Live data from Hacker News

How Purism avoids Intel’s Active Management Technology

puri.sm

101–110 of 121 posts

Re: How Purism avoids Intel’s Active Management Technology

#101

I've been hearing about Intel’s Active Management Technology for years, but I'd like to see a demonstration of how an attack would work. I have an unused laptop with: 1. an Intel CPU that supports the vPro feature set 2. an Intel networking card 3. the corporate version of the Intel Management Engine (Intel ME) binary (well, definitely, a corporate laptop that used to get updates, but how do I check for ME?) Is there…

Absence of evidence is not the evidence for absence. If the backdoor exists you will need to know a secret to open it. Currently, the public obviously doesn't know this secret or the doors would be wide open for virtually anybody. Because we don't know the secret key, we cannot open them to prove that they exist. So we don't know for sure if the backdoors exist. But the way the IME is designed and handled makes it po…

The odds of this being actively exploited by a nation state is higher than it not being exploited. It's too juicy of a attack target, while being almost universally deployed since 2008.

Even 14 years ago the FBI was using off cellphones as microphones, recording in-person conversations in a restaurant between some Mafia targets. It was acknowledged during a criminal trial, which means it was probably old-hat by then:

> Kaplan's opinion said that the eavesdropping technique "functioned whether the phone was powered on or off."

> He ruled that the "roving bug" was legal because federal wiretapping law is broad enough to permit eavesdropping even of conversations that take place near a suspect's cell phone.

https://www.cnet.com/news/fbi-taps-cell-phone-mic-as-eavesdr...

Getting access to laptops/PCs regardless of power state with long-term persistence and very low detectability, regardless of traditional OS monitoring, would be top of the list in terms of requirements for any intelligence agency.

Re: How Purism avoids Intel’s Active Management Technology

#103

I've been hearing about Intel’s Active Management Technology for years, but I'd like to see a demonstration of how an attack would work. I have an unused laptop with: 1. an Intel CPU that supports the vPro feature set 2. an Intel networking card 3. the corporate version of the Intel Management Engine (Intel ME) binary (well, definitely, a corporate laptop that used to get updates, but how do I check for ME?) Is there…

Absence of evidence is not the evidence for absence. If the backdoor exists you will need to know a secret to open it. Currently, the public obviously doesn't know this secret or the doors would be wide open for virtually anybody. Because we don't know the secret key, we cannot open them to prove that they exist. So we don't know for sure if the backdoors exist. But the way the IME is designed and handled makes it po…

>So we don't know for sure if the backdoors exist

Doesn't the NSA_High_Assurance_Platform bit or whatever it's called pretty much prove there's a backdoor?

edit: Here it is: https://en.wikipedia.org/wiki/Intel_Management_Engine#%22Hig...

Why would the NSA demand such a feature if they didn't foresee even a potential vulnerability there?

Re: How Purism avoids Intel’s Active Management Technology

#105
post #49

Still no 16x10 screens. Welcome to the failbin.

A bit harsh, but sure, once you go 16:10 it's very hard to go back to 16:9 laptops.

> once you go 16:10 it's very hard to go back to 16:9 laptops.

flashbacks from 2010 incoming ...

I still don't understand why people accepted the downgrade back then so easily, some of them even thinking 16:9 is somehow more modern or better.

Re: How Purism avoids Intel’s Active Management Technology

#106
post #22
post #2

Looking forward to AMD laptops with Coreboot support as well.

AMD has a similar backdoor: https://en.wikipedia.org/wiki/AMD_Platform_Security_Processo...

I would argue that the out of band management provided by DMTF DASH is closer to what people consider then Intel backdoor then the AMD PSP. The PSP cannot be accessed remotely and is only available locally which removes most of the attack surface.

https://www.amd.com/system/files/documents/out-of-band-clien...

Re: How Purism avoids Intel’s Active Management Technology

#107
post #72

Earlier quoted context omitted.

I feel TrackPoint and Trackpad both present at the same time is ugly But FWIW the inspiration for the red cap is from pickled plum in bento boxes[0] so [0]: https://images.app.goo.gl/Xf3kHjv9JVMdeXA77

> But FWIW the inspiration for the red cap is from pickled plum in bento boxes I get now why so many anime people love thinkpads.

lol you’re downvoted but right. IBM had a lab to the west of Tokyo where lots of ThinkPads were said to have born there so not just people like them but same people make them.

Re: How Purism avoids Intel’s Active Management Technology

#108

Earlier quoted context omitted.

The trackpoint is the single reason I never bought a Thinkpad.

It's certainly one of those "acquired tastes", though like with 3.5mm elimination, I don't understand the sheer vitriol against it by those who happen not to use it. Why do you care? If everything else in Thinkpad appealed to you, why would an eminently ignorable feature be such a HUGE ("single reason") deal breaker? In my mind, either a) There are other reasons and this is a convenient conscious or subconscious scap…

Not much against nipple itself, but what about the TWO GIANT physical clicky buttons under the spacebar?

- extra accidental clicks - steal of space from the touchpad - more moving parts - visual clutter - undermine chassis rigidity - add weight - With touchscreen and a good touchpad, there's nothing that justifies its existence.

Maybe I have a fixation for minimalism too.

Re: How Purism avoids Intel’s Active Management Technology

#109
post #93

Clearly there’s demand for an Intel product with these features absent from the platform controller hub. I acknowledge that hardware products take years to develop, and they already have a lot on their plate. Perhaps Intel doesn’t care about consumer whims, but clearly there’s demand from companies like Google. I’m just generally surprised at the lack of public-facing responses from Intel’s leadership around this and…

[deleted]

Re: How Purism avoids Intel’s Active Management Technology

#110

Earlier quoted context omitted.

It's certainly one of those "acquired tastes", though like with 3.5mm elimination, I don't understand the sheer vitriol against it by those who happen not to use it. Why do you care? If everything else in Thinkpad appealed to you, why would an eminently ignorable feature be such a HUGE ("single reason") deal breaker? In my mind, either a) There are other reasons and this is a convenient conscious or subconscious scap…

Not much against nipple itself, but what about the TWO GIANT physical clicky buttons under the spacebar? - extra accidental clicks - steal of space from the touchpad - more moving parts - visual clutter - undermine chassis rigidity - add weight - With touchscreen and a good touchpad, there's nothing that justifies its existence. Maybe I have a fixation for minimalism too.

>but what about the TWO GIANT physical clicky buttons under the spacebar?

AFAIK that's designed to be used with the trackpoint. Otherwise you don't have any keys to left/middle/right click with.

Post reply on HN