https://www.intel.com/content/www/us/en/support/articles/000...
“We have obtained fully functional JTAG for Intel CSME via USB DCI”
191–200 of 413 posts
Re: “We have obtained fully functional JTAG for Intel CSME via USB DCI”
#192Earlier quoted context omitted.
Why would they do something as ridiculous as telling you its true purpose?
They wouldn't. As I said, this is to the best of my knowledge. However, I believe I would know because it's not like one day the CEO came to us with a folder filled with requirements to be implemented. This is something that started very small ("find a way to force reboot a PC remotely if it's non-responsive") and evolved from there over months/years. I endured way too many meetings were design decisions were made. U…
Also, I think people here severely underestimate the red tape and huge efforts needed to implement something mildly complex, Intel scale. Developing ME under wraps with full CIA-like functionality is staggeringly difficult - I've seen the effort needed getting the BIOS to work on the prototype boards without crashing or destroying the HW; pulling ME to work reliably on all boards would be one order of magnitude harder; making it spy CIA-style - add two more orders of magnitude. I think people don't really understand how difficult is to get something that close to the metal work reliably; able to poke inside the memory of a running OS - forget about it.
Also, I think the readers of HN severely overestimate the effort CIA needs to spy on the internet users - why even try to bug the firmware when people actively share their privacy via apps that they themselves install???
Re: “We have obtained fully functional JTAG for Intel CSME via USB DCI”
#193Earlier quoted context omitted.
Right. ME does make sense as a feature for sysadmins. Except . . . . Well, can you shed light on the following: 1. Why did your team deem it necessary to deny the end-user the capability to disable this feature? 2. Why did your team decide to enable ME on ALL consumer grade chips? You could have only enabled it on, say, Xeon, as a value-add - exactly like you do for ECC support. You could have made more money this wa…
> Why did your team decide to enable ME on ALL consumer grade chips? Can you please provide a reference? I've been trying to enable ME forever for my consumer-grade i7 with Intel motherboard for remote management, and I can't seem to be able to.
Re: “We have obtained fully functional JTAG for Intel CSME via USB DCI”
#194Re: “We have obtained fully functional JTAG for Intel CSME via USB DCI”
#195Earlier quoted context omitted.
I'm going to assume "relatively high level languages" are for example Python, Ruby, C#, Javascript... Imagine that you have your high level program. When you execute it, it goes through a just-in-time compilation (whether that's script parsing or bytecode conversion, or actual compilation, or whatever) before reaching the CPU which actually executes your code. Now imagine that your interpreter has the capability of r…
> It allows a remote party to inject their own flow of execution into your program. Thanks for your helpful explanation. This bit sounds particularly bad - is the really possible in practice or just theoretical? Is there any source that has shown this?
* it's definitely possible for Intel (and anyone Intel gives access to) * it's theoretically possible for anyone with a zero-day hack (or now physical access)
Re: “We have obtained fully functional JTAG for Intel CSME via USB DCI”
#196Earlier quoted context omitted.
They wouldn't. As I said, this is to the best of my knowledge. However, I believe I would know because it's not like one day the CEO came to us with a folder filled with requirements to be implemented. This is something that started very small ("find a way to force reboot a PC remotely if it's non-responsive") and evolved from there over months/years. I endured way too many meetings were design decisions were made. U…
Having worked for Intel (in the open source org) I trust you. I've seen first hand how a cool, small, simple feature is blossoming into something dr. Frankenstein would be proud of. Also, I think people here severely underestimate the red tape and huge efforts needed to implement something mildly complex, Intel scale. Developing ME under wraps with full CIA-like functionality is staggeringly difficult - I've seen the…
Complete aside, but the whole story of Frankenstein is about how Dr. Frankenstein is repulsed by his actions the moment that he brings the monster to life. So he most certainly wasn't "proud" of his actions, he was horrified by them. But I agree that this is likely how some of the engineers who worked on Intel ME would feel too.
