Live data from Hacker News

After CIA leak, Intel Security releases detection tool for EFI rootkits

pcworld.com

21–30 of 61 posts

Re: After CIA leak, Intel Security releases detection tool for EFI rootkits

#21
post #8
post #6

No amount of EFI rootkit detection will ever remove the possibility that malicious code is running inside the Intel Management Engine (ME), because code inside the ME would run side-by-side with the bootloader and with unlimited permissions. Unless Intel provides source code for the ME, it is impossible to 100% know whether unauthorized code is running.

Someone at https://puri.sm almost completely removed the ME. https://puri.sm/posts/neutralizing-intel-management-engine-o...

What's with the free advertising? They were not the ones to do the original work with coreboot or removing the non important parts of the ME. If anything, Purism has lied, taken credit for other peoples work and given people a false sense of "privacy" and "security". "Almost completely removed the ME" is not good enough and there is way too much room to do malicious things.

Re: After CIA leak, Intel Security releases detection tool for EFI rootkits

#22
post #8
post #6

No amount of EFI rootkit detection will ever remove the possibility that malicious code is running inside the Intel Management Engine (ME), because code inside the ME would run side-by-side with the bootloader and with unlimited permissions. Unless Intel provides source code for the ME, it is impossible to 100% know whether unauthorized code is running.

Someone at https://puri.sm almost completely removed the ME. https://puri.sm/posts/neutralizing-intel-management-engine-o...

.

Re: After CIA leak, Intel Security releases detection tool for EFI rootkits

#23
post #12

Earlier quoted context omitted.

Even if Intel gave you the source code, you still wouldn't know if there was any unauthorised code running.

Reproducible builds is a very important part of knowing you are secure, and in the absence of that at least being able to flash on your own compilation.

Well even with reproducible builds how do you check what actually is running there? That'd be the ME reporting "I'm running version X" without a way to really verify it. Also if you flashed it you cannot be 100% sure there is no other component that is still running a rootkit.

Re: After CIA leak, Intel Security releases detection tool for EFI rootkits

#24
post #8

Earlier quoted context omitted.

Someone at https://puri.sm almost completely removed the ME. https://puri.sm/posts/neutralizing-intel-management-engine-o...

What's with the free advertising? They were not the ones to do the original work with coreboot or removing the non important parts of the ME. If anything, Purism has lied, taken credit for other peoples work and given people a false sense of "privacy" and "security". "Almost completely removed the ME" is not good enough and there is way too much room to do malicious things.

[deleted]

Re: After CIA leak, Intel Security releases detection tool for EFI rootkits

#26
post #22
post #8

Earlier quoted context omitted.

Someone at https://puri.sm almost completely removed the ME. https://puri.sm/posts/neutralizing-intel-management-engine-o...

.

What's your point? Is it that exploit developers are not compensated financially for their work? Exploit developers should find a better business model than their current one. This guy was able to take freely available exploit knowledge and monetize it. If the parties responsible for creating the exploit feel they have some sort of IP claim against them, they should sue. If exploit developers wish to release exploit details for free then the best they can wish for is charity.

Re: After CIA leak, Intel Security releases detection tool for EFI rootkits

#27
post #20
post #5

Earlier quoted context omitted.

You can reverse engineer the EFI modules, build a whitelist based on known safe code, and then detect subversion at Intel, so this is not a good strategy for serious adversaries.

In theory, sure. Is it sufficiently simple that people will do it in practice? (I don't know, I expect you would know) Wouldn't the malicious alterations introduced in a scenario like that most likely be exploitable defects that could be explained away as mistakes? If they accumulate too much around certain people that's suspicious of course, but it seems like it would often be difficult to downright prove that someo…

The point is that it doesn't matter what the typical person will do. All that matters is that somebody, somewhere reverse engineers the EFI binaries, and that it's easy enough for normal people to run a program to check their current EFI against a whitelist of known good EFI binaries.

This is a banal point, except: if the threat is that Intel (or some other huge vendor) backdoors their EFI binaries, it will get out that they did so. It's not "the perfect crime"; it's practically the opposite of that: one guaranteed to be detected, and that will exact maximal damage on the perpetrators when it gets out.

Re: After CIA leak, Intel Security releases detection tool for EFI rootkits

#28
post #7
post #2

And what if intel is compromised? Mass rootkit installation!

Of all the attacks a nation state could do, surely finding a few talented people to get PhDs in the appropriate fields and go to work at Intel and collect a paycheck along with a nice stipend from the nation state is likely among the easiest.

Isn't it unlikely that an individual engineer (or even a handful) could effect a design level compromise on such a massive project as building a processor? Not only because of the managerial oversight they'd have to circumvent, but because of the overall system complexity. As sibs have pointed it, it would seem much more practical to just compromise Intel at a corporate/managerial level.

Re: After CIA leak, Intel Security releases detection tool for EFI rootkits

#29

Nice try CIA and Intel, but I'm not falling for this.

and.... what alternative could you possibly have? There's a reason the Russians reportedly moved to typewriters.

https://www.theguardian.com/world/2013/jul/11/russia-reverts...

The entire computing ecosystem appears to be P0wned by various intelligence services. And, its not unique to the CIA or NSA. The Chinese are assumed to have backdoors into most of what ships from their country.

Re: After CIA leak, Intel Security releases detection tool for EFI rootkits

#30

Nice try CIA and Intel, but I'm not falling for this.

LOL!

It's pretty bloody sad state that we're in that your comment cannot be dismissed as some tin-foil-hat-lunatic, but very reasonable skepticism nowadays.

Post reply on HN