Live data from Hacker News

Intel ME Manufacturing Mode: obscured dangers and MacBook vulnerability

blog.ptsecurity.com

81–85 of 85 posts

Re: Intel ME Manufacturing Mode: obscured dangers and MacBook vulnerability

#81

Earlier quoted context omitted.

...only until someone finds a bypass for BootGuard, which might actually exist. I'm not too optimistic, but I hope so --- and seeing the reactions of different groups when/if it happens will be interesting to say the least.

CVE-2018-12169: Platform sample code firmware included with Haswell, Broadwell, Skylake, Kaby Lake, Coffee Lake and Cannon Lake processors contains a logic error allowing a physical attacker to bypass BootGuard firmware authentication. https://edk2-docs.gitbooks.io/security-advisory/content/unau... "also potentially allows a developer to "jailbreak" their BootGuard protected laptop since the UEFI DXE volume can be re…

Well, LinuxBoot is more like heads (the kernel based pre-boot environment), which was possible for a while now (because the DXE was often not required to be signed for BootGuard to be happy).

If we could do coreboot with only the FSP as blob, that would be cool. We'd still have the ME glued in tho, so not complete free booting there yet.

Also, sadly, most firmwares out there don't have that 1:1 edk2 code in their firmware.

Re: Intel ME Manufacturing Mode: obscured dangers and MacBook vulnerability

#82
post #70

Earlier quoted context omitted.

I will also never trust Purism after their dishonest claims of having an entirely open laptop and entirely ignoring Intel ME problems for the sake of better marketing.

They've managed to disable the Intel ME in their laptops. https://puri.sm/posts/purism-librem-laptops-completely-disab...

No they haven't. You can't "completely disable" the ME in modern Intel x86 laptops, it is literally instrumental in the boot process.

They can turn on the HAP bit and run me_cleaner, this reduces the amount of code which runs on the ME. This is an attack surface reduction. It is wholly misleading to refer to it as outright disablement of the ME.

Re: Intel ME Manufacturing Mode: obscured dangers and MacBook vulnerability

#83
post #65
post #63

Earlier quoted context omitted.

DRM doesn't stop you from playing pirated content, the goal is to make the content only decryptable using approved hardware/software, to limit people's ability to copy and paste content Willy nilly and share with their friends in Napster fashion. The determined people still stealing content never will be stopped, but it's inconvenient enough that average people aren't going to duplicate DRM-laden stuff themselves. Im…

> Importantly, I think, when there's a higher barrier to content theft, the remaining sources of pirated content are fewer and easier to track. Except DRM on end-user devices is done with security by obscurity and it's never ever worked for media. And never will. So there is so many sources of pirated content that attempts to track of stop them never succeeded. Fortunately NSA and other government spying organization…

Yeah but I bet the hardware makers will still take fat contracts from the content providers to pay lip service to DRM

Re: Intel ME Manufacturing Mode: obscured dangers and MacBook vulnerability

#84
post #46

Earlier quoted context omitted.

Purism is a sham. They are openly trying to abuse the RYF process to get a phone with proprietary firmware blobs certified as "RYF", defeating the entire point of the RYF programme: https://puri.sm/posts/librem5-solving-the-first-fsf-ryf-hurd... They also have a history of selling x86 systems while articulating vague hopes that the blob/owner control situation will improve in the future, despite this being clearly im…

I will also never trust Purism after their dishonest claims of having an entirely open laptop and entirely ignoring Intel ME problems for the sake of better marketing.

> entirely ignoring Intel ME problems

That's a big stretch. Purism does a lot of work, openly, to try to disable ME.

https://duckduckgo.com/?q=intel+me+site%3Apuri.sm

Re: Intel ME Manufacturing Mode: obscured dangers and MacBook vulnerability

#85

Earlier quoted context omitted.

I will also never trust Purism after their dishonest claims of having an entirely open laptop and entirely ignoring Intel ME problems for the sake of better marketing.

> entirely ignoring Intel ME problems That's a big stretch. Purism does a lot of work, openly, to try to disable ME. https://duckduckgo.com/?q=intel+me+site%3Apuri.sm

They ignored it in their marketing. Labeling a laptop as 100% free and open when it wasn't.
Post reply on HN