Live data from Hacker News

Intel ME Manufacturing Mode: obscured dangers and MacBook vulnerability

blog.ptsecurity.com

61–70 of 85 posts

Re: Intel ME Manufacturing Mode: obscured dangers and MacBook vulnerability

#61
post #47
post #5

Earlier quoted context omitted.

Exactly. Remember Intel ME is a great utility and has some awesome abilities. The issue that people have is not the fact there is a CPU running another CPU that looks after the main one. It's that it's closed source and has remote control capabilities that can not be controlled by the user. If Intel would just allow an owner to build and flash their own Intel ME version using their own private/public keys then no one…

I previously wrote about why this will never happen. https://www.devever.net/~hl/intelme The TLDR is that once they started putting a CPU vendor-controlled management CPU on their chipsets, they realised they could use it to implement DRM that Hollywood had been asking them for. We know that AMD has a contractual obligation to DRM vendors not to open source their GPU firmware for this reason, and it's likely Intel an…

Do you have any source for a time this DRM worked? What I mean is that I have watched/downloaded/streamed a lot of pirated content from various sources, using Intel and AMD hardware. CPU's and GPUs. Not once have the drivers blocked the viewing of pirated content via some kind of built in DRM. So if there is DRM baked into the drivers/ME, then what's the point if it doesn't do anything?

Re: Intel ME Manufacturing Mode: obscured dangers and MacBook vulnerability

#62
post #46

A couple of small vendors are trying to offer choices with open firmware. They don't yet have the scale for low cost pricing. 1) Purism has been discussed on HN, trying to extend their laptop coreboot success to a phone form factor, http://puri.sm 2) Librebox is a desktop computer with coreboot, from Portugal, https://libretrend.com and https://youtube.com/watch?&v=mHyJCSqWhFw For data centers, OpenCompute server own…

Purism is a sham. They are openly trying to abuse the RYF process to get a phone with proprietary firmware blobs certified as "RYF", defeating the entire point of the RYF programme: https://puri.sm/posts/librem5-solving-the-first-fsf-ryf-hurd... They also have a history of selling x86 systems while articulating vague hopes that the blob/owner control situation will improve in the future, despite this being clearly im…

I am not sure if seeking a “secondary processor” exclusion qualifies as "abuse". I agree that their products are not as "pure" as advocated by some enthusiasts. But the company itself openly says so and for me that is important.

What I do not like is their absolutely ridiculous pricing of additional equipment. For instance, they ask $499 for a 500GB NVMe storage [1], while it can easily be purchased for less than third the price [2]. When I complained about it, their response was: "we are well aware of the problem and will be addressing it within the next few months". That was 4 months ago.

[1] https://puri.sm/shop/librem-13/ [2] https://www.amazon.com/Samsung-970-EVO-500GB-MZ-V7E500BW/dp/...

Re: Intel ME Manufacturing Mode: obscured dangers and MacBook vulnerability

#63
post #47

Earlier quoted context omitted.

I previously wrote about why this will never happen. https://www.devever.net/~hl/intelme The TLDR is that once they started putting a CPU vendor-controlled management CPU on their chipsets, they realised they could use it to implement DRM that Hollywood had been asking them for. We know that AMD has a contractual obligation to DRM vendors not to open source their GPU firmware for this reason, and it's likely Intel an…

Do you have any source for a time this DRM worked? What I mean is that I have watched/downloaded/streamed a lot of pirated content from various sources, using Intel and AMD hardware. CPU's and GPUs. Not once have the drivers blocked the viewing of pirated content via some kind of built in DRM. So if there is DRM baked into the drivers/ME, then what's the point if it doesn't do anything?

DRM doesn't stop you from playing pirated content, the goal is to make the content only decryptable using approved hardware/software, to limit people's ability to copy and paste content Willy nilly and share with their friends in Napster fashion. The determined people still stealing content never will be stopped, but it's inconvenient enough that average people aren't going to duplicate DRM-laden stuff themselves.

Importantly, I think, when there's a higher barrier to content theft, the remaining sources of pirated content are fewer and easier to track.

Re: Intel ME Manufacturing Mode: obscured dangers and MacBook vulnerability

#64
post #63

Earlier quoted context omitted.

Do you have any source for a time this DRM worked? What I mean is that I have watched/downloaded/streamed a lot of pirated content from various sources, using Intel and AMD hardware. CPU's and GPUs. Not once have the drivers blocked the viewing of pirated content via some kind of built in DRM. So if there is DRM baked into the drivers/ME, then what's the point if it doesn't do anything?

DRM doesn't stop you from playing pirated content, the goal is to make the content only decryptable using approved hardware/software, to limit people's ability to copy and paste content Willy nilly and share with their friends in Napster fashion. The determined people still stealing content never will be stopped, but it's inconvenient enough that average people aren't going to duplicate DRM-laden stuff themselves. Im…

[deleted]

Re: Intel ME Manufacturing Mode: obscured dangers and MacBook vulnerability

#65
post #63

Earlier quoted context omitted.

Do you have any source for a time this DRM worked? What I mean is that I have watched/downloaded/streamed a lot of pirated content from various sources, using Intel and AMD hardware. CPU's and GPUs. Not once have the drivers blocked the viewing of pirated content via some kind of built in DRM. So if there is DRM baked into the drivers/ME, then what's the point if it doesn't do anything?

