Live data from Hacker News

Disabling Intel ME 11 via undocumented mode

blog.ptsecurity.com

181–190 of 228 posts

Re: Disabling Intel ME 11 via undocumented mode

#181
ACPI is almost as horrible: complicated, opaque, untrusted code running on a VM instead of using declarative data tables.

Closed-source firmware and silicon must end, because it's impossible to authoritatively verify correctness or rule out malware implants inserted at some point along the way.

Re: Disabling Intel ME 11 via undocumented mode

#182

Earlier quoted context omitted.

If some other CPU architecture were the dominant PC platform, do you think it wouldn't grow such features too? It's not hard to imagine an alternate universe in which we all have RISC workstations with the equivalent of ME, and Intel/AMD are the minorities who have more "open" CPUs without, but only because they hadn't grown enough. The underlying reason why ME became popular is the same reason why proprietary walled…

> The underlying reason why ME became popular ... ... is also because it provides management features that are wanted by enterprise customers. If you're running hundreds of servers in a data center, the more management you can do remotely, without visiting the machine room and preferably automated as much as possible, the better. This is quite irrelevant and even undesirable for an individual's personal computer.

I read statements like this often on HN, but not once during my years of work as a sysadmin in enterprise IT in different countries did I meet anyone who used ME/AMT for employee laptops. Also not at conferences.

Admins use the ILOM/IPMI for servers, so you don't really need it for server CPUs. For laptops all management happens at the operating system level, not below it.

Re: Disabling Intel ME 11 via undocumented mode

#183
post #174
post #172

What happened to 3rd party chipsets? Seems like VIA, ALi, SiS, Nvidia nForce, all stopped making them for Intel processors around 2008. If there were alternative chipsets still around, we would see more motherboard makers adopting something like openBMC with an alternative chipset and using it. No Intel PCH, no Intel ME.

If there were alternative chipsets still around, we would see more motherboard makers adopting something like openBMC with an alternative chipset and using it. No we wouldn't. All the chipsets would be subject to the same market forces and thus would converge on similar features, including the ME. Just like how 99% of x86 systems are running UEFI instead of coreboot.

This coreboot that is on every chromebook, and itself implements the UEFI standard? https://en.wikipedia.org/wiki/Coreboot#History

Big companies will do open consumer friendly products, once the ecosystem exists and there is some consumer awareness.

Re: Disabling Intel ME 11 via undocumented mode

#184
Can someone explain simply what this means for projects like libreboot and coreboot? I'm always interested with this stuff and it's implications, but don't have the background to understand a lot of low level details. Is the verdict still the same or are we gaining ground? Last time I checked, purism was quite optimistic about it, but the libreboot website seemed really pessimistic about it.

Re: Disabling Intel ME 11 via undocumented mode

#185

Earlier quoted context omitted.

Then let owners control whether it's enabled or not (by a hardware switch if necessary). As it currently stands, I can't imagine a benign reason that would drive intel and AMD to lock users out of their machines.

You can't think of any reason? Have you or do you work for a large company [1], especially hardware companies? I've sat through I don't know how many "planning" meetings, which were little better than design by committee, and whose outcome was not in the best interest of the customer despite the best intentions of everyone there. 1. Or the government or one of it's contractors. I've even sat through meetings 12 engin…

Explain to me why I can't disable it for my home PC.

Re: Disabling Intel ME 11 via undocumented mode

#186
post #171

Earlier quoted context omitted.

Wouldn't it just take a motherboard maker or two to find an alternative to the PCH, like Nvidia nforce or a VIA chipset. adopt something like openbmc and sell it as an open feature? No intel PCH, no Intel ME. Seems like the Linux kernel is eager to support it: https://lwn.net/Articles/683320/ What happened to 3rd parties making chipsets? Another case of Intel abusing it's monopoly?

I'd love it. But it probably would increase the manufacturer's costs for the motherboard (including engineering, component costs, etc.), distract the organization (managers, engineers, purchasing personnel, etc. spending time on this novel tech instead of just buying Intel/AMD chipsets), reduce quality (can they really compete with Intel's engineering resources?), which increases support costs, etc. ... all for a mar…

The consumer market might be small, but the enterprise market would be what it is. I can't imagine openbmc being more expensive than a builtin wifi card with an external antenna connector for basic features. Features like RDP would be more off course. I imagine they could take a similar embedded processor and slap openbmc on it and market it as open just fine. The fact is, no alternatives to Intel PCH exist, so doing this isn't even an option. If Nvidia nForce or a VIA chipset existed for the newest Xeon with similar capabilities as the PCH minus the Intel ME, would you really doubt that there wouldn't be some motherboard maker that would go this route?

VIA used to make dual socket server class chipsets, for the pentium 3, which ever age was in.

Re: Disabling Intel ME 11 via undocumented mode

#187

ACPI is almost as horrible: complicated, opaque, untrusted code running on a VM instead of using declarative data tables. Closed-source firmware and silicon must end, because it's impossible to authoritatively verify correctness or rule out malware implants inserted at some point along the way.

Well said. It also makes computing much more expensive and slow to progress. But those fraudsters love their violence-backed monopoly. Image if a few vital manufacturing plants were destroyed, we would have silicone shortages. We have made ourselves fragile, backwards and weak.

Re: Disabling Intel ME 11 via undocumented mode

#188

Imagine if some non-US government voided Intel and AMD's patents as a self-defence measure against these probably-backdoored 'features'. Why should they protect the profits of hostile corporations?

Voiding patents probably doesn't change anything because patents usually contain just vague description.

You underestimate how much patents are used to impede competition - see https://arstechnica.com/information-technology/2017/06/intel... , and the many less public patent licenses and threats.

Re: Disabling Intel ME 11 via undocumented mode

#189

Earlier quoted context omitted.

You can't think of any reason? Have you or do you work for a large company [1], especially hardware companies? I've sat through I don't know how many "planning" meetings, which were little better than design by committee, and whose outcome was not in the best interest of the customer despite the best intentions of everyone there. 1. Or the government or one of it's contractors. I've even sat through meetings 12 engin…

Explain to me why I can't disable it for my home PC.

Nobody (aside from the US Government, obviously) really cares enough to buy hardware without a management engine, so why put the effort into writing and testing a configuration that a tiny segment of the population will use? (Also, Intel AMT contains some functionality that is actually used by the OS in everyday use, and turning it off would break that.)

Re: Disabling Intel ME 11 via undocumented mode

#190
post #90

Earlier quoted context omitted.

Likely to do with the EURion constellation: https://en.wikipedia.org/wiki/EURion_constellation Another item of interest may be printer stenography, in which every piece of printed paper, seemingly from every printer, can be traced back to make, model and potentially even the unit used to print it: https://en.wikipedia.org/wiki/Printer_steganography

I'm one of the most paranoid people you're ever likely to meet. (People more paranoid than I am won't communicate online.) Printer stenography is just beyond the limit I set for myself to try to disbelieve, and yet, here it is. (Meaning that I always assumed something like this was going on, because that's what I would do , but I try to disbelieve it so as to be able to act normal. I believe all phones are continuall…

I wrote off freedom and privacy 2 years ago simply because it was having adverse effects on my mental health. I wasn't changing anything by being paranoid so I just stopped being paranoid.

I still don't use facebook and I run free/open-source software exclusively, but worrying about it didn't change anything.

Post reply on HN