No amount of EFI rootkit detection will ever remove the possibility that malicious code is running inside the Intel Management Engine (ME), because code inside the ME would run side-by-side with the bootloader and with unlimited permissions. Unless Intel provides source code for the ME, it is impossible to 100% know whether unauthorized code is running.
Someone at https://puri.sm almost completely removed the ME. https://puri.sm/posts/neutralizing-intel-management-engine-o...
After CIA leak, Intel Security releases detection tool for EFI rootkits
21–30 of 61 posts
Re: After CIA leak, Intel Security releases detection tool for EFI rootkits
#22No amount of EFI rootkit detection will ever remove the possibility that malicious code is running inside the Intel Management Engine (ME), because code inside the ME would run side-by-side with the bootloader and with unlimited permissions. Unless Intel provides source code for the ME, it is impossible to 100% know whether unauthorized code is running.
Someone at https://puri.sm almost completely removed the ME. https://puri.sm/posts/neutralizing-intel-management-engine-o...
Re: After CIA leak, Intel Security releases detection tool for EFI rootkits
#23Earlier quoted context omitted.
Even if Intel gave you the source code, you still wouldn't know if there was any unauthorised code running.
Reproducible builds is a very important part of knowing you are secure, and in the absence of that at least being able to flash on your own compilation.
Re: After CIA leak, Intel Security releases detection tool for EFI rootkits
#24Earlier quoted context omitted.
Someone at https://puri.sm almost completely removed the ME. https://puri.sm/posts/neutralizing-intel-management-engine-o...
What's with the free advertising? They were not the ones to do the original work with coreboot or removing the non important parts of the ME. If anything, Purism has lied, taken credit for other peoples work and given people a false sense of "privacy" and "security". "Almost completely removed the ME" is not good enough and there is way too much room to do malicious things.
Re: After CIA leak, Intel Security releases detection tool for EFI rootkits
#25Re: After CIA leak, Intel Security releases detection tool for EFI rootkits
#26Earlier quoted context omitted.
Someone at https://puri.sm almost completely removed the ME. https://puri.sm/posts/neutralizing-intel-management-engine-o...
.
Re: After CIA leak, Intel Security releases detection tool for EFI rootkits
#27Earlier quoted context omitted.
You can reverse engineer the EFI modules, build a whitelist based on known safe code, and then detect subversion at Intel, so this is not a good strategy for serious adversaries.
In theory, sure. Is it sufficiently simple that people will do it in practice? (I don't know, I expect you would know) Wouldn't the malicious alterations introduced in a scenario like that most likely be exploitable defects that could be explained away as mistakes? If they accumulate too much around certain people that's suspicious of course, but it seems like it would often be difficult to downright prove that someo…
This is a banal point, except: if the threat is that Intel (or some other huge vendor) backdoors their EFI binaries, it will get out that they did so. It's not "the perfect crime"; it's practically the opposite of that: one guaranteed to be detected, and that will exact maximal damage on the perpetrators when it gets out.
Re: After CIA leak, Intel Security releases detection tool for EFI rootkits
#28And what if intel is compromised? Mass rootkit installation!
Of all the attacks a nation state could do, surely finding a few talented people to get PhDs in the appropriate fields and go to work at Intel and collect a paycheck along with a nice stipend from the nation state is likely among the easiest.
Re: After CIA leak, Intel Security releases detection tool for EFI rootkits
#29Nice try CIA and Intel, but I'm not falling for this.
https://www.theguardian.com/world/2013/jul/11/russia-reverts...
The entire computing ecosystem appears to be P0wned by various intelligence services. And, its not unique to the CIA or NSA. The Chinese are assumed to have backdoors into most of what ships from their country.
Re: After CIA leak, Intel Security releases detection tool for EFI rootkits
#30Nice try CIA and Intel, but I'm not falling for this.
It's pretty bloody sad state that we're in that your comment cannot be dismissed as some tin-foil-hat-lunatic, but very reasonable skepticism nowadays.