Live data from Hacker News

'Unfixable' security flaw in Intel boot ROM

theregister.co.uk

31–40 of 65 posts

Re: 'Unfixable' security flaw in Intel boot ROM

#31
post #9

Earlier quoted context omitted.

the problem is the hardware being replaced to begin with. The ME is not needed for the end user to operate thier machine in a secure manner. The ME is a trojan that allows intel to manipulate your system and lock you into the whole DRM nonsense. the only reason Intel platforms havent become as bad as mobile platforms is because there isnt enough fear of system compromise from the average user. https://en.wikipedia.or…

You know if your did less FUD there's a chance people may actually engage in a conversation with you. Anyone from enterprise knows his much of a timesaver amt is. I make a call andi don't have to wait for the IT dude to appear on my desk- he clicks a few buttons from his desk and my problem is fixed.

Why does that technology, with attendant attack surface, need to be in consumer chips on consumer motherboards?

Besides, we already had a solution for this. It can be provided with add-in cards.

Re: 'Unfixable' security flaw in Intel boot ROM

#32

> This is used for things like providing anti-piracy DRM protections, and Internet-of-Things attestation "Internet-of-Things attestation" ?? A poor attempt to stick a refreshing buzzword in front of a fundamentally unwanted user-betraying open-society-undermining technology. Remote attestation does away with the basic foundation of protocols for mediating between mutually-untrusting parties, making it so users must t…

> "Internet-of-Things attestation" ?? A poor attempt to stick a refreshing buzzword in front of a fundamentally unwanted user-betraying open-society-undermining technology.

While I agree with you at a consumer level, at the industrial level this is a thing. Like, imagine a vertical farm that is controlled by a thousand, networked on-prem robots. An "attestation" mechanism makes setting this up easier and less-error prone.

Re: 'Unfixable' security flaw in Intel boot ROM

#34

Earlier quoted context omitted.

You know if your did less FUD there's a chance people may actually engage in a conversation with you. Anyone from enterprise knows his much of a timesaver amt is. I make a call andi don't have to wait for the IT dude to appear on my desk- he clicks a few buttons from his desk and my problem is fixed.

Why does that technology, with attendant attack surface, need to be in consumer chips on consumer motherboards? Besides, we already had a solution for this. It can be provided with add-in cards.

one thing that comes to mind is that the consumer-based wedge of the pie is handled as an enterprise deployment of its own managed by intel.

Re: 'Unfixable' security flaw in Intel boot ROM

#35

The useful gist: > "To fully compromise EPID, hackers would need to extract the hardware key used to encrypt the Chipset Key, which resides in Secure Key Storage (SKS)," explained Positive's Mark Ermolov. > "However, this key is not platform-specific. A single key is used for an entire generation of Intel chipsets. And since the ROM vulnerability allows seizing control of code execution before the hardware key genera…

> When this happens, utter chaos will reign. Utter chaos? I don't think so. > Hardware IDs will be forged Seems like a victory for privacy. Who wants to be tracked via hardware IDs? > digital content will be extracted Any victory over DRM technology is a good thing. The only people shedding any tears will be those in the copyright industry. > data from encrypted hard disks will be decrypted People actually rely on pr…

Anybody who doesn't want their data copied will be shedding tears. Including anybody with private files.

You are more than welcome to decline to use DRM if you don't like it. Just don't expect people to give you copies of data they don't want shared by you.

Re: 'Unfixable' security flaw in Intel boot ROM

#36
post #30
post #13

Earlier quoted context omitted.

>That ship has sailed. Not in the least. "Cloud" is merely the modern spin on "terminal in the office, mainframe at the HQ". We moved from terminals to local mini/microcomputers back then, and we will move from "cloud" to edge computing again. Notably, serverless and "installable web apps" are already a growing thing. And no, Sun, the network is the computer will not come to pass during this cycle.

> And no, Sun, Now that's a ship that has sailed.

It's a sun that has set.

Re: 'Unfixable' security flaw in Intel boot ROM

#37

Earlier quoted context omitted.

You know if your did less FUD there's a chance people may actually engage in a conversation with you. Anyone from enterprise knows his much of a timesaver amt is. I make a call andi don't have to wait for the IT dude to appear on my desk- he clicks a few buttons from his desk and my problem is fixed.

Why do we need ME for that?

Active Management Technology (AMT) is built on top of Intel ME. ME lets a trusted party control the computer without letting every peer control the computer.

Re: 'Unfixable' security flaw in Intel boot ROM

#39

> This is used for things like providing anti-piracy DRM protections, and Internet-of-Things attestation "Internet-of-Things attestation" ?? A poor attempt to stick a refreshing buzzword in front of a fundamentally unwanted user-betraying open-society-undermining technology. Remote attestation does away with the basic foundation of protocols for mediating between mutually-untrusting parties, making it so users must t…

> "Internet-of-Things attestation" ?? A poor attempt to stick a refreshing buzzword in front of a fundamentally unwanted user-betraying open-society-undermining technology. While I agree with you at a consumer level, at the industrial level this is a thing. Like, imagine a vertical farm that is controlled by a thousand, networked on-prem robots. An "attestation" mechanism makes setting this up easier and less-error p…

How so specifically, compared to say just imaging the devices? Are we really worried about rogue employees putting rootkits on said robots, and to what end?

Remote attestation in general does have positive uses, and would be freedom preserving if the signing keys were controlled by the device's owner. The problem is Intel's design of baking in privileged keys that they themselves control, such that hostile parties can require that you run software that they provably control.

Re: 'Unfixable' security flaw in Intel boot ROM

#40
post #38

So it seems that the flaw can’t plausibly be exploited by a remote or adjacent attacker or software. So what’s the impact here? Warez scene wreaking havoc with lossless WEB-DLs?

if intel can manage your machine state remotely [they can with ME] then someone else can as well.

corporate customers often have an elevated relationship that retail consumers dont have. There is a different level of trust. I dont trust Intel. I didnt ask for ME and i treat any hardware with ME as an edge device.

as far as impact is concerned its possible that clone machines could be manufactured with hardware modifications. how possible depends on how much money someone has to throw at the project.

exploit chips could become a common offering all you need is a steady hand and a solder iron, and a blob of epoxy for good measure if you want to hide the job.

if as a highminded attacker you determine the hardware key, as it stands you can then decode a software key and begin manipulating firmware. The concern being that the same hardware key is used accross all ME chipsets.

Post reply on HN