Live data from Hacker News

Intel ME Manufacturing Mode: obscured dangers and MacBook vulnerability

blog.ptsecurity.com

41–50 of 85 posts

Re: Intel ME Manufacturing Mode: obscured dangers and MacBook vulnerability

#41

A couple of small vendors are trying to offer choices with open firmware. They don't yet have the scale for low cost pricing. 1) Purism has been discussed on HN, trying to extend their laptop coreboot success to a phone form factor, http://puri.sm 2) Librebox is a desktop computer with coreboot, from Portugal, https://libretrend.com and https://youtube.com/watch?&v=mHyJCSqWhFw For data centers, OpenCompute server own…

Also https://www.raptorcs.com/TALOSII/. Pricy, but no longer impossibly so.

Re: Intel ME Manufacturing Mode: obscured dangers and MacBook vulnerability

#42
post #7

Does ME Manufacturing mode allow the user to change all the configuration? Does it mean that hackers who incidentally purchased such a machine (but probably not Apple's) with ME Manufacturing mode enabled, can theoretically port coreboot to the machine, then flash their own public key fingerprints into ME, using Boot Guard to protect firmware signed by themselves instead of OEM's? I remember several bunches of Lenovo…

It sure would be nice if we could just purchase such unlocked devices directly. You used to actually control the devices you purchased. Then mobile comes along and so far we've seen locked OS accounts (rooting), locked bootloaders, and locked basebands. Now there's locked ME or PSP. This is getting ridiculous, as well as difficult to keep track of. Perhaps we need some sort of "Fully Unlocked" certification to indica…

Like this one? https://fsf.org/ryf

"The "Respects Your Freedom" computer hardware product certification program encourages the creation and sale of hardware that will do as much as possible to respect your freedom and your privacy, and will ensure that you have control over your device. "

Re: Intel ME Manufacturing Mode: obscured dangers and MacBook vulnerability

#43
post #35

Earlier quoted context omitted.

They also won government contracts by not doing it; the High Assurance Platform mode (‘setting the HAP bit’) was a feature implemented by Intel for the NSA, incidentally discovered by security researchers. Dell sold laptops with this as an option until they were asked not to. It would be pretty easy for a sizable country or even a wealthy US state to demand that these ‘secure’ co-processors can be disabled at the use…

> Dell sold laptops with this as an option until they were asked not to. Source?

https://www.reddit.com/r/linuxhardware/comments/7grglm/how_t...

Re: Intel ME Manufacturing Mode: obscured dangers and MacBook vulnerability

#44
post #23

Earlier quoted context omitted.

NSA can't hire the hackers they want because they all smoke weed. China sends all their drug users to the execution van so all the new CS and security grads can go right to work for the govt.

I once worked with a guy who had previously worked for GCHQ doing something with cyphers/cryptography. He said he had never consumed more drugs in his life than during that period. They didn't care he took drugs as long as he was open about it and couldn't be black mailed through his use of drugs.

Interesting! Though GCHQ is UK, I'm not sure what the NSA is like. My impression so far here has been that they tend to hire people who live rather boring, quiet personal lives, since they're easier to vet.

I'm sure non-mainstream political views likely count against you more, though.

Re: Intel ME Manufacturing Mode: obscured dangers and MacBook vulnerability

#45
post #5

Does ME Manufacturing mode allow the user to change all the configuration? Does it mean that hackers who incidentally purchased such a machine (but probably not Apple's) with ME Manufacturing mode enabled, can theoretically port coreboot to the machine, then flash their own public key fingerprints into ME, using Boot Guard to protect firmware signed by themselves instead of OEM's? I remember several bunches of Lenovo…

Exactly. Remember Intel ME is a great utility and has some awesome abilities. The issue that people have is not the fact there is a CPU running another CPU that looks after the main one. It's that it's closed source and has remote control capabilities that can not be controlled by the user. If Intel would just allow an owner to build and flash their own Intel ME version using their own private/public keys then no one…

> If Intel would just allow an owner to build and flash their own Intel ME version using their own private/public keys then no one would have an issue with that.

Note that unless you manufacture the CPU yourself you still cannot be sure if there are no hidden backdoors. For example the ME could pretend it's really running your firmware but at the same time running some hidden code only delegating some operations to your code.

Re: Intel ME Manufacturing Mode: obscured dangers and MacBook vulnerability

#46

A couple of small vendors are trying to offer choices with open firmware. They don't yet have the scale for low cost pricing. 1) Purism has been discussed on HN, trying to extend their laptop coreboot success to a phone form factor, http://puri.sm 2) Librebox is a desktop computer with coreboot, from Portugal, https://libretrend.com and https://youtube.com/watch?&v=mHyJCSqWhFw For data centers, OpenCompute server own…

Purism is a sham. They are openly trying to abuse the RYF process to get a phone with proprietary firmware blobs certified as "RYF", defeating the entire point of the RYF programme: https://puri.sm/posts/librem5-solving-the-first-fsf-ryf-hurd...

