A couple of small vendors are trying to offer choices with open firmware. They don't yet have the scale for low cost pricing. 1) Purism has been discussed on HN, trying to extend their laptop coreboot success to a phone form factor, http://puri.sm 2) Librebox is a desktop computer with coreboot, from Portugal, https://libretrend.com and https://youtube.com/watch?&v=mHyJCSqWhFw For data centers, OpenCompute server own…
Intel ME Manufacturing Mode: obscured dangers and MacBook vulnerability
41–50 of 85 posts
Re: Intel ME Manufacturing Mode: obscured dangers and MacBook vulnerability
#42Does ME Manufacturing mode allow the user to change all the configuration? Does it mean that hackers who incidentally purchased such a machine (but probably not Apple's) with ME Manufacturing mode enabled, can theoretically port coreboot to the machine, then flash their own public key fingerprints into ME, using Boot Guard to protect firmware signed by themselves instead of OEM's? I remember several bunches of Lenovo…
It sure would be nice if we could just purchase such unlocked devices directly. You used to actually control the devices you purchased. Then mobile comes along and so far we've seen locked OS accounts (rooting), locked bootloaders, and locked basebands. Now there's locked ME or PSP. This is getting ridiculous, as well as difficult to keep track of. Perhaps we need some sort of "Fully Unlocked" certification to indica…
"The "Respects Your Freedom" computer hardware product certification program encourages the creation and sale of hardware that will do as much as possible to respect your freedom and your privacy, and will ensure that you have control over your device. "
Re: Intel ME Manufacturing Mode: obscured dangers and MacBook vulnerability
#43Earlier quoted context omitted.
They also won government contracts by not doing it; the High Assurance Platform mode (‘setting the HAP bit’) was a feature implemented by Intel for the NSA, incidentally discovered by security researchers. Dell sold laptops with this as an option until they were asked not to. It would be pretty easy for a sizable country or even a wealthy US state to demand that these ‘secure’ co-processors can be disabled at the use…
> Dell sold laptops with this as an option until they were asked not to. Source?
Re: Intel ME Manufacturing Mode: obscured dangers and MacBook vulnerability
#44Earlier quoted context omitted.
NSA can't hire the hackers they want because they all smoke weed. China sends all their drug users to the execution van so all the new CS and security grads can go right to work for the govt.
I once worked with a guy who had previously worked for GCHQ doing something with cyphers/cryptography. He said he had never consumed more drugs in his life than during that period. They didn't care he took drugs as long as he was open about it and couldn't be black mailed through his use of drugs.
I'm sure non-mainstream political views likely count against you more, though.
Re: Intel ME Manufacturing Mode: obscured dangers and MacBook vulnerability
#45Does ME Manufacturing mode allow the user to change all the configuration? Does it mean that hackers who incidentally purchased such a machine (but probably not Apple's) with ME Manufacturing mode enabled, can theoretically port coreboot to the machine, then flash their own public key fingerprints into ME, using Boot Guard to protect firmware signed by themselves instead of OEM's? I remember several bunches of Lenovo…
Exactly. Remember Intel ME is a great utility and has some awesome abilities. The issue that people have is not the fact there is a CPU running another CPU that looks after the main one. It's that it's closed source and has remote control capabilities that can not be controlled by the user. If Intel would just allow an owner to build and flash their own Intel ME version using their own private/public keys then no one…
Note that unless you manufacture the CPU yourself you still cannot be sure if there are no hidden backdoors. For example the ME could pretend it's really running your firmware but at the same time running some hidden code only delegating some operations to your code.
Re: Intel ME Manufacturing Mode: obscured dangers and MacBook vulnerability
#46A couple of small vendors are trying to offer choices with open firmware. They don't yet have the scale for low cost pricing. 1) Purism has been discussed on HN, trying to extend their laptop coreboot success to a phone form factor, http://puri.sm 2) Librebox is a desktop computer with coreboot, from Portugal, https://libretrend.com and https://youtube.com/watch?&v=mHyJCSqWhFw For data centers, OpenCompute server own…
They also have a history of selling x86 systems while articulating vague hopes that the blob/owner control situation will improve in the future, despite this being clearly implausible. In one case for example, they claimed they might get Intel to sign a custom ME firmware for them in the future. Anyone who knows anything about the ME knows that Intel would never do this, ever.
Re: Intel ME Manufacturing Mode: obscured dangers and MacBook vulnerability
#47Does ME Manufacturing mode allow the user to change all the configuration? Does it mean that hackers who incidentally purchased such a machine (but probably not Apple's) with ME Manufacturing mode enabled, can theoretically port coreboot to the machine, then flash their own public key fingerprints into ME, using Boot Guard to protect firmware signed by themselves instead of OEM's? I remember several bunches of Lenovo…
Exactly. Remember Intel ME is a great utility and has some awesome abilities. The issue that people have is not the fact there is a CPU running another CPU that looks after the main one. It's that it's closed source and has remote control capabilities that can not be controlled by the user. If Intel would just allow an owner to build and flash their own Intel ME version using their own private/public keys then no one…
The TLDR is that once they started putting a CPU vendor-controlled management CPU on their chipsets, they realised they could use it to implement DRM that Hollywood had been asking them for. We know that AMD has a contractual obligation to DRM vendors not to open source their GPU firmware for this reason, and it's likely Intel and AMD have similar contractual obligations as regards their Intel ME/AMD PSP firmware, as these are also involved in DRM.
Re: Intel ME Manufacturing Mode: obscured dangers and MacBook vulnerability
#48A couple of small vendors are trying to offer choices with open firmware. They don't yet have the scale for low cost pricing. 1) Purism has been discussed on HN, trying to extend their laptop coreboot success to a phone form factor, http://puri.sm 2) Librebox is a desktop computer with coreboot, from Portugal, https://libretrend.com and https://youtube.com/watch?&v=mHyJCSqWhFw For data centers, OpenCompute server own…
Re: Intel ME Manufacturing Mode: obscured dangers and MacBook vulnerability
#49Earlier quoted context omitted.
Exactly. Remember Intel ME is a great utility and has some awesome abilities. The issue that people have is not the fact there is a CPU running another CPU that looks after the main one. It's that it's closed source and has remote control capabilities that can not be controlled by the user. If Intel would just allow an owner to build and flash their own Intel ME version using their own private/public keys then no one…
> If Intel would just allow an owner to build and flash their own Intel ME version using their own private/public keys then no one would have an issue with that. Note that unless you manufacture the CPU yourself you still cannot be sure if there are no hidden backdoors. For example the ME could pretend it's really running your firmware but at the same time running some hidden code only delegating some operations to y…
Even if the intentions are 100% legit, this is an operating system that you can not update (as frequently as your main operating system), and has many attack vectors.
Yes, it could pretend to run your firmware, but secretly load it's own, but it's actually quite hard to hide a 5mb (2mb min) piece of firmware in the chip. Research microchip decapping. You can clearly see the different regions of the chip.
But yes, it could be possible to hide a few x64 instructions, or circuits that could be manipulated. But running a remote control environment that can share your screen without your knowledge can only really be done clearly by running a large separate application stack alongside your main chip. (For now, who knows where we'll be in 5 to 10 years).
Re: Intel ME Manufacturing Mode: obscured dangers and MacBook vulnerability
#50Earlier quoted context omitted.
And still fail. The state is dysfunctional in many regards.
NSA can't hire the hackers they want because they all smoke weed. China sends all their drug users to the execution van so all the new CS and security grads can go right to work for the govt.