Live data from Hacker News

'Unfixable' security flaw in Intel boot ROM

theregister.co.uk

21–30 of 65 posts

Re: 'Unfixable' security flaw in Intel boot ROM

#21

The useful gist: > "To fully compromise EPID, hackers would need to extract the hardware key used to encrypt the Chipset Key, which resides in Secure Key Storage (SKS)," explained Positive's Mark Ermolov. > "However, this key is not platform-specific. A single key is used for an entire generation of Intel chipsets. And since the ROM vulnerability allows seizing control of code execution before the hardware key genera…

let's put this way Apple's redesign Mac laptop launch in 2021 is not using intel chips but their own chip

Re: 'Unfixable' security flaw in Intel boot ROM

#22
The labs team at work wrote a bit [0] about why this is over-hyped (more context in the full post):

> Arbitrary code execution is bad! But exploiting this vulnerability requires local access at a minimum, compounded by the attacker needing to exploit a relevant device to gain a foothold on the system. This list of valid footholds is quite limited. For instance, an attacker would need to perform code execution in the ISH or other Platform Controller Hub (PCH) devices — exploiting PCIe devices (like GPUs or RAID controllers) wouldn’t suffice. Additionally, per the original blog post, other methods of exploitation require physical access. Either way, this is limited to incredibly motivated and well-resourced attackers (like a nation-state with a high-value target identified).

[0] https://capsule8.com/blog/ramming-down-hype-via-intel-csme/

Re: 'Unfixable' security flaw in Intel boot ROM

#23
post #13

Earlier quoted context omitted.

> "maintain physical possession of their platform" That ship has sailed.

>That ship has sailed. Not in the least. "Cloud" is merely the modern spin on "terminal in the office, mainframe at the HQ". We moved from terminals to local mini/microcomputers back then, and we will move from "cloud" to edge computing again. Notably, serverless and "installable web apps" are already a growing thing. And no, Sun, the network is the computer will not come to pass during this cycle.

>> That ship has sailed.

AWS makes up a massive fraction of the whole internet. That ship has absolutely not sailed. If your company doesn't own the mainframe, it doesn't control the hardware.

> And no, Sun, the network is the computer will not come to pass during this cycle.

... we are arguing about this via web browser. O365, Google docs, Dropbox, iCloud and company are common ways to work with documents, SaaS has been a wild success in business, and major players (no pun intended) are pushing game streaming. The network isn't the only computer, but for a lot of people it's the main one.

Re: 'Unfixable' security flaw in Intel boot ROM

#24

The useful gist: > "To fully compromise EPID, hackers would need to extract the hardware key used to encrypt the Chipset Key, which resides in Secure Key Storage (SKS)," explained Positive's Mark Ermolov. > "However, this key is not platform-specific. A single key is used for an entire generation of Intel chipsets. And since the ROM vulnerability allows seizing control of code execution before the hardware key genera…

> When this happens, utter chaos will reign.

Utter chaos? I don't think so.

> Hardware IDs will be forged

Seems like a victory for privacy. Who wants to be tracked via hardware IDs?

> digital content will be extracted

Any victory over DRM technology is a good thing. The only people shedding any tears will be those in the copyright industry.

> data from encrypted hard disks will be decrypted

People actually rely on proprietary hardware encryption? They should have learned the lesson when built-in SSD encryption turned out to be worthless.

Re: 'Unfixable' security flaw in Intel boot ROM

#25
post #13

Earlier quoted context omitted.

>That ship has sailed. Not in the least. "Cloud" is merely the modern spin on "terminal in the office, mainframe at the HQ". We moved from terminals to local mini/microcomputers back then, and we will move from "cloud" to edge computing again. Notably, serverless and "installable web apps" are already a growing thing. And no, Sun, the network is the computer will not come to pass during this cycle.

>> That ship has sailed. AWS makes up a massive fraction of the whole internet. That ship has absolutely not sailed. If your company doesn't own the mainframe, it doesn't control the hardware. > And no, Sun, the network is the computer will not come to pass during this cycle. ... we are arguing about this via web browser. O365, Google docs, Dropbox, iCloud and company are common ways to work with documents, SaaS has…

>If your company doesn't own the mainframe

The historical mainframes usually were rented from IBM and the likes. Less sunk investment, less reasons to stick with it.