They also have a history of selling x86 systems while articulating vague hopes that the blob/owner control situation will improve in the future, despite this being clearly implausible. In one case for example, they claimed they might get Intel to sign a custom ME firmware for them in the future. Anyone who knows anything about the ME knows that Intel would never do this, ever.

Re: Intel ME Manufacturing Mode: obscured dangers and MacBook vulnerability

#47
post #5

Does ME Manufacturing mode allow the user to change all the configuration? Does it mean that hackers who incidentally purchased such a machine (but probably not Apple's) with ME Manufacturing mode enabled, can theoretically port coreboot to the machine, then flash their own public key fingerprints into ME, using Boot Guard to protect firmware signed by themselves instead of OEM's? I remember several bunches of Lenovo…

Exactly. Remember Intel ME is a great utility and has some awesome abilities. The issue that people have is not the fact there is a CPU running another CPU that looks after the main one. It's that it's closed source and has remote control capabilities that can not be controlled by the user. If Intel would just allow an owner to build and flash their own Intel ME version using their own private/public keys then no one…

I previously wrote about why this will never happen. https://www.devever.net/~hl/intelme

The TLDR is that once they started putting a CPU vendor-controlled management CPU on their chipsets, they realised they could use it to implement DRM that Hollywood had been asking them for. We know that AMD has a contractual obligation to DRM vendors not to open source their GPU firmware for this reason, and it's likely Intel and AMD have similar contractual obligations as regards their Intel ME/AMD PSP firmware, as these are also involved in DRM.

Re: Intel ME Manufacturing Mode: obscured dangers and MacBook vulnerability

#48

A couple of small vendors are trying to offer choices with open firmware. They don't yet have the scale for low cost pricing. 1) Purism has been discussed on HN, trying to extend their laptop coreboot success to a phone form factor, http://puri.sm 2) Librebox is a desktop computer with coreboot, from Portugal, https://libretrend.com and https://youtube.com/watch?&v=mHyJCSqWhFw For data centers, OpenCompute server own…

Librebox seems interesting, but since it uses an i7, won't it still run ME?

Re: Intel ME Manufacturing Mode: obscured dangers and MacBook vulnerability

#49
post #45
post #5

Earlier quoted context omitted.

Exactly. Remember Intel ME is a great utility and has some awesome abilities. The issue that people have is not the fact there is a CPU running another CPU that looks after the main one. It's that it's closed source and has remote control capabilities that can not be controlled by the user. If Intel would just allow an owner to build and flash their own Intel ME version using their own private/public keys then no one…

> If Intel would just allow an owner to build and flash their own Intel ME version using their own private/public keys then no one would have an issue with that. Note that unless you manufacture the CPU yourself you still cannot be sure if there are no hidden backdoors. For example the ME could pretend it's really running your firmware but at the same time running some hidden code only delegating some operations to y…

I understand and agree with you to a certain extent, but we're not just talking about a couple of assembly commands that could be misused. The Intel ME is a FULL Operating System running MINIX Linux (edit: MINIX is not Linux, as corrected by @dragonwriter). It has it's own network and apps, that run inside a running kernel, of which you have no access to.

Even if the intentions are 100% legit, this is an operating system that you can not update (as frequently as your main operating system), and has many attack vectors.

Yes, it could pretend to run your firmware, but secretly load it's own, but it's actually quite hard to hide a 5mb (2mb min) piece of firmware in the chip. Research microchip decapping. You can clearly see the different regions of the chip.

But yes, it could be possible to hide a few x64 instructions, or circuits that could be manipulated. But running a remote control environment that can share your screen without your knowledge can only really be done clearly by running a large separate application stack alongside your main chip. (For now, who knows where we'll be in 5 to 10 years).

Re: Intel ME Manufacturing Mode: obscured dangers and MacBook vulnerability

#50
post #23

Earlier quoted context omitted.

And still fail. The state is dysfunctional in many regards.

NSA can't hire the hackers they want because they all smoke weed. China sends all their drug users to the execution van so all the new CS and security grads can go right to work for the govt.

Also a lot of hackers/engineers have ethics that don't necessarily match that of government security agencies. I would happily work to protect my country from terrorism or foreign attacks, but not if it means sacrificing the freedoms that we were originally trying to protect.
Post reply on HN