Live data from Hacker News

Secrets of Intel Management Engine – Hidden code in your chipset

slideshare.net

21–30 of 64 posts

Re: Secrets of Intel Management Engine – Hidden code in your chipset

#21

tldr: Intel's remote management capabilities are obscurely baked into every chipset. The ME has out of band access to the network card and main memory. Since ME also has its own flashable memory in principle a machine could be compromised in a nearly undetectable way. The presentation shows that a lot of interesting details of ME have been brought to light but it has also withstood a first round of attacks. No rootki…

It just has to be a matter of time until it is cracked. I am surprised Intel did this.

My guess is that this was requested and passed by without fully understanding the consequences.

Re: Secrets of Intel Management Engine – Hidden code in your chipset

#22

Earlier quoted context omitted.

> My first thought was that it seems increasingly clear that Stallman has been right all along. The problem is that being philosophically right doesn't always mean being practically right. In order to create the perfect Stallman-esque machine, one would have to design everything from the logic chips up from scratch, because in the end, no third party can be trusted. He says this himself about the Loongson system he u…

We can certainly do a lot better than this, an attitude of "unless its perfect its futile to even try" is defeatist bullshit, and not what Stallman endorses at all.

[deleted]

Re: Secrets of Intel Management Engine – Hidden code in your chipset

#24

tldr: Intel's remote management capabilities are obscurely baked into every chipset. The ME has out of band access to the network card and main memory. Since ME also has its own flashable memory in principle a machine could be compromised in a nearly undetectable way. The presentation shows that a lot of interesting details of ME have been brought to light but it has also withstood a first round of attacks. No rootki…

It just has to be a matter of time until it is cracked. I am surprised Intel did this.

I believe it has already been cracked. See "Persistent, Stealthy, Remote-controlled Dedicated Hardware Malware" from 30c3: https://www.youtube.com/watch?v=Ck8bIjAUJgE

Re: Secrets of Intel Management Engine – Hidden code in your chipset

#25

Earlier quoted context omitted.

rms doesn't have the Loongson netbook anymore, he rolls with a Gluglug X60 now I believe.

Thanks for that, I'll have to look into that device and see what it's all about. Edit: So it's an off the shelf Thinkpad X60 with fully open source software? I thought that was something he was wary of, given his stance on Intel's partially closed designs. Also, wouldn't the TPM chip be an obstacle given the privacy concerns surrounding it raised by RMS himself?[1] From what I saw from the gluglug website, there is n…

From my understanding, you can disable the TPM by removing the kernel driver and any other drivers. The X60 is the last Thinkpad model in which it lives in a separate chip.

Re: Secrets of Intel Management Engine – Hidden code in your chipset

#26

Wow. SPARC and Java, two things you wouldn't ever expect Intel hardware to ship with! The mention of SOAP-based protocols is also rather surprising, since they have rather high overhead, and this means ME is not just a little 8051-class MCU but almost a fully-featured PC itself... The amount of complexity - and the opportunities to hide things in that - has increased so much compared to earlier PCs that in some ways…

Fortunately, a number of non-PC systems exist (one is probably in your pocket).

Re: Secrets of Intel Management Engine – Hidden code in your chipset

#27

Wow. SPARC and Java, two things you wouldn't ever expect Intel hardware to ship with! The mention of SOAP-based protocols is also rather surprising, since they have rather high overhead, and this means ME is not just a little 8051-class MCU but almost a fully-featured PC itself... The amount of complexity - and the opportunities to hide things in that - has increased so much compared to earlier PCs that in some ways…

Not SPARC, ARC: https://en.wikipedia.org/wiki/ARC_International

Re: Secrets of Intel Management Engine – Hidden code in your chipset

#30
post #7

What, SPARC and Java in Intel motherboards? Is this some elaborate gag on Sun/Oracle? I hope they'll demo it by running Solaris there for good measure.

ARC, not SPARC. Did the title on HN say "SPARC" originally or something? Because the slides never mentions SPARC, they discuss ARC, an embedded ISA.
Post reply on HN