Live data from Hacker News

Uncorrectable freedom and security issues on x86 platforms (2016)

decentralize.today

111–120 of 141 posts

Re: Uncorrectable freedom and security issues on x86 platforms (2016)

#111
post #8

Isn't it sci-fi-level incredible, and frankly both scary and shady, that every modern x86 CPU has this forced sub-ring-0 control program? And that the CPU vendors apparently go to extreme lengths in hiding its functionality? Why would even large vendors like Apple or Dell agree to this? The 30-minute timeout is particularly mischievous. It's like they REALLY want to slow down any effort at patching out the ME. Are we…

NSA 100% . Some time around 10 years ago governments decided the internet was too "dangerous" to be free. Arab spring cemented that into their minds, and now a bastion of free thought has become the worlds biggest spying apparatus.

>NSA 100%

What about the other powers? China, France, Russia have their own NSA's that would be asked to provide solutions to protect all the PCs in the service of their own governments, what are they doing about it?

Re: Uncorrectable freedom and security issues on x86 platforms (2016)

#112

Earlier quoted context omitted.

> there is no suggestions for how to secure and harden devices without refining these trusted computing techniques. We need to harden these devices. Because the thing you are asking for is not possible. You have a bad premise: > And I just don't understand how anyone can maintain that farce when the last year has shown that it's a genuine challenge even for the US FBI to unlock a mobile device without the owners say-…

> Which has two flaws. First, it wasn't a challenge for them, they were just using it as an excuse to whine about the second one that actually is. And second, the only real security is math (encryption), but it doesn't require any special support from the hardware. They bought a hack from another company for an old model of phone. If the case had been involving the latest model handset, the vendor claimed they had no…

> They bought a hack from another company for an old model of phone. If the case had been involving the latest model handset, the vendor claimed they had not yet (but were confident they would) hack it.

There is actually an important distinction to make here too.

When you have something like Secure Boot, whose purpose is to make the device trustworthy to enter your passphrase into, it's completely impossible. You don't know if the device you're using is actually the same device, you don't know if someone is watching you, the thing it claims to do is not a thing it can actually accomplish.

But Apple does something separate from that. They have tamper-resistant hardware for storing keys, so that the hardware can store a strong key and enforce a maximum number of guess attempts for a weaker password/PIN.

The disadvantage of this is that it's pure attack surface compared with using a strong passphrase to begin with. If you have a strong passphrase the attacker has to break the encryption. If you have a weak PIN for hardware protecting a stronger key the attacker can break the encryption or break/backdoor the hardware or guess the weak PIN before hitting the maximum number of attempts.

The advantage is of course that it lets you use a PIN instead of a long passphrase, but there is also something else. That hardware doesn't need root. All it needs is to store a key while the device is locked and then spit it back out if you give the right PIN and erase it if you make too many bad attempts. No part of that inherently requires it to be at ring -3. It can be completely independent from all of that.

> And if the device is tamper-resistant?

That's the problem with Secure Boot -- it doesn't matter. Stealing your passphrase by recording it is an attack that can be pulled off by a middle schooler with a nanny cam. It's easier to do that than to backdoor the firmware on a non-tamper-resistant computer, which at least requires you to know what "firmware" is. So what attack are we actually preventing at the cost of having untrusted and potentially vulnerable code at ring -3?

Re: Uncorrectable freedom and security issues on x86 platforms (2016)

#113
post #8

Isn't it sci-fi-level incredible, and frankly both scary and shady, that every modern x86 CPU has this forced sub-ring-0 control program? And that the CPU vendors apparently go to extreme lengths in hiding its functionality? Why would even large vendors like Apple or Dell agree to this? The 30-minute timeout is particularly mischievous. It's like they REALLY want to slow down any effort at patching out the ME. Are we…

Below ring 0 and in addition to ME you have the less known "ring -2". https://en.wikipedia.org/wiki/System_Management_Mode

There is also microcode, and many patches are issued through microcode.

Re: Uncorrectable freedom and security issues on x86 platforms (2016)

#114
post #72

I was struck by the following passage: >including Secure Boot, which even now requires FOSS users to purchase a license from Microsoft to boot FOSS on affected machines that lack an appropriate Secure Boot override." Can someone explain this to me, would this be for instance be Lenovo laptops making a deal with Microsoft since Windows is the default OS installed on these laptops? Is Microsoft mandating all OEMs/hardw…

> now requires FOSS users to purchase a license from Microsoft to boot FOSS This isn't actually true, is it?

Nope. It should be normally possible to disable Secure Boot.

In fact, many distributions don't support Secure Boot at all.

Re: Uncorrectable freedom and security issues on x86 platforms (2016)

#115

Earlier quoted context omitted.

NSA 100% . Some time around 10 years ago governments decided the internet was too "dangerous" to be free. Arab spring cemented that into their minds, and now a bastion of free thought has become the worlds biggest spying apparatus.

