Live data from Hacker News

The Intel ME subsystem can take over your machine, can't be audited

boingboing.net

151–160 of 282 posts

Re: The Intel ME subsystem can take over your machine, can't be audited

#151

Can someone tell me if people have actually spotted the Intel ME doing unauthorized communication? I imagine it should be easy to spot in any network firewall log (note I said network, not OS), and in reality, if it's never been observed to communicate with the outside world without explicitly being told to then do people really need to worry?

People should always worry about attack surface area

OK, but that doesn't answer my first question.

Re: The Intel ME subsystem can take over your machine, can't be audited

#152

I'm very surprised that no-one on HN has talked about their experiences of using AMT for enterprise IT management. Aside from the security problems, I've personally never encountered or seen it's use, which makes the ME's inclusion (on all chips, for about 6 years) seem like an odd decision from Intel.

My previous employer used it, and it was pretty useful. When we got a new PC, we'd enroll our local keys by booting with a USB drive with the keyfile in the root of the filesystem. The firmware would offer to enroll the keys, after which (remote) sysadmins could remotely administer the machine through AMT -- basically a remote KVM.

The firmware has an on-screen indication that's happening, so it couldn't be used for spying. Plus for most day-to-day purposes, we could use AD to administer the machines (which probably could be used for spying, if that were necessary). But when things broke enough that AD stopped working (or when first setting up a box), much of the time AMT meant that we didn't need a physical presence to fix them again.

Re: The Intel ME subsystem can take over your machine, can't be audited

#153
post #149

And this is why monopoly of one giant monolith is bad, in any area or case! They get to the whatever the f they want! It's not like everything is made today to track, and give access to "authorities" when they want it. But what really drives me mad is that I feel tricked! You put trust into someone and it's work, and give them money for that, but they do this, without you even knowing. I was always making fun of swor…

I think AMD and ARM have similar features though. ARM with TrustZone for example, hiding the "secure world" from knowledge by the "normal world".

Yeah I thought so, but I hoped competition would make things different, where one of leaders would go like full transparent, without these "spy" sectors, and it would give it edge over others.

And it's not about securing, it's about control! Who owns the thing I bought, that I use. It's not only they can watch, but now they can control whole computer. That's what bugs me the most. :(

Re: The Intel ME subsystem can take over your machine, can't be audited

#154
post #149

And this is why monopoly of one giant monolith is bad, in any area or case! They get to the whatever the f they want! It's not like everything is made today to track, and give access to "authorities" when they want it. But what really drives me mad is that I feel tricked! You put trust into someone and it's work, and give them money for that, but they do this, without you even knowing. I was always making fun of swor…

I think AMD and ARM have similar features though. ARM with TrustZone for example, hiding the "secure world" from knowledge by the "normal world".

Trustzone in itself is not closed though, and FAFAIK is not a separate engine. Trustzone is more like IOMMU on steroids, and runs on the main processor (it relies on hardware support to fence off system resources).

Re: The Intel ME subsystem can take over your machine, can't be audited

#155

Does this apply to Macs?

As others point out, it's an Intel thing, so any Mac running an Intel chip, but I wonder if this is more of an industry thing. Has Apple put something similar in their A-series mobile chips?

Re: The Intel ME subsystem can take over your machine, can't be audited

#156

I'm very surprised that no-one on HN has talked about their experiences of using AMT for enterprise IT management. Aside from the security problems, I've personally never encountered or seen it's use, which makes the ME's inclusion (on all chips, for about 6 years) seem like an odd decision from Intel.

[deleted]

Re: The Intel ME subsystem can take over your machine, can't be audited

#157

I'm very surprised that no-one on HN has talked about their experiences of using AMT for enterprise IT management. Aside from the security problems, I've personally never encountered or seen it's use, which makes the ME's inclusion (on all chips, for about 6 years) seem like an odd decision from Intel.

> I've personally never encountered or seen it's use, which makes the ME's inclusion (on all chips, for about 6 years) seem like an odd decision from Intel. I consider it as quite plausible that the reason why Intel included ME into all chips is that it is much cheaper to add those unnecessary gates to any chip than to create two different versions of it. The much more interesting question is why ME cannot be disable…

> it is clear why Intel has a reason why ME should not be possible to disable on some chips.

Only "under some conditions" should not be possible, that is, once you as a user turn on the anti-theft protection. Theoretically, turn-on-once, afterwards-no-turn-off technology can be implemented.

Re: The Intel ME subsystem can take over your machine, can't be audited

#158
post #39

The real question is what the firmware can be convinced to do remotely. Probably most of the things in here.[1] Remote management is supposed to be listening on TCP ports TCP 623 for HTTP and 664 for HTTPS. [1] http://www.dmtf.org/sites/default/files/standards/documents/...

Are you suggesting that detecting if your system is exposed to remote control is as easy as checking to see if your machine appears to have such ports open? And would the ports appear to be open if checked from the same machine?

Re: The Intel ME subsystem can take over your machine, can't be audited

#159

Does this apply to Macs?

More precise question is: Is Intel CPU connected with 3G laptop modem on Mac? If YES: Data can be read/written remotely from/on your Mac (even if turned OFF - as long batteries are installed). If NO: Most probably it can not be done! (Source: http://www.intel.com/content/dam/doc/product-brief/mobile-co...)

Re: The Intel ME subsystem can take over your machine, can't be audited

#160
post #154
post #149

Earlier quoted context omitted.

I think AMD and ARM have similar features though. ARM with TrustZone for example, hiding the "secure world" from knowledge by the "normal world".

Trustzone in itself is not closed though, and FAFAIK is not a separate engine. Trustzone is more like IOMMU on steroids, and runs on the main processor (it relies on hardware support to fence off system resources).

And i think the variant found on Qualcomm SOCs were recently cracked open.
Post reply on HN