Since Intel/AMD also designs the processor they can also put in backdoors beyond ME, microcode updates, etc. If you don’t trust proprietary blobs, I respect that. But you can’t trust proprietary silicon either.
https://en.wikipedia.org/wiki/Defence_in_depth
Why is the latest Intel hardware unsupported in libreboot? (2017)
121–130 of 132 posts
Re: Why is the latest Intel hardware unsupported in libreboot? (2017)
#122Earlier quoted context omitted.
Feel free to call it a conspiracy theory, but I firmly believe the IME/PSP is an operation by one of those three letters. Intel Management Engine is abbreviated as IME, and AMD Platform Security Processor is abbreviated as PSP. Those are each same abbreviation as Input Method Editor, a mandatory keyboard input layer for East Asian languages, and PlayStation Portable, Sony’s game console which cryptographic security i…
Show me any three-letter acronym that doesn't have multiple meanings already attached to it.
Re: Why is the latest Intel hardware unsupported in libreboot? (2017)
#123This is why I have an Apple Powermac G5 or two stored in my basement. These run entirely free of that backdoor.
Can you build a modern browser to run on PPC? Say, latest fully patched firefox? Because using the browser that comes with Ubuntu 16.04 is not an option, security wise.
http://www.floodgap.com/software/tenfourfox/
Otherwise for Linux on PowerPC, you can build a modern browser. There are also pre-built binaries:
https://forums.macrumors.com/threads/arctic-fox-web-browser-...
Re: Why is the latest Intel hardware unsupported in libreboot? (2017)
#124Are these side-channel based management technologies turns on even on MacBook laptops?
Re: Why is the latest Intel hardware unsupported in libreboot? (2017)
#125> Libreboot has support for fam15h AMD hardware (~2012 gen) and some older Intel platforms like Napa, Montevina, Eagle Lake, Lakeport (2004-2006). We also have support for some ARM chipsets (rk3288). On the Intel side, we’re also interested in some of the chipsets that use Atom CPUs (rebranded from older chipsets, mostly using ich7-based southbridges).
This is why I still run Intel hardware, even with the ME. A truly free computing platform seems to be incompatible with high performance modern chips at the moment.
Re: Why is the latest Intel hardware unsupported in libreboot? (2017)
#126Scrolling up they recommend avoiding Purism hardware because > In particular, the Intel Management Engine is a severe threat to privacy and security, not to mention freedom, since it is a remote backdoor that provides Intel remote access to a computer where it is present. However, the Intel ME has been disabled in Purism hardware since 2017. https://puri.sm/posts/purism-librem-laptops-completely-disab...
Pretty sure that write up was done around 2009
Re: Why is the latest Intel hardware unsupported in libreboot? (2017)
#127Earlier quoted context omitted.
> Could a user tell it's happening? What signals would indicate this? Is it increased CPU usage disguised as a system process? Intel AMT allows redirecting graphics output and keyboard/mouse/USB input over network connection. It's like a hardware device connected to HDMI port to capture screen and to USB ports to send inputs, but it's built right into the motherboard. It doesn't spawn a process in the operating syste…
Occasionally all these features would be quite useful if it was documented and accessible for mere mortals.
Re: Why is the latest Intel hardware unsupported in libreboot? (2017)
#128Earlier quoted context omitted.
No SSL => MITMer can definitely read your traffic trivially. Broken SSL => MITMer can possibly negotiate insecure and read your traffic anyway. MITMer can also possibly cause a denial-of-service, or get arbitrary code execution on that one chip that controls your entire CPU . If I had to choose, I would take the first option. (This precludes options like removing the IME entirely, or updating it to a version with non…
I'm coming from a place of good faith here so bear with me. My understanding is that any vulnerability here would also exist in accessing any HTTPS website. I'm assuming you wouldn't choose to browse the web without SSL/TLS, so I'm assuming the difference here is that it's the CPU management chip instead of your browser? I suppose that if you broke SSL/TLS you could commandeer arbitrary AWS/GCP/Azure instances. For t…
Re: Why is the latest Intel hardware unsupported in libreboot? (2017)
#129Earlier quoted context omitted.
Really? I am curious to know what observations or evidence you base your arguments/predictions on? Do you believe they have an (even better than 'post-Snowden leaks') search-engine like PRISM, but for private networks all around the world? Could a user tell it's happening? What signals would indicate this? Is it increased CPU usage disguised as a system process? And are you talking about mainstream proprietary OS'es…
> Could a user tell it's happening? What signals would indicate this? Is it increased CPU usage disguised as a system process? Intel AMT allows redirecting graphics output and keyboard/mouse/USB input over network connection. It's like a hardware device connected to HDMI port to capture screen and to USB ports to send inputs, but it's built right into the motherboard. It doesn't spawn a process in the operating syste…
Re: Why is the latest Intel hardware unsupported in libreboot? (2017)
#130This is really sad. I am sure hundreds of hours were spent on this project with now essentially does nothing. Does this mean all free software advocates are stuck on archaic pre 2010 hardware?
Pre-2010 hardware is not archaic. I would argue that there was very little progress since 2010.
Which consumer/workstation computer from 2010 feature 32-64 cores?
How much RAM could you put into such machines? etc.