Live data from Hacker News

'Unfixable' security flaw in Intel boot ROM

theregister.co.uk

1–10 of 65 posts

Re: 'Unfixable' security flaw in Intel boot ROM

#2
The useful gist:

> "To fully compromise EPID, hackers would need to extract the hardware key used to encrypt the Chipset Key, which resides in Secure Key Storage (SKS)," explained Positive's Mark Ermolov.

> "However, this key is not platform-specific. A single key is used for an entire generation of Intel chipsets. And since the ROM vulnerability allows seizing control of code execution before the hardware key generation mechanism in the SKS is locked, and the ROM vulnerability cannot be fixed, we believe that extracting this key is only a matter of time.

> "When this happens, utter chaos will reign. Hardware IDs will be forged, digital content will be extracted, and data from encrypted hard disks will be decrypted."

And this formidable response as usual:

> Intel says folks should install the firmware-level mitigations, "maintain physical possession of their platform," and "adopt best security practices by installing updates as soon as they become available and being continually vigilant to detect and prevent intrusions and exploitations."

When will it stop? How deep run the flaws in Intel's platform? Is AMD equally exposed?

Re: 'Unfixable' security flaw in Intel boot ROM

#6

The useful gist: > "To fully compromise EPID, hackers would need to extract the hardware key used to encrypt the Chipset Key, which resides in Secure Key Storage (SKS)," explained Positive's Mark Ermolov. > "However, this key is not platform-specific. A single key is used for an entire generation of Intel chipsets. And since the ROM vulnerability allows seizing control of code execution before the hardware key genera…

> "maintain physical possession of their platform"

That ship has sailed.

Re: 'Unfixable' security flaw in Intel boot ROM

#7
> This is used for things like providing anti-piracy DRM protections, and Internet-of-Things attestation

"Internet-of-Things attestation" ?? A poor attempt to stick a refreshing buzzword in front of a fundamentally unwanted user-betraying open-society-undermining technology.

Remote attestation does away with the basic foundation of protocols for mediating between mutually-untrusting parties, making it so users must trust the remote party. Imagine if websites attempting to enforce (browser fingerprinting, no image save, anti-adblock, etc) could successfully implement their hostile restrictions!

This break is great news for everybody that wants their computer to remain under their own control, rather than an increasingly locked down Big Tech WebTV.

Re: 'Unfixable' security flaw in Intel boot ROM

#8

The useful gist: > "To fully compromise EPID, hackers would need to extract the hardware key used to encrypt the Chipset Key, which resides in Secure Key Storage (SKS)," explained Positive's Mark Ermolov. > "However, this key is not platform-specific. A single key is used for an entire generation of Intel chipsets. And since the ROM vulnerability allows seizing control of code execution before the hardware key genera…

> "maintain physical possession of their platform" That ship has sailed.

What about physical possession before you own it? Will this potentially sour a used/refurbished market?

Re: 'Unfixable' security flaw in Intel boot ROM

#9

So ugly, I can't just replace all of our hardware. Remaining forever vigilant is tiring. CPUs are so broken that security is just a facade.

the problem is the hardware being replaced to begin with.

The ME is not needed for the end user to operate thier machine in a secure manner.

The ME is a trojan that allows intel to manipulate your system and lock you into the whole DRM nonsense. the only reason Intel platforms havent become as bad as mobile platforms is because there isnt enough fear of system compromise from the average user.

https://en.wikipedia.org/wiki/Intel_Management_Engine

Re: 'Unfixable' security flaw in Intel boot ROM

#10
post #4

“utter chaos” seems overstated. I’ve never heard of anyone protecting DRM with the TPM on any consumer platform.

I read that part as slightly tongue in cheek. No, it won't be the end of the world, but it will be the end of the usefulness of that hardware.
Post reply on HN