash their own Intel ME version using their own private/public keys then no one…
> It's the fact it's a secret closed system that has full control to monitor everything you do, and can not be fully disabled. To add to that, it also makes code audits impossible. Intel, AMD, ARM, et al: There is zero, and I mean ZERO reason to hide management functionality from users in this day and age. It's 2018, security through obscurity has been proven wrong time and time again. It's foolish to think otherwise…
It's not a coding error. It's built to do exactly what it looks like it's supposed to do: diminish any ordinary person's claim of total control over the behavior of the system, such that, should the need arise, a trained hand can lift the proper latch and intervene, to gain the upper hand, ostensibly so "the good guys" win.
The good guys being those that ordered Intel into compliance with such requirements.
Re: Intel ME Manufacturing Mode: obscured dangers and MacBook vulnerability
#23"The weakness of "security through obscurity" is so well known as to be obvious. Yet major hardware manufacturers, citing the need to protect intellectual property, often require a non-disclosure agreement (NDA) before allowing access to technical documentation. " I believe the actual reason for "security through obscurity" is that it's a delay tactic used against well-funded adversaries. There's an inherent problem…
And still fail. The state is dysfunctional in many regards.
Re: Intel ME Manufacturing Mode: obscured dangers and MacBook vulnerability
#24Earlier quoted context omitted.
In other words, this vulnerability is "the insecurity that gives us freedom"? That's what it looks like from a quick scan through the article, and if that's the case this is yet another sad instance where the authoritarian "security" community is openly hostile against user freedom. On that moral point, a relevant comment I made on an article recently: https://news.ycombinator.com/item?id=18102434 Anyone who is activ…
"Freedom or persistent compromise" depending on whether it's the rightful owner or an attacker using the exploit. The most user-hostile part is forcing users to choose between accepting an OEM locked down platform, or running an open platform that an attacker can permanently lock down.
Re: Intel ME Manufacturing Mode: obscured dangers and MacBook vulnerability
#25Earlier quoted context omitted.
In other words, this vulnerability is "the insecurity that gives us freedom"? That's what it looks like from a quick scan through the article, and if that's the case this is yet another sad instance where the authoritarian "security" community is openly hostile against user freedom. On that moral point, a relevant comment I made on an article recently: https://news.ycombinator.com/item?id=18102434 Anyone who is activ…
"Freedom or persistent compromise" depending on whether it's the rightful owner or an attacker using the exploit. The most user-hostile part is forcing users to choose between accepting an OEM locked down platform, or running an open platform that an attacker can permanently lock down.
That is flawed logic. The article demonstrates that the OEM version is insecure. Why would you assume that the open version would be more vulnerable to attackers?
Re: Intel ME Manufacturing Mode: obscured dangers and MacBook vulnerability
#261) Purism has been discussed on HN, trying to extend their laptop coreboot success to a phone form factor, http://puri.sm
2) Librebox is a desktop computer with coreboot, from Portugal, https://libretrend.com and https://youtube.com/watch?&v=mHyJCSqWhFw
For data centers, OpenCompute server owners are also the "OEM" and in control of more keys.
Re: Intel ME Manufacturing Mode: obscured dangers and MacBook vulnerability
#27Earlier quoted context omitted.
And still fail. The state is dysfunctional in many regards.
NSA can't hire the hackers they want because they all smoke weed. China sends all their drug users to the execution van so all the new CS and security grads can go right to work for the govt.
Re: Intel ME Manufacturing Mode: obscured dangers and MacBook vulnerability
#28Earlier quoted context omitted.
> It's the fact it's a secret closed system that has full control to monitor everything you do, and can not be fully disabled. To add to that, it also makes code audits impossible. Intel, AMD, ARM, et al: There is zero, and I mean ZERO reason to hide management functionality from users in this day and age. It's 2018, security through obscurity has been proven wrong time and time again. It's foolish to think otherwise…
So it's a back door. And a hamfisted one at that. It's not a coding error. It's built to do exactly what it looks like it's supposed to do: diminish any ordinary person's claim of total control over the behavior of the system, such that, should the need arise, a trained hand can lift the proper latch and intervene, to gain the upper hand, ostensibly so " the good guys " win. The good guys being those that ordered Int…
There is vast case law surrounding our first amendment right to refuse this kind of coercion. No one can force you to present something as yours against your will (at least, if they want it to hold up in court).
What is more likely is that Intel won a great many more government contracts by doing this. They'd make tons of money doing it, so they did it. And if they didn't do it, their competitor would. That's how the system works in this country.
We shouldn't excuse them so readily.
Re: Intel ME Manufacturing Mode: obscured dangers and MacBook vulnerability
#29Earlier quoted context omitted.
And still fail. The state is dysfunctional in many regards.
NSA can't hire the hackers they want because they all smoke weed. China sends all their drug users to the execution van so all the new CS and security grads can go right to work for the govt.
Re: Intel ME Manufacturing Mode: obscured dangers and MacBook vulnerability
#30Earlier quoted context omitted.
So it's a back door. And a hamfisted one at that. It's not a coding error. It's built to do exactly what it looks like it's supposed to do: diminish any ordinary person's claim of total control over the behavior of the system, such that, should the need arise, a trained hand can lift the proper latch and intervene, to gain the upper hand, ostensibly so " the good guys " win. The good guys being those that ordered Int…
>The good guys being those that ordered Intel into compliance with such requirements. There is vast case law surrounding our first amendment right to refuse this kind of coercion. No one can force you to present something as yours against your will (at least, if they want it to hold up in court). What is more likely is that Intel won a great many more government contracts by doing this. They'd make tons of money doin…
I don't think the gov goes around doing this willy nilly, but I think it's clear that this is about the only reliable way to defeat block ciphers. And since there are only 2 real CPU manufacturers, it's easier to do this than attack crypto directly. My personal pet theory is that the aes keys are kept on the die for later retrieval. That and/or keystrokes.