> why even try to bug the firmware when people actively share their privacy via apps that they themselves install???
We know (thanks to Snowden and WikiLeaks) that the NSA and CIA have programs like this, so it's actually more incredible that you don't believe that the CIA or NSA would invest resources in adding backdoors to things like Intel ME. I don't buy that they designed it, but given that we know they intentionally sabotage internet standards it's very likely they sabotaged it in some manner. Or at the very least they have security vulnerabilities they are not disclosing, so they can exploit them.
Re: “We have obtained fully functional JTAG for Intel CSME via USB DCI”
#197Earlier quoted context omitted.
I don't want to get too deep into imagination, but the details of the ME/PSP story make it seem like an outside force of some sort is compelling them to add this stuff to their platforms.
The invisible hand of the market is sufficient to explain it, no nefarious conspiracy necessary. For servers far away in a data-center, there needs to be some sort of "oh shit" access for when the OS dies, and this is implemented in high-end servers as separate second computer inside the server with its own ethernet port (ILOM), however the extra hardware costs more to manufacture. Intel decided it wanted a piece of…
There are some obvious reasons why it's not completely open, notably that ME enables feature unlocking keys and DRM at a lower cost than more hardware-involved approaches; but I don't think that explains the recent PR attempts and complete dodging of this issue.
Re: “We have obtained fully functional JTAG for Intel CSME via USB DCI”
#198Earlier quoted context omitted.
Is this enough to block this attack? That is, is a "cleaned" system vulnerable to a USB device?
DMA/Firewire over USB makes pretty much every systen vulnerable to USB attacks (ME aside.)
Re: “We have obtained fully functional JTAG for Intel CSME via USB DCI”
#199Earlier quoted context omitted.
From a technical perspective there is a difference now that this is public, but from a security stance, physical access is physical access. Why? Security knows there are always bugs in software, and assumes they exist. Thanks to @h0t_max, the rest of us know this particular bug exists, but this bug has been around for a while - who's to say evil hax0rs didn't find this bug years ago and have been exploiting it since?…
> while there are mitigations for the evil maid attack (like an encrypted drive and shutting down -not just suspending, when the machine is out of sight), That mitigation is useless against Evil Maid. There are much more sophisticated mitigations (using a TPM to measure the boot, and then do something akin to TOTP in order to allow the user to actually verify the state of the machine) which actually could protect aga…
Encrypted drive + shutdown is a defense against a specific Evil Maid attack, cold boot attacks. It is not a very expensive attack to run; for the cost of a can of compressed air, and a USB drive, anybody sophisticated can run this attack. https://en.wikipedia.org/wiki/Cold_boot_attack
Sorry to sound defeatist, but if you had been relying on IOMMU to save you, the trivial "plug anything into a USB port and you have CPU JTAG access" attack has always been possible. (Never mind that IOMMU implementations aren't guaranteed to be bug free.)
In the face of that, what do you do?
With this knowledge, all I really can do is stay up to date and patch-patch-patch. Have a travel Chromebook for leaving in hotel rooms, but ultimately I just have to know that it's not enough, especially against a CIA-grade Evil Maid, or an Evil Maid that's able to factor 4096-bit prime numbers. (That last one's not theoretical, either. It was revealed a few weeks ago that TPMs in Chromebooks and other hardware was generating weak keys, leading to cloud-factorable 4096-bit RSA keys.)
A less-sophisticated Evil Maid can still physically steal my laptop for pawning, and even if they can't get my data, I've still had my laptop stolen. Not-being-defeatist, I backup my data, although that has a totally different set of security concerns over the Internet.
Re: “We have obtained fully functional JTAG for Intel CSME via USB DCI”
#200Earlier quoted context omitted.
We should start demanding physical shutters for laptop webcams. Does anyone make those yet?
Even better is a hardware kill switch, especially for the mic.
Of course a switch would be nice, similar to the older Thinkpads which had a hardware switch for the network devices on the front, originally for use on airplanes.