Live data from Hacker News

Neutralize ME Firmware on SandyBridge and IvyBridge Platforms

hardenedlinux.org

11–20 of 81 posts

Re: Neutralize ME Firmware on SandyBridge and IvyBridge Platforms

#11
rootkit is defined by google search as "a set of software tools that enable an unauthorized user to gain control of a computer system without being detected."

* A set of software tools: Check

* Unauthorized user: Check Caveat: user is not authorized by you, but by someone else (Intel)

* Gain control of a computer system without being detected. Can access your machine while it appears to be "powered off" but plugged in. Has full access to RAM. Can draw undetected on top of screen. Can read screen. Check.

So. Does this qualify the Management Engine as a rootkit? It meets the definition. Just because the rootkit is installed by the manufacturer doesn't make it less of one.

Re: Neutralize ME Firmware on SandyBridge and IvyBridge Platforms

#14
post #9

What if I like using the integrated NIC?

Just reboot after neutralization. "With ME neutralized, the MEI interface disappears from the PCI bus, and the integrated NIC ceases to work, but will resume to work after a reboot."

The phrasing there is confusing. Does the NIC break because the ME is neutralized? Then rebooting again with the ME neutralized will break the NIC again.

Why would the NIC only break once after the ME is neutralized? The system is started from a fully powered-off state after the ME firmware is updated. Maybe the NIC has some sort of non-volatile state that gets updated when the ME fails to initialize, and then the NIC starts working again. That's the most complex explanation so I thought it unlikely, but I'm happy to hear more from someone who has actually neutralized their ME.

Re: Neutralize ME Firmware on SandyBridge and IvyBridge Platforms

#16

As a potential backdoor with access to a computer with compromising the OS, how much is ME neutralized by just not using the integrated NIC and instead using a PCI-E or USB NIC?

How do you think it accesses the network? In fact, I don't think every version has network support in the first place.

Re: Neutralize ME Firmware on SandyBridge and IvyBridge Platforms

#18

As a potential backdoor with access to a computer with compromising the OS, how much is ME neutralized by just not using the integrated NIC and instead using a PCI-E or USB NIC?

The ME firmware includes a Java VM so that other companies can run their secret apps inside the ME's environment (e.g. DRM crypto plugins). That is just one example of all the features included in the ME firmware, and none of it is published or well documented, much less audited at the source level by an independent third party.

The ME is very alarming, and seems to only become more alarming the closer you look at what it is designed to do.

Re: Neutralize ME Firmware on SandyBridge and IvyBridge Platforms

#20

Earlier quoted context omitted.

The NIC permits remote access to the Intel rootkit, you probably don't want to use the NIC.

Can you elaborate?

It is supposed to be used for corporate environments using Intel AMT for remote management.
Post reply on HN