Live data from Hacker News

“We have obtained fully functional JTAG for Intel CSME via USB DCI”

twitter.com

161–170 of 413 posts

Re: “We have obtained fully functional JTAG for Intel CSME via USB DCI”

#161

I worked on what became ME at Intel from the mid 2000s through around 2012 ou 2013. I completely agree that in retrospect, it wasn't the best idea. However, I really want to say that it was never a project for the CIA as some keep saying. This was a widely-marketed product at the time of its inception. It was the whole point of the Intel vPro line. I've been to a ton of roadshows between 2008 and 2009 where the marke…

Three questions if you don't mind (and feel free to speculate yourself or anyone else):

1. Many features have options to be disabled (e.g. bios settings). Why doesn't this, even to this day?

2. You may have been involved in implementation, but do you know why it still exists on every board regardless of backlash?

3. I am a bit ignorant, does the chip fabbing process justify putting this on every board instead of just on enterprise ones (especially since you can consider it a feature worth upcharging for)?

Pardon my skepticism, but its continued use without the ability to disable speaks to ulterior motives regardless of original implementation design.

Re: “We have obtained fully functional JTAG for Intel CSME via USB DCI”

#162
post #118

Earlier quoted context omitted.

From a technical perspective there is a difference now that this is public, but from a security stance, physical access is physical access. Why? Security knows there are always bugs in software, and assumes they exist. Thanks to @h0t_max, the rest of us know this particular bug exists, but this bug has been around for a while - who's to say evil hax0rs didn't find this bug years ago and have been exploiting it since?…

> while there are mitigations for the evil maid attack (like an encrypted drive and shutting down -not just suspending, when the machine is out of sight), That mitigation is useless against Evil Maid. There are much more sophisticated mitigations (using a TPM to measure the boot, and then do something akin to TOTP in order to allow the user to actually verify the state of the machine) which actually could protect aga…

The TPM is actually implemented as an Intel ME applet on a lot of PCs... >.<

Re: “We have obtained fully functional JTAG for Intel CSME via USB DCI”

#163
post #83

Earlier quoted context omitted.

In the past discussions of the ME here and elsewhere, there have always been people making self-assured poo-pooing noises about what a trivial nonissue it is, make deceptive claims about exposure, and then dumb claims about how you can't trust any hardware. They never reply to particular questions that might point out how deceptive the arguments are.

I'm one of the people that claims you can't trust hardware. Care to elaborate why that's not the case. How does one trust a chip with 14nm transistors? Are you claiming that one can 'simply' decap the chip and examine it with a microscope on a Saturday night? How do I then trust that the chip I have in hand is of the same architecture as the one you decapped and examined?

You're only responding to the part after "dumb claims," right?

And your (valid) refutation of that part in no way implies spending less time reverse engineering and disabling ME, nor being less excited about this tweet. Correct?

Re: “We have obtained fully functional JTAG for Intel CSME via USB DCI”

#164
post #12

Earlier quoted context omitted.

Intel CPUs have an embedded supervisory CPU called the Management Engine. It can read all of memory, control power states on the main CPU, and generally has super-root privileges on everything. You, an end-user, aren't allowed to program it. The current MEs run a form of Minix. They represent an incredible security and privacy risk, because we don't know what code they run and it is widely believed that the NSA or ot…

To add, and maybe the others can correct me if I'm wrong: Intel ME can be controlled remotely if you have an Intel lan card, even if the main cpu is off, but the motherboard is powered on. It goes from there and gets worse is my understanding.

Yup, that's AMT, enabled on vPro-series and Xeon chips only though

Re: “We have obtained fully functional JTAG for Intel CSME via USB DCI”

#165
post #85

Can someone ELI5 this for me?

Intel created a product (Similar to Dell's iDRAC) which has a co-processor for system admin type stuff. This product and/or associated modules have security flaws. Those flaws can be potentially used to takeover the machine and allow malware to exist outside of the CPU/RAM/HDD architecture and stay undetected.

Re: “We have obtained fully functional JTAG for Intel CSME via USB DCI”

#166

In principle, how is the Intel Management Engine different from the Apple Secure Enclave coprocessor on iOS devices?

ME can see everything coming in on your ethernet port, with no accountability to the host OS. It's like a wiretap, ostensibly for remote control commands, but again with no accountability for what it is up to.

Re: “We have obtained fully functional JTAG for Intel CSME via USB DCI”

#167
post #91

Earlier quoted context omitted.

Seriously? A 4chan post? While the ME is worrying for many reasons, there's absolutely zero evidence that the Intel ME contains a backdoor. Backdoors don't stay hidden forever.