>NSA 100% What about the other powers? China, France, Russia have their own NSA's that would be asked to provide solutions to protect all the PCs in the service of their own governments, what are they doing about it?

also how can the American NSA trust the manufacturing process? Couldn't the Chinese counterpart of the NSA possibly reprogram the code of this processor when it was manufactured? Reflections on trusting trust that is...

Re: Uncorrectable freedom and security issues on x86 platforms (2016)

#116
post #108
post #107

Earlier quoted context omitted.

I believe that the Windows 10 logo requirements are exactly the opposite of that. If you look at the UEFI requirements for Windows 10[1], specifically clauses 19 and 20, it says for non-ARM systems the user MUST be able to put Secure Boot into Custom signature-checking mode. [1] https://msdn.microsoft.com/windows/hardware/commercialize/de...

They're not opposites. PCs are required to have secure boot and they're required to have MS's cert installed and they're required to be able to disable secure boot.

This was true in Windows 8 times, but with Windows 10 the requirement to be able to turn off Secure Boot vanished: https://arstechnica.com/information-technology/2015/03/windo...

The whole story around Secure Boot could be understood (even without a tinfoil hat) as a part of a slippery slope to lock out alternative OSes, highly recommended post: https://www.phoronix.com/forums/forum/phoronix/general-discu...

Re: Uncorrectable freedom and security issues on x86 platforms (2016)

#117
post #31

Earlier quoted context omitted.

So why not build our own network with crypto, blackjack & hookers on libre hardware? Say on an OrangePi PC2 with a bunch of high gain USB 5GHz radios attached, and throw some spinning rust on there so you can run a Nextcloud instance and/or join your local Ceph cluster/IPFS. We have CJDNS (which salsa20's all your data & can VPN legacy networks to ya), fully FLOSS SBCs for under $20ea, and 802.11n and AC outdoor radi…

The issue is not widely known, silicon is very costly to manufacture, and most people frankly don't care, as long that spying is unobtrusive (and hell it is so). Also, most people already are living with the thought that their computers are cracked/hacked/virused the moment they are connected to the internet - all my friends and relatives ask me to check their computer for viruses - almost none trust their computers…

Anyone trusting a computer - any computer - is a giant fool in my book. Trust is a strong word, and computers suck balls fundamentally at keeping information safe.

Re: Uncorrectable freedom and security issues on x86 platforms (2016)

#118
post #60

Earlier quoted context omitted.

Secure boot has 4 types of keys: The signature database (db) and forbidden signature database (dbx) contain a whitelist and blacklist respectivly of keys, signatures, and hashes that are trusted to run. Updates to either of the above lists must be signed by a Key Exchange Key (KEK). Most implementations allow multiple Key Exchanges Keys. Updates to the list of Key Exchange Keys must be signed by the Platform Key (PK)…

People are calling the old BIOS "PC BIOS" and UEFI "UEFI BIOS" nowadays. So feel free to continue to call it a BIOS.

Some UEFI implementations even call themselves BIOS :-)

Re: Uncorrectable freedom and security issues on x86 platforms (2016)

#119

Want complete software freedom? How about the MIPS chips the Russian military uses[1]? Those don't have an NSA back door. Sucks you can't really buy them as they are only made for use in Russian military and government applications. "Last year, the Russian government announced that it doesn't want to rely on Intel and AMD chips from the U.S. anymore and will focus more on using homegrown chips from Russia." [1] http:…

There are also the Elbrus processors which I believe are entirely designed in Russia, although some models are manufactured by TSMC (and some are manufactured in Russia).

The early models implemented a proprietary VLIW architecture with enterprise-y features (like hardware-tagged pointers, probably borrowed-ish from Itanium) with a dynamic binary translation layer for x86 compatibility on top, not sure if they still do that or perhaps the other way around now.

Re: Uncorrectable freedom and security issues on x86 platforms (2016)

#120

Earlier quoted context omitted.

> there is no suggestions for how to secure and harden devices without refining these trusted computing techniques. We need to harden these devices. Because the thing you are asking for is not possible. You have a bad premise: > And I just don't understand how anyone can maintain that farce when the last year has shown that it's a genuine challenge even for the US FBI to unlock a mobile device without the owners say-…

> Which has two flaws. First, it wasn't a challenge for them, they were just using it as an excuse to whine about the second one that actually is. And second, the only real security is math (encryption), but it doesn't require any special support from the hardware. They bought a hack from another company for an old model of phone. If the case had been involving the latest model handset, the vendor claimed they had no…

> Most people can't effectively harden themselves against nation-state level attacks (if only because incarceration and interrogation exist and even physical security won't stop them), but nation-state level attacks involving a conspiracy amongst manufacturers and the NSA is the justification used to discredit the use of TPMs.

That is missing the point, as this is not about the security of an individual against targeted attacks, but about the reliability of our governing structure. In order to harden a democracy against subversion by minorities, it's not necessary for each individual to be able to fend off an army. That does not mean that implanting every citizen with a centrally triggered kill device would be a good idea.

Also, no conspiracy is required: If there is a remote access key, say, that is a single point of failure that no company can defend if a nation state wants to have access to it, even if that may well be their intention.

Post reply on HN