Live data from Hacker News

Intel ME Manufacturing Mode: obscured dangers and MacBook vulnerability

blog.ptsecurity.com

31–40 of 85 posts

Re: Intel ME Manufacturing Mode: obscured dangers and MacBook vulnerability

#31

Earlier quoted context omitted.

So it's a back door. And a hamfisted one at that. It's not a coding error. It's built to do exactly what it looks like it's supposed to do: diminish any ordinary person's claim of total control over the behavior of the system, such that, should the need arise, a trained hand can lift the proper latch and intervene, to gain the upper hand, ostensibly so " the good guys " win. The good guys being those that ordered Int…

>The good guys being those that ordered Intel into compliance with such requirements. There is vast case law surrounding our first amendment right to refuse this kind of coercion. No one can force you to present something as yours against your will (at least, if they want it to hold up in court). What is more likely is that Intel won a great many more government contracts by doing this. They'd make tons of money doin…

They also won government contracts by not doing it; the High Assurance Platform mode (‘setting the HAP bit’) was a feature implemented by Intel for the NSA, incidentally discovered by security researchers.

Dell sold laptops with this as an option until they were asked not to.

It would be pretty easy for a sizable country or even a wealthy US state to demand that these ‘secure’ co-processors can be disabled at the user’s discretion, via regulation.

From the NSA’s perspective, having the keys to the backdoor is an asset, but having a backdoor at all is a huge liability, now they’re not the only game in town. US businesses and citizens simply have more to lose.

Honestly, I think it’s laziness and inertia more than conspiracy.

Re: Intel ME Manufacturing Mode: obscured dangers and MacBook vulnerability

#32

Earlier quoted context omitted.

>The good guys being those that ordered Intel into compliance with such requirements. There is vast case law surrounding our first amendment right to refuse this kind of coercion. No one can force you to present something as yours against your will (at least, if they want it to hold up in court). What is more likely is that Intel won a great many more government contracts by doing this. They'd make tons of money doin…

They also won government contracts by not doing it; the High Assurance Platform mode (‘setting the HAP bit’) was a feature implemented by Intel for the NSA, incidentally discovered by security researchers. Dell sold laptops with this as an option until they were asked not to. It would be pretty easy for a sizable country or even a wealthy US state to demand that these ‘secure’ co-processors can be disabled at the use…

> From the NSA’s perspective, having the keys to the backdoor is an asset, but having a backdoor at all is a huge liability, now they’re not the only game in town. US businesses and citizens simply have more to lose. Honestly, I think it’s laziness and inertia more than conspiracy.

You're assuming (fully) rational actors. It's fairly easy to have blindspots when they are (at least temporarily) useful.

Re: Intel ME Manufacturing Mode: obscured dangers and MacBook vulnerability

#33
post #23

Earlier quoted context omitted.

NSA can't hire the hackers they want because they all smoke weed. China sends all their drug users to the execution van so all the new CS and security grads can go right to work for the govt.

What about countries where drugs have been decriminalized?

They don’t care

Re: Intel ME Manufacturing Mode: obscured dangers and MacBook vulnerability

#34

Does ME Manufacturing mode allow the user to change all the configuration? Does it mean that hackers who incidentally purchased such a machine (but probably not Apple's) with ME Manufacturing mode enabled, can theoretically port coreboot to the machine, then flash their own public key fingerprints into ME, using Boot Guard to protect firmware signed by themselves instead of OEM's? I remember several bunches of Lenovo…

>But finding these unpatched and vulnerable series of machines is a hit-or-miss game with minimum chance of success

Bios update version changes or the name itself mentions 'intel ME' in the manufacturer's site for their products[1] it should be fairly simple to find computers with an older bios version.

[1] : https://www.acer.com/ac/en/IN/content/support-product/6752?b...

Re: Intel ME Manufacturing Mode: obscured dangers and MacBook vulnerability

#35

Earlier quoted context omitted.

