Live data from Hacker News

Why is the latest Intel hardware unsupported in libreboot? (2017)

libreboot.org

121–130 of 132 posts

Re: Why is the latest Intel hardware unsupported in libreboot? (2017)

#121
post #4

Since Intel/AMD also designs the processor they can also put in backdoors beyond ME, microcode updates, etc. If you don’t trust proprietary blobs, I respect that. But you can’t trust proprietary silicon either.

https://en.wikipedia.org/wiki/Defence_in_depth

Defense in depth fails when the attacker has unrestricted access to the core of your defense infrastructure.

Re: Why is the latest Intel hardware unsupported in libreboot? (2017)

#122
post #63

Earlier quoted context omitted.

Feel free to call it a conspiracy theory, but I firmly believe the IME/PSP is an operation by one of those three letters. Intel Management Engine is abbreviated as IME, and AMD Platform Security Processor is abbreviated as PSP. Those are each same abbreviation as Input Method Editor, a mandatory keyboard input layer for East Asian languages, and PlayStation Portable, Sony’s game console which cryptographic security i…

Show me any three-letter acronym that doesn't have multiple meanings already attached to it.

https://en.wikipedia.org/wiki/Wikipedia:List_of_TLA_disambig... BEZ, CJK, DXF, IEQ, IXH, JGZ, QFP, QTH, SJX, SXA, XPX, XVF and some more.

Re: Why is the latest Intel hardware unsupported in libreboot? (2017)

#123

This is why I have an Apple Powermac G5 or two stored in my basement. These run entirely free of that backdoor.

Can you build a modern browser to run on PPC? Say, latest fully patched firefox? Because using the browser that comes with Ubuntu 16.04 is not an option, security wise.

For Mac OS X 10.5.8 on PowerPC, there is even a specific G5 binary ...

http://www.floodgap.com/software/tenfourfox/

Otherwise for Linux on PowerPC, you can build a modern browser. There are also pre-built binaries:

https://forums.macrumors.com/threads/arctic-fox-web-browser-...

Re: Why is the latest Intel hardware unsupported in libreboot? (2017)

#124
post #76

Are these side-channel based management technologies turns on even on MacBook laptops?

That is a great question. I would assume that they are because the Intel management technology is currently built in to ALL Intel chips for the past 10 years. It may be a good thing that Apple is looking at building their own ARM based Macs.

Re: Why is the latest Intel hardware unsupported in libreboot? (2017)

#125
> What can I use, then?

> Libreboot has support for fam15h AMD hardware (~2012 gen) and some older Intel platforms like Napa, Montevina, Eagle Lake, Lakeport (2004-2006). We also have support for some ARM chipsets (rk3288). On the Intel side, we’re also interested in some of the chipsets that use Atom CPUs (rebranded from older chipsets, mostly using ich7-based southbridges).

This is why I still run Intel hardware, even with the ME. A truly free computing platform seems to be incompatible with high performance modern chips at the moment.

Re: Why is the latest Intel hardware unsupported in libreboot? (2017)

#126

Scrolling up they recommend avoiding Purism hardware because > In particular, the Intel Management Engine is a severe threat to privacy and security, not to mention freedom, since it is a remote backdoor that provides Intel remote access to a computer where it is present. However, the Intel ME has been disabled in Purism hardware since 2017. https://puri.sm/posts/purism-librem-laptops-completely-disab...

Pretty sure that write up was done around 2009

Just to clarify and save anyone else from the ambiguity - it looks like TFA should be tagged [2009], while parents link from Pusim is more recent (2017).

Re: Why is the latest Intel hardware unsupported in libreboot? (2017)

#127
post #105
post #94

Earlier quoted context omitted.

> Could a user tell it's happening? What signals would indicate this? Is it increased CPU usage disguised as a system process? Intel AMT allows redirecting graphics output and keyboard/mouse/USB input over network connection. It's like a hardware device connected to HDMI port to capture screen and to USB ports to send inputs, but it's built right into the motherboard. It doesn't spawn a process in the operating syste…

Occasionally all these features would be quite useful if it was documented and accessible for mere mortals.

Go play with Mesh Commander....

Re: Why is the latest Intel hardware unsupported in libreboot? (2017)

#128

Earlier quoted context omitted.

No SSL => MITMer can definitely read your traffic trivially. Broken SSL => MITMer can possibly negotiate insecure and read your traffic anyway. MITMer can also possibly cause a denial-of-service, or get arbitrary code execution on that one chip that controls your entire CPU . If I had to choose, I would take the first option. (This precludes options like removing the IME entirely, or updating it to a version with non…

I'm coming from a place of good faith here so bear with me. My understanding is that any vulnerability here would also exist in accessing any HTTPS website. I'm assuming you wouldn't choose to browse the web without SSL/TLS, so I'm assuming the difference here is that it's the CPU management chip instead of your browser? I suppose that if you broke SSL/TLS you could commandeer arbitrary AWS/GCP/Azure instances. For t…

There is no specific TLS flaw. The TLS spec is very complicated, so it's difficult to make a library that implements it without bugs. Insofar as TLS implementations have bugs, the TLS implementation in by browser can be updated to fix those bugs. The TLS implementation in my IME cannot.

Re: Why is the latest Intel hardware unsupported in libreboot? (2017)

#129
post #94

Earlier quoted context omitted.

Really? I am curious to know what observations or evidence you base your arguments/predictions on? Do you believe they have an (even better than 'post-Snowden leaks') search-engine like PRISM, but for private networks all around the world? Could a user tell it's happening? What signals would indicate this? Is it increased CPU usage disguised as a system process? And are you talking about mainstream proprietary OS'es…

> Could a user tell it's happening? What signals would indicate this? Is it increased CPU usage disguised as a system process? Intel AMT allows redirecting graphics output and keyboard/mouse/USB input over network connection. It's like a hardware device connected to HDMI port to capture screen and to USB ports to send inputs, but it's built right into the motherboard. It doesn't spawn a process in the operating syste…

It would be a really good idea to have something on your corporate network listening for management engine traffic.

Re: Why is the latest Intel hardware unsupported in libreboot? (2017)

#130
post #65

This is really sad. I am sure hundreds of hours were spent on this project with now essentially does nothing. Does this mean all free software advocates are stuck on archaic pre 2010 hardware?

Pre-2010 hardware is not archaic. I would argue that there was very little progress since 2010.

really? Which laptops from 2010 have 13-15 hours of battery life?

Which consumer/workstation computer from 2010 feature 32-64 cores?

How much RAM could you put into such machines? etc.

Post reply on HN