>we are arguing about this via web browser

Which works equally well for remote AND local resources. Electron is popular for a reason.

All the centralized services - online Docs, Dropbox, Github etc., - are more subject to disruption and replacement than they would want you to believe.

SaaS has been a success in the same way "bring your own device" was a success - an end-run around the ossified, slow-moving and bureaucratic ICT department. It was nimble, fast and elastic; allowed for quick iteration and experimentation. Now that the SaaS is a big game, it's subject to the very same kind of disruption.

Take a look around, you'll see people using local Git repositories, and locally hosted web-based services to get shit done. Just to avoid the hassle of procurement & upkeep of big-name SaaS. Containers let you move the data & code to unmanaged iron where it's close to the user, instead of one big managed datacenter. SaaS and datacenter computing is not nimble anymore; local is nimble, and Google Stadia delivered the eulogy.

Re: 'Unfixable' security flaw in Intel boot ROM

#26

The useful gist: > "To fully compromise EPID, hackers would need to extract the hardware key used to encrypt the Chipset Key, which resides in Secure Key Storage (SKS)," explained Positive's Mark Ermolov. > "However, this key is not platform-specific. A single key is used for an entire generation of Intel chipsets. And since the ROM vulnerability allows seizing control of code execution before the hardware key genera…

[deleted]

Re: 'Unfixable' security flaw in Intel boot ROM

#27

The useful gist: > "To fully compromise EPID, hackers would need to extract the hardware key used to encrypt the Chipset Key, which resides in Secure Key Storage (SKS)," explained Positive's Mark Ermolov. > "However, this key is not platform-specific. A single key is used for an entire generation of Intel chipsets. And since the ROM vulnerability allows seizing control of code execution before the hardware key genera…

> When will it stop? How deep run the flaws in Intel's platform? Is AMD equally exposed?

We're seeing the tide turn from x86 to ARM pretty quick in both the datacenter and laptop markets. AMD should come through relatively unscathed as they're pretty diversified, but Intel is fucked. Graviton2 (Amazon's proprietary ARM stack) absolutely crushes x86 from a $/performance perspective, and there are plenty of other companies building 80+ core ARM chips.

Combined with the persistent rumors that Apple is shifting the Mac to ARM along with Microsoft reviving ARM Windows are a pretty strong signal as to where the laptop / desktop market is headed too. x86 (and by extension Intel's platform) is definitely headed towards a more niche role in the computing landscape.

Re: 'Unfixable' security flaw in Intel boot ROM

#28

> This is used for things like providing anti-piracy DRM protections, and Internet-of-Things attestation "Internet-of-Things attestation" ?? A poor attempt to stick a refreshing buzzword in front of a fundamentally unwanted user-betraying open-society-undermining technology. Remote attestation does away with the basic foundation of protocols for mediating between mutually-untrusting parties, making it so users must t…

"Piracy" is a buzzword too. Copyright infringement is a crime so victimless they feel the need to compare it to literal high seas piracy in order to make an impact.

> This break is great news for everybody that wants their computer to remain under their own control, rather than an increasingly locked down Big Tech WebTV.

Completely agree. This "security breach" is only bad for corporations who want to track users and implement DRM. It's great for the freedom of the people who are actually using the computers.

Re: 'Unfixable' security flaw in Intel boot ROM

#29

The useful gist: > "To fully compromise EPID, hackers would need to extract the hardware key used to encrypt the Chipset Key, which resides in Secure Key Storage (SKS)," explained Positive's Mark Ermolov. > "However, this key is not platform-specific. A single key is used for an entire generation of Intel chipsets. And since the ROM vulnerability allows seizing control of code execution before the hardware key genera…

[deleted]

Re: 'Unfixable' security flaw in Intel boot ROM

#30
post #13

Earlier quoted context omitted.

> "maintain physical possession of their platform" That ship has sailed.

>That ship has sailed. Not in the least. "Cloud" is merely the modern spin on "terminal in the office, mainframe at the HQ". We moved from terminals to local mini/microcomputers back then, and we will move from "cloud" to edge computing again. Notably, serverless and "installable web apps" are already a growing thing. And no, Sun, the network is the computer will not come to pass during this cycle.

> And no, Sun,

Now that's a ship that has sailed.

Post reply on HN