Live data from Hacker News

Uncorrectable freedom and security issues on x86 platforms (2016)

decentralize.today

1–10 of 141 posts

Re: Uncorrectable freedom and security issues on x86 platforms (2016)

#2
Should point to: http://mail.fsfeurope.org/pipermail/discussion/2016-April/01...

Canonical presentation: REcon 2014 - Intel Management Engine Secrets (Igor Skochinsky) https://www.youtube.com/watch?v=4kCICUPc9_8

Decoding ME firmware in BIOS updates until Skylake (2015): http://io.netgarage.org/me/

Re: Uncorrectable freedom and security issues on x86 platforms (2016)

#5
This needs more attention. Particularly now that AMD may actually look into cooperating with the community on this matter somewhat. I wouldn't get my hopes up yet though, as this was a Reddit AMA done during a time when AMD is keen to please the community. This matter must not go away for something to be done about it.

Re: Uncorrectable freedom and security issues on x86 platforms (2016)

#8
Isn't it sci-fi-level incredible, and frankly both scary and shady, that every modern x86 CPU has this forced sub-ring-0 control program? And that the CPU vendors apparently go to extreme lengths in hiding its functionality? Why would even large vendors like Apple or Dell agree to this?

The 30-minute timeout is particularly mischievous. It's like they REALLY want to slow down any effort at patching out the ME.

Are we going to have to wait on an insider leak on what's the real deal here? Or have I completely missed out on a perfectly good excuse for what's going on?

Re: Uncorrectable freedom and security issues on x86 platforms (2016)

#9
... I confess I'm very frustrated reading about how trusted computing modules hurt the cause of FOSS but no alternatives to actually try and carry out cryptography to execute trusted code.

Inevitably the complaint is, "Well if they have physical access you're screwed anyways." And I just don't understand how anyone can maintain that farce when the last year has shown that it's a genuine challenge even for the US FBI to unlock a mobile device without the owners say-so and it's getting harder all the time.

If you truly believe that physical access is a trump of any security then you can never trust your hardware anyways, as it is exceptionaly hard to prove it conforms to a spec.

Re: Uncorrectable freedom and security issues on x86 platforms (2016)

#10
post #6

The article states the following for RISCV: >"While this architecture is extremely limited in performance, price" Can anyone say thy the performance of RISCV is so lacking?

Likely because there's no major consumer devices shipping them (or at least high-end versions of them) that could help them hit a scale that brings the cost down, which makes them less viable for a general public consumer standpoint, which means there's less time spent optimizing it.

I remember a wihle back when Google was shopping around for Intel replacements (likely a negotiation tactic), people were saying they should buy the POWER division from IBM (IIRC). That would have been really interesting...

Post reply on HN