Live data from Hacker News

Secrets of Intel Management Engine – Hidden code in your chipset

slideshare.net

11–20 of 64 posts

Re: Secrets of Intel Management Engine – Hidden code in your chipset

#11
tldr: Intel's remote management capabilities are obscurely baked into every chipset. The ME has out of band access to the network card and main memory. Since ME also has its own flashable memory in principle a machine could be compromised in a nearly undetectable way. The presentation shows that a lot of interesting details of ME have been brought to light but it has also withstood a first round of attacks. No rootkit has yet been shown to be practical.

Re: Secrets of Intel Management Engine – Hidden code in your chipset

#12

Wow. SPARC and Java, two things you wouldn't ever expect Intel hardware to ship with! The mention of SOAP-based protocols is also rather surprising, since they have rather high overhead, and this means ME is not just a little 8051-class MCU but almost a fully-featured PC itself... The amount of complexity - and the opportunities to hide things in that - has increased so much compared to earlier PCs that in some ways…

Do fewer people know how to write SPARC shellcode than x86?

Re: Secrets of Intel Management Engine – Hidden code in your chipset

#13

tldr: Intel's remote management capabilities are obscurely baked into every chipset. The ME has out of band access to the network card and main memory. Since ME also has its own flashable memory in principle a machine could be compromised in a nearly undetectable way. The presentation shows that a lot of interesting details of ME have been brought to light but it has also withstood a first round of attacks. No rootki…

what an unlikely coincidence. amazing what nature can come up with without any sort of plan or guidance. :)

Re: Secrets of Intel Management Engine – Hidden code in your chipset

#14

tldr: Intel's remote management capabilities are obscurely baked into every chipset. The ME has out of band access to the network card and main memory. Since ME also has its own flashable memory in principle a machine could be compromised in a nearly undetectable way. The presentation shows that a lot of interesting details of ME have been brought to light but it has also withstood a first round of attacks. No rootki…

It just has to be a matter of time until it is cracked. I am surprised Intel did this.

Re: Secrets of Intel Management Engine – Hidden code in your chipset

#15
post #3

My second thought on reading this was how can a server be PCI compliant with Intel management engine installed? but a quick search shows that Intel have thought of this: http://www.intel.co.uk/content/dam/www/public/us/en/document... My first thought was that it seems increasingly clear that Stallman has been right all along.

> My first thought was that it seems increasingly clear that Stallman has been right all along. The problem is that being philosophically right doesn't always mean being practically right. In order to create the perfect Stallman-esque machine, one would have to design everything from the logic chips up from scratch, because in the end, no third party can be trusted. He says this himself about the Loongson system he u…

We can certainly do a lot better than this, an attitude of "unless its perfect its futile to even try" is defeatist bullshit, and not what Stallman endorses at all.

Re: Secrets of Intel Management Engine – Hidden code in your chipset

#16

ARC[1], not SPARC. It evolved from the SuperFX chip used in some SNES games. [1]: http://en.wikipedia.org/wiki/ARC_International

The earlier ME versions used an ARC. The later ones use a SPARC. Look at slide 50.

Slide 50 just says "Questions?"

Re: Secrets of Intel Management Engine – Hidden code in your chipset

#17
post #3

My second thought on reading this was how can a server be PCI compliant with Intel management engine installed? but a quick search shows that Intel have thought of this: http://www.intel.co.uk/content/dam/www/public/us/en/document... My first thought was that it seems increasingly clear that Stallman has been right all along.

> My first thought was that it seems increasingly clear that Stallman has been right all along. The problem is that being philosophically right doesn't always mean being practically right. In order to create the perfect Stallman-esque machine, one would have to design everything from the logic chips up from scratch, because in the end, no third party can be trusted. He says this himself about the Loongson system he u…

rms doesn't have the Loongson netbook anymore, he rolls with a Gluglug X60 now I believe.

Re: Secrets of Intel Management Engine – Hidden code in your chipset

#18
"Can be active even when the system is hibernating or turned off (but connected to mains)"

On top of the security issues, it seems Intel owes a lot of people some reimbursements for their share of the power bill. Unfortunately, I suspect this theft of electricity will be quietly swept under the rug and forgotten about.

Re: Secrets of Intel Management Engine – Hidden code in your chipset

#19

Earlier quoted context omitted.

> My first thought was that it seems increasingly clear that Stallman has been right all along. The problem is that being philosophically right doesn't always mean being practically right. In order to create the perfect Stallman-esque machine, one would have to design everything from the logic chips up from scratch, because in the end, no third party can be trusted. He says this himself about the Loongson system he u…

We can certainly do a lot better than this, an attitude of "unless its perfect its futile to even try" is defeatist bullshit, and not what Stallman endorses at all.

> "unless its perfect its futile to even try"

I didn't say that. I said there's little we can do, not nothing we can do. And there are people, Stallman and others, who are doing something. I'm simply acknowledging that it's a mountain, not a foothill.

Re: Secrets of Intel Management Engine – Hidden code in your chipset

#20

Earlier quoted context omitted.

> My first thought was that it seems increasingly clear that Stallman has been right all along. The problem is that being philosophically right doesn't always mean being practically right. In order to create the perfect Stallman-esque machine, one would have to design everything from the logic chips up from scratch, because in the end, no third party can be trusted. He says this himself about the Loongson system he u…

rms doesn't have the Loongson netbook anymore, he rolls with a Gluglug X60 now I believe.

Thanks for that, I'll have to look into that device and see what it's all about.

Edit: So it's an off the shelf Thinkpad X60 with fully open source software? I thought that was something he was wary of, given his stance on Intel's partially closed designs. Also, wouldn't the TPM chip be an obstacle given the privacy concerns surrounding it raised by RMS himself?[1] From what I saw from the gluglug website, there is no mention of removing or disabling the TPM module, though I suppose one could remove it from the board themselves after purchase.

[1]: https://www.gnu.org/philosophy/can-you-trust.html

Post reply on HN