DRM doesn't stop you from playing pirated content, the goal is to make the content only decryptable using approved hardware/software, to limit people's ability to copy and paste content Willy nilly and share with their friends in Napster fashion. The determined people still stealing content never will be stopped, but it's inconvenient enough that average people aren't going to duplicate DRM-laden stuff themselves. Im…

> Importantly, I think, when there's a higher barrier to content theft, the remaining sources of pirated content are fewer and easier to track.

Except DRM on end-user devices is done with security by obscurity and it's never ever worked for media. And never will.

So there is so many sources of pirated content that attempts to track of stop them never succeeded. Fortunately NSA and other government spying organizations can still have their backdoor because "Hollywood needs DRM" bullshit.

Re: Intel ME Manufacturing Mode: obscured dangers and MacBook vulnerability

#66
post #46

Earlier quoted context omitted.

Purism is a sham. They are openly trying to abuse the RYF process to get a phone with proprietary firmware blobs certified as "RYF", defeating the entire point of the RYF programme: https://puri.sm/posts/librem5-solving-the-first-fsf-ryf-hurd... They also have a history of selling x86 systems while articulating vague hopes that the blob/owner control situation will improve in the future, despite this being clearly im…

I am not sure if seeking a “secondary processor” exclusion qualifies as "abuse". I agree that their products are not as "pure" as advocated by some enthusiasts. But the company itself openly says so and for me that is important. What I do not like is their absolutely ridiculous pricing of additional equipment. For instance, they ask $499 for a 500GB NVMe storage [1], while it can easily be purchased for less than thi…

The secondary processor exception exists for legitimate reasons. If you have some machine with 100% open source boot firmware, Coreboot, etc., that's still worth certifying even if some Ethernet chip turns out to have firmware inside it.

What Purism is doing is moving memory init code away from the CPU on which it would normally and most naturally execute (in terms of engineering design decisions) for the express purpose of moving something they can't actually open out of the scope of RYF. And are then brazenly admitting how they are gaming this in the above blogpost.

Most people would expect "open source firmware" to mean "open source memory initialisation", because we understand that's something the firmware does. Moving this onto a secondary CPU is literally no better than proprietary firmware. It can't be audited, and if it's able to initialise the memory controller, it can be expected to have full access to the system. They're practically carving out an Intel ME-like boot processor here, with much of the same disadvantages and concerns.

Re: Intel ME Manufacturing Mode: obscured dangers and MacBook vulnerability

#68
post #46

Earlier quoted context omitted.

Purism is a sham. They are openly trying to abuse the RYF process to get a phone with proprietary firmware blobs certified as "RYF", defeating the entire point of the RYF programme: https://puri.sm/posts/librem5-solving-the-first-fsf-ryf-hurd... They also have a history of selling x86 systems while articulating vague hopes that the blob/owner control situation will improve in the future, despite this being clearly im…

I am not sure if seeking a “secondary processor” exclusion qualifies as "abuse". I agree that their products are not as "pure" as advocated by some enthusiasts. But the company itself openly says so and for me that is important. What I do not like is their absolutely ridiculous pricing of additional equipment. For instance, they ask $499 for a 500GB NVMe storage [1], while it can easily be purchased for less than thi…

Tangential: I noticed a similar issue with the pricing of SSD drives offered on Dell's Precision Mobile Workstation laptops.

Perhaps Dell's SSDs are extra-awesome in some manner that I'm failing to recognize. But otherwise it makes way more sense to just buy your own SSD drives for those laptops, AFAICT.

Re: Intel ME Manufacturing Mode: obscured dangers and MacBook vulnerability

#69
post #46

A couple of small vendors are trying to offer choices with open firmware. They don't yet have the scale for low cost pricing. 1) Purism has been discussed on HN, trying to extend their laptop coreboot success to a phone form factor, http://puri.sm 2) Librebox is a desktop computer with coreboot, from Portugal, https://libretrend.com and https://youtube.com/watch?&v=mHyJCSqWhFw For data centers, OpenCompute server own…

Purism is a sham. They are openly trying to abuse the RYF process to get a phone with proprietary firmware blobs certified as "RYF", defeating the entire point of the RYF programme: https://puri.sm/posts/librem5-solving-the-first-fsf-ryf-hurd... They also have a history of selling x86 systems while articulating vague hopes that the blob/owner control situation will improve in the future, despite this being clearly im…

I will also never trust Purism after their dishonest claims of having an entirely open laptop and entirely ignoring Intel ME problems for the sake of better marketing.

Re: Intel ME Manufacturing Mode: obscured dangers and MacBook vulnerability

#70
post #46

Earlier quoted context omitted.

Purism is a sham. They are openly trying to abuse the RYF process to get a phone with proprietary firmware blobs certified as "RYF", defeating the entire point of the RYF programme: https://puri.sm/posts/librem5-solving-the-first-fsf-ryf-hurd... They also have a history of selling x86 systems while articulating vague hopes that the blob/owner control situation will improve in the future, despite this being clearly im…

I will also never trust Purism after their dishonest claims of having an entirely open laptop and entirely ignoring Intel ME problems for the sake of better marketing.

They've managed to disable the Intel ME in their laptops.

https://puri.sm/posts/purism-librem-laptops-completely-disab...

Post reply on HN