That's a bad argument. Firstly, it's my understanding that there have already been root-access 0 days discovered in the ME (and since patched since exposed). AND The USB jtag backdoor is the whole point of this post. Secondly, a security hole and a backdoor are interchangeable these days. So we'll never be able to prove which new 0-days are deliberate, and as far as impact it kinda doesn't matter if they're deliberat…

We're talking about deliberate government backdoors, and it's my opinion that those are highly unlikely.

The ME is a really bad idea because it introduces massive, unnecessary attack surface and vulnerabilities are inevitable, but no conspiracy.

Re: “We have obtained fully functional JTAG for Intel CSME via USB DCI”

#168

Earlier quoted context omitted.

> Intel ME and the (assumed [0]) partnership with CIA to design and build this system I worked at Intel on ME and the things that came before it until around 2013. I can tell you two things -- 1. No, Intel ME wasn't born out of a desire to spy on people nor was it -- to the best of my knowledge but I honestly believe I would know -- created at the request of the US government (or others). It was an honest attempt at…

Right. ME does make sense as a feature for sysadmins. Except . . . . Well, can you shed light on the following: 1. Why did your team deem it necessary to deny the end-user the capability to disable this feature? 2. Why did your team decide to enable ME on ALL consumer grade chips? You could have only enabled it on, say, Xeon, as a value-add - exactly like you do for ECC support. You could have made more money this wa…

Having been a sys-admin once upon a time (2006-2008), these answers are straight forward. Servers used to have discrete ME cards which were paid add-ons. Competition in the early 2000s drove these ME cards to be integrated in the motherboard in order to better compete on the low end of the market. I’ve had servers I was only able to remotely fix due to the out of band management interface (more than once). They pain they fix is real.

The same techniques for managing server farms are useful for managing hundreds/thousands of corporate desktops. Being able to power up a desktop (“lights out” management) and re-image it at 3:00AM is very useful for example. You could also install 3rd party security products to the ME to provide higher level threat detection that’s hard for a rootkit to hide from. So once the work of getting an integrated management engine production ready was complete, it made perfect sense to use it in corporate desktops. It’s expensive to produce chip variants, so doubtless that further cost pressures on Intel lead to them putting the ME their core shared across all products. Plus, now IT admins can let the VP of Sales get the laptop she wants knowing they can leverage their System Center/OpenDesk/etc. console to manage it via ME.

So no, they aren’t a Fed backdoor. Those of us who worked in IT 10 years ago remember how the market drove Intel to add the ME. That is doubtless why many are silently conflicted. They don’t want to take a big step back. They likely are expecting/hoping Intel will “fix” the problem.

Re: “We have obtained fully functional JTAG for Intel CSME via USB DCI”

#169
post #29

Earlier quoted context omitted.

I don't want to get too deep into imagination, but the details of the ME/PSP story make it seem like an outside force of some sort is compelling them to add this stuff to their platforms.

It's indeed nice to imagine that the people behind Intel are relieved that somebody finally found the kill-switch they left behind in the monster they had to create. And the AMD people now thinking hard how they can leak hints to their kill-switch in an inconspicuous way, too. But that's indeed imagination. Unforunately, we don't (yet) know much about their motivations.

ME is used for market segmentation too, from locking hyperthreading to overclocking capablities. (they used to sell product update keys for some Pentium CPUs that were processed by an applet on the ME...)

Re: “We have obtained fully functional JTAG for Intel CSME via USB DCI”

#170
post #120

Earlier quoted context omitted.

> And yet we really don’t seem to care much. I know we're used to "Internet speed" and the tweet happened an entire 24 hours ago, but give it a bit of time before declaring it dead. Wired and Vice need a second to write it up, and see if it hits the mainstream before declaring the issue ignored. Not saying it will get picked up, though I sure hope it does, but as you point out, it's a bit obscure and takes some expla…

Plenty of people were still saying the Snowden revelations were old hat when they came out, we all knew it was happening just didn't have proof, etc. The novelty and seriousness tends to be out-of-whack with the amount of news coverage. It's a poor way to measure the importance of existing news coverage or lack of it for that reason. What matters is that it gets out and incentivizes developers, manufacturers, company…

Prior to the NSA contractor Edward Snowden's revelations in 2013, Room-641A had already been exposed by an AT&T employee-turned-whistleblower Mark Klein. The EFF sued the government in 2006 over it.

Tape over laptop cameras isn't just a "parents-of-friends" thing, it's a good idea. Buy a set of stickers and support the EFF: https://supporters.eff.org/shop/laptop-camera-cover-set

Anyone know somebody at Wired?

Post reply on HN