Live data from Hacker News

Why is the latest Intel hardware unsupported in libreboot? (2017)

libreboot.org

111–120 of 132 posts

Re: Why is the latest Intel hardware unsupported in libreboot? (2017)

#111
post #105
post #94

Earlier quoted context omitted.

> Could a user tell it's happening? What signals would indicate this? Is it increased CPU usage disguised as a system process? Intel AMT allows redirecting graphics output and keyboard/mouse/USB input over network connection. It's like a hardware device connected to HDMI port to capture screen and to USB ports to send inputs, but it's built right into the motherboard. It doesn't spawn a process in the operating syste…

Occasionally all these features would be quite useful if it was documented and accessible for mere mortals.

It is documented and accessible. Not to the extent many people want, but enough to use it. If your CPU and motherboard combination supports remote management, you can usually turn it on by pressing Control+P during boot (launches configuration screen; see motherboard's manual if it doesn't) and then use freely available software like Manageability Commander from Intel's site to manage the PC.

Mandatory disclaimer: it's highly recommended to keep the network port with active management interface isolated in a separate network with no internet access.

Re: Why is the latest Intel hardware unsupported in libreboot? (2017)

#112
post #7

Realistically if some party made use of these backdoors regularly someone would probably have noticed the traffic already.

If you have firmware level access to a device like an NIC, you could theoretically circumvent the NIC reporting any network activity at all from your actions. This wouldn't cover external network monitoring of course, but how often do you scour the packet logs of your router's I/O?

Re: Why is the latest Intel hardware unsupported in libreboot? (2017)

#113

What about sbc's? afaik, they wouldn't be subject to any of this and since Intel and amd are doomed, wouldn't something like a pinebookpro or rpi make for a secure, yet affordable, solution?

Perhaps I need more coffee, but I can't tell if there is sarcasm in this or not.

Wasn't being sarcastic. Assuming your workload can support the hardware, why isn't this a viable alternative? I could do ~99% of my job with one. People below are asking about affordable ways around this and it made me think of this

Re: Why is the latest Intel hardware unsupported in libreboot? (2017)

#114
stupid question I'm mildly wondering

> Another module is the Dynamic Application Loader (DAL), which consists of a Java virtual machine

What does that mean in regards to using intel hardware and oracle's java license mentioning nuclear weapons?

I thought it mentioned nuclear facilities but it looks like it changed at some stage.

Re: Why is the latest Intel hardware unsupported in libreboot? (2017)

#115
post #99
post #66

Earlier quoted context omitted.

There's also the Blackbird which is even more affordable - https://raptorcs.com/content/BK1B01/intro.html . It's still sadly more than I could justify spending - for my non-portable needs I use a ~5 year old Intel NUC which was cheap as chips and still going strong. But if that ever changes a Talos POWER-based system is at top of my list. The Talos guys pop up in the comments on HN now and then and they're very pleas…

> https://raptorcs.com/content/BK1B01/intro.html That motherboard + cpu bundle costs $1732 (plus shipping, I guess). I mean... Okay, it's super cool, but... I doubt that most people can affort that.

What I was saying was it’s more affordable than the Talos II mentioned earlier in this thread. I agree that it’s not exactly cheap, but I don’t think it’s for everyone.

Re: Why is the latest Intel hardware unsupported in libreboot? (2017)

#116
post #112
post #7

Realistically if some party made use of these backdoors regularly someone would probably have noticed the traffic already.

If you have firmware level access to a device like an NIC, you could theoretically circumvent the NIC reporting any network activity at all from your actions. This wouldn't cover external network monitoring of course, but how often do you scour the packet logs of your router's I/O?

For it to remain a secret it has to be noticed by nobody. I do not regularly scour packet logs but you can be sure people exist who do.

Re: Why is the latest Intel hardware unsupported in libreboot? (2017)

#117

After all this time, I'm still trying to work out what is in it for Intel and AMD to force these technologies into their chips with no supported option to disable them and then to be so secretive about what they're doing and exactly who has access to what. I'm not generally one for crazy conspiracy theories, but I have to wonder what is going on behind closed doors that this is still being done by both of the two big…

It’s not a “crazy conspiracy theory” to suggest that intelligence agencies pressure private industry to help them out. Just look at PRISM or Crypto AG. If Intel or AMD tried to refuse they’d be blacklisted for government contracts like Quest, or worse: think about the CIA spying on Congress scandal.

Maybe once the Chinese or some other adversary get caught using this backdoor to steal secrets, or decide to brick a few million systems remotely, just maybe then security will be considered over spyability.

Re: Why is the latest Intel hardware unsupported in libreboot? (2017)

#118
post #63

Earlier quoted context omitted.

Yea, that was disappointing indeed. After reading the first several paragraphs, I was hoping that the answer would be get an AMD processor instead of Intel , but nope. I hope that in the future some manufacturer(s) start making fully open source verifiably secure RISC-V (or ARM) processors, and that we have a migration over to that.

Feel free to call it a conspiracy theory, but I firmly believe the IME/PSP is an operation by one of those three letters. Intel Management Engine is abbreviated as IME, and AMD Platform Security Processor is abbreviated as PSP. Those are each same abbreviation as Input Method Editor, a mandatory keyboard input layer for East Asian languages, and PlayStation Portable, Sony’s game console which cryptographic security i…

Show me any three-letter acronym that doesn't have multiple meanings already attached to it.

Re: Why is the latest Intel hardware unsupported in libreboot? (2017)

#119
post #61

I wonder if Right to Repair legislation would help us with this.

This has nothing to do with repair because the product is not broken by any meaningful definition of the word "broken". It's just ill-designed from a certain POV.

Re: Why is the latest Intel hardware unsupported in libreboot? (2017)

#120
post #61

I wonder if Right to Repair legislation would help us with this.

This has nothing to do with repair because the product is not broken by any meaningful definition of the word "broken". It's just ill-designed from a certain POV.

In the context of the proposed laws, does it have to be already broken for it to be considered repairable?

Personally I'd rather not see the law as a bludgeon aimed at Intel's head but rather as a protocol or platform for communication about this issue. For example an if they released their overclockable CPUs with an individual encryption key for the ME, putting the end-users' interests first, I might be interested in being their customer once again. Right now I have a 2500k SandyBridge and no reason at all to upgrade, and certainly not with an Intel device.

Post reply on HN