Live data from Hacker News

The Intel ME subsystem can take over your machine, can't be audited

boingboing.net

101–110 of 282 posts

Re: The Intel ME subsystem can take over your machine, can't be audited

#101
post #69

I think this is time for AMD or IBM's POWER8/9 to step in. If anything a little good PR vis-a-vis the "rootkit nightmare waiting to happen in your server" would be nice.

See "The World Beyond x86" presentation for a presentation of alternatives, focusing on POWER8:

https://raptorengineering.com/TALOS/op_twbx86.php

https://static.rpteng.com/TALOS/assets/the_world_beyond_x86....

Re: The Intel ME subsystem can take over your machine, can't be audited

#102
post #97

Strange that Intel gives people more reason to go to other processors like ARM when Intel is under such pressure from competition.

Such decisions are not made in the face of pressure. I think, they are made years ago and now they are (still) executed.

In the corporation centers, nobody thinks of critical users that look very carefully on things. They mostly think about the average user, that just wants more "power".

Re: The Intel ME subsystem can take over your machine, can't be audited

#104
post #97

Strange that Intel gives people more reason to go to other processors like ARM when Intel is under such pressure from competition.

Who does this give reason to move to ARM? End-users generally don't have a choice (good luck running AutoCAD on ARM) and OEMs either don't seem to care or list ME as one of the selling points of their systems.

You could make the case that this might convince people to use AMD CPUs, but from what I hear AMD has all the same issues with worse performance to boot.

Re: The Intel ME subsystem can take over your machine, can't be audited

#106
post #69

I think this is time for AMD or IBM's POWER8/9 to step in. If anything a little good PR vis-a-vis the "rootkit nightmare waiting to happen in your server" would be nice.

Unfortunately, AMD follows all bad and destroying trust practices that were developed in Intel.

Re: The Intel ME subsystem can take over your machine, can't be audited

#107
post #22

Earlier quoted context omitted.

It's impossible to "reverse-engineer" a cryptographic signature. Properly implemented (and you can bet that Intel has had time to finalize this) it's computationally insurmountable.

just like how DVD Encryption ( https://en.wikipedia.org/wiki/Content_Scramble_System ) was never reverse engineered because the key was too difficult to crack ?

CSS is only 40 bits, which is ridiculously easy to crack. 56-bit DES keys are pretty unsafe these days, so you want at least 128 bits if you're talking private keys.

If it's using 2048-bit RSA, that's perhaps equivalent to a 256-bit private key.

So entirely different ballpark to CSS.

Re: The Intel ME subsystem can take over your machine, can't be audited

#108

Igor Skochinsky (of IDA Hex-Rays fame, among others) has been studying Intel ME for quite some time. He gave a nice talk at Breakpoint summarizing what he'd discovered (slides here [pdf]: https://github.com/skochinsky/papers/blob/master/2014-10%20%... ). Among other things, he finds that ME is capable of running signed Java code which is pushed to the device. Due to the complexity and size of the Java code, it's quit…

ME is capable of running signed Java code

How much firmware is in the thing? Is there a whole JVM in there? An OS? That's a lot of attack surface.

Re: The Intel ME subsystem can take over your machine, can't be audited

#109

It may be, that Intel didn't plan this as an NSA/XYZ back door - but it doesn't actually matter. What matters is that we know 1) Intel has such technology implemented in allmost all desktops/servers currently running 2) you can access those machines remotely (even over GSM) and perform reads/writes. Example misuse: somebody can put illegal stuff on your machine and then sue you... (Intel has marketed this feature for…

>1) Intel has such technology implemented in allmost all desktops/servers currently running

Ever wondered why Google is working on their own CPU?

Re: The Intel ME subsystem can take over your machine, can't be audited

#110
post #58

Taking another angle: What if the computer's owner wants to use it to access her computer remotely? Are there some instructions how to do this? Is it feasible? If not, then there seems little justification to have a relatively new feature like this turned on by default. Who is this feature really for? If it's not for all users then why is activation mandatory in CPUs after Core2? I mean, if ME has to be active, then…

It's marketed as Intel vPro. Pricing is probably typical enterprise level. This page has more details: http://www.intel.com/content/www/us/en/architecture-and-tech...

Intel vPro page is way more scarer than the OP article :)

http://www.intel.com/content/www/us/en/architecture-and-tech...

Post reply on HN