Live data from Hacker News

Intel ME Manufacturing Mode: obscured dangers and MacBook vulnerability

blog.ptsecurity.com

21–30 of 85 posts

Re: Intel ME Manufacturing Mode: obscured dangers and MacBook vulnerability

#21
post #6

"The weakness of "security through obscurity" is so well known as to be obvious. Yet major hardware manufacturers, citing the need to protect intellectual property, often require a non-disclosure agreement (NDA) before allowing access to technical documentation. " I believe the actual reason for "security through obscurity" is that it's a delay tactic used against well-funded adversaries. There's an inherent problem…

The beauty of public key cryptography is that a x5 increase in security researchers is nowhere near a x2^128 increase in difficulty. What's pitiful is coming up with O(1) schemes and hoping for security through obscurity to keep them safe.

Re: Intel ME Manufacturing Mode: obscured dangers and MacBook vulnerability

#22
post #5

Earlier quoted context omitted.

Exactly. Remember Intel ME is a great utility and has some awesome abilities. The issue that people have is not the fact there is a CPU running another CPU that looks after the main one. It's that it's closed source and has remote control capabilities that can not be controlled by the user. If Intel would just allow an owner to build and flash their own Intel ME version using their own private/public keys then no one…

> It's the fact it's a secret closed system that has full control to monitor everything you do, and can not be fully disabled. To add to that, it also makes code audits impossible. Intel, AMD, ARM, et al: There is zero, and I mean ZERO reason to hide management functionality from users in this day and age. It's 2018, security through obscurity has been proven wrong time and time again. It's foolish to think otherwise…

So it's a back door. And a hamfisted one at that.

It's not a coding error. It's built to do exactly what it looks like it's supposed to do: diminish any ordinary person's claim of total control over the behavior of the system, such that, should the need arise, a trained hand can lift the proper latch and intervene, to gain the upper hand, ostensibly so "the good guys" win.

The good guys being those that ordered Intel into compliance with such requirements.

Re: Intel ME Manufacturing Mode: obscured dangers and MacBook vulnerability

#23
post #6

"The weakness of "security through obscurity" is so well known as to be obvious. Yet major hardware manufacturers, citing the need to protect intellectual property, often require a non-disclosure agreement (NDA) before allowing access to technical documentation. " I believe the actual reason for "security through obscurity" is that it's a delay tactic used against well-funded adversaries. There's an inherent problem…

And still fail. The state is dysfunctional in many regards.

NSA can't hire the hackers they want because they all smoke weed. China sends all their drug users to the execution van so all the new CS and security grads can go right to work for the govt.

Re: Intel ME Manufacturing Mode: obscured dangers and MacBook vulnerability

#24
post #19

Earlier quoted context omitted.

In other words, this vulnerability is "the insecurity that gives us freedom"? That's what it looks like from a quick scan through the article, and if that's the case this is yet another sad instance where the authoritarian "security" community is openly hostile against user freedom. On that moral point, a relevant comment I made on an article recently: https://news.ycombinator.com/item?id=18102434 Anyone who is activ…

"Freedom or persistent compromise" depending on whether it's the rightful owner or an attacker using the exploit. The most user-hostile part is forcing users to choose between accepting an OEM locked down platform, or running an open platform that an attacker can permanently lock down.

I'd happily pick the third option of running a platform locked down by me, the hardware purchaser, if it were ever made available to the general market. I have absolutely no objection to locked down hardware or DRM-like protections so long as the devices and software I'm using and installing obey me and only me.

Re: Intel ME Manufacturing Mode: obscured dangers and MacBook vulnerability

#25
post #19

Earlier quoted context omitted.

In other words, this vulnerability is "the insecurity that gives us freedom"? That's what it looks like from a quick scan through the article, and if that's the case this is yet another sad instance where the authoritarian "security" community is openly hostile against user freedom. On that moral point, a relevant comment I made on an article recently: https://news.ycombinator.com/item?id=18102434 Anyone who is activ…

"Freedom or persistent compromise" depending on whether it's the rightful owner or an attacker using the exploit. The most user-hostile part is forcing users to choose between accepting an OEM locked down platform, or running an open platform that an attacker can permanently lock down.

> The most user-hostile part is forcing users to choose between accepting an OEM locked down platform, or running an open platform that an attacker can permanently lock down.

That is flawed logic. The article demonstrates that the OEM version is insecure. Why would you assume that the open version would be more vulnerable to attackers?

Re: Intel ME Manufacturing Mode: obscured dangers and MacBook vulnerability

#26
A couple of small vendors are trying to offer choices with open firmware. They don't yet have the scale for low cost pricing.

1) Purism has been discussed on HN, trying to extend their laptop coreboot success to a phone form factor, http://puri.sm

2) Librebox is a desktop computer with coreboot, from Portugal, https://libretrend.com and https://youtube.com/watch?&v=mHyJCSqWhFw

For data centers, OpenCompute server owners are also the "OEM" and in control of more keys.

Re: Intel ME Manufacturing Mode: obscured dangers and MacBook vulnerability

#27
post #23

Earlier quoted context omitted.

And still fail. The state is dysfunctional in many regards.

NSA can't hire the hackers they want because they all smoke weed. China sends all their drug users to the execution van so all the new CS and security grads can go right to work for the govt.

:%s/can't/won't/g

Re: Intel ME Manufacturing Mode: obscured dangers and MacBook vulnerability

#28

Earlier quoted context omitted.

> It's the fact it's a secret closed system that has full control to monitor everything you do, and can not be fully disabled. To add