>The good guys being those that ordered Intel into compliance with such requirements. There is vast case law surrounding our first amendment right to refuse this kind of coercion. No one can force you to present something as yours against your will (at least, if they want it to hold up in court). What is more likely is that Intel won a great many more government contracts by doing this. They'd make tons of money doin…

They also won government contracts by not doing it; the High Assurance Platform mode (‘setting the HAP bit’) was a feature implemented by Intel for the NSA, incidentally discovered by security researchers. Dell sold laptops with this as an option until they were asked not to. It would be pretty easy for a sizable country or even a wealthy US state to demand that these ‘secure’ co-processors can be disabled at the use…

> Dell sold laptops with this as an option until they were asked not to.

Source?

Re: Intel ME Manufacturing Mode: obscured dangers and MacBook vulnerability

#36
post #24
post #19

Earlier quoted context omitted.

"Freedom or persistent compromise" depending on whether it's the rightful owner or an attacker using the exploit. The most user-hostile part is forcing users to choose between accepting an OEM locked down platform, or running an open platform that an attacker can permanently lock down.

I'd happily pick the third option of running a platform locked down by me, the hardware purchaser, if it were ever made available to the general market. I have absolutely no objection to locked down hardware or DRM-like protections so long as the devices and software I'm using and installing obey me and only me.

I think DRM means that you cannot control the platform completely.

Re: Intel ME Manufacturing Mode: obscured dangers and MacBook vulnerability

#37
post #24

Earlier quoted context omitted.

I'd happily pick the third option of running a platform locked down by me, the hardware purchaser, if it were ever made available to the general market. I have absolutely no objection to locked down hardware or DRM-like protections so long as the devices and software I'm using and installing obey me and only me.

I think DRM means that you cannot control the platform completely.

Agreed, but I wasn't sure how to describe software that attempts to tightly restrict user actions, protect content streams, etc other than as DRM-like. Perhaps just "secure"? Someone controls the platform, and others (users, guests, adversaries, whoever) don't - I just want to be that someone if it's my device.

Re: Intel ME Manufacturing Mode: obscured dangers and MacBook vulnerability

#38

A couple of small vendors are trying to offer choices with open firmware. They don't yet have the scale for low cost pricing. 1) Purism has been discussed on HN, trying to extend their laptop coreboot success to a phone form factor, http://puri.sm 2) Librebox is a desktop computer with coreboot, from Portugal, https://libretrend.com and https://youtube.com/watch?&v=mHyJCSqWhFw For data centers, OpenCompute server own…

[deleted]

Re: Intel ME Manufacturing Mode: obscured dangers and MacBook vulnerability

#39
post #23

Earlier quoted context omitted.

And still fail. The state is dysfunctional in many regards.

NSA can't hire the hackers they want because they all smoke weed. China sends all their drug users to the execution van so all the new CS and security grads can go right to work for the govt.

I once worked with a guy who had previously worked for GCHQ doing something with cyphers/cryptography. He said he had never consumed more drugs in his life than during that period. They didn't care he took drugs as long as he was open about it and couldn't be black mailed through his use of drugs.

Re: Intel ME Manufacturing Mode: obscured dangers and MacBook vulnerability

#40
post #14
post #7

Earlier quoted context omitted.

It sure would be nice if we could just purchase such unlocked devices directly. You used to actually control the devices you purchased. Then mobile comes along and so far we've seen locked OS accounts (rooting), locked bootloaders, and locked basebands. Now there's locked ME or PSP. This is getting ridiculous, as well as difficult to keep track of. Perhaps we need some sort of "Fully Unlocked" certification to indica…

> Perhaps we need some sort of "Fully Unlocked" certification to indicate that a device you're considering purchasing would actually be yours? Maybe we should make it impossible to advertise a product as being purchasable if you also aren't purchasing rights to the software (and the ability to modify it). Just remove ownership from the equation entirely unless they can demonstrate that the user has full control of th…

That would be a pyrrhic victory at best. True ownership of comsumer devices is de facto a thing of the distant past. If you degraded sales to rentals by law, manufacturers would immediately try to jump onto that train and come up with ways to extract even more momey from customers. How would you feel for having to pay your CPU manufacturer for the actual CPU time spent on your personal desktop computer at home? Of course, each core counts separately. Can't have you pay less for running properly paralellized programs, now can we?
Post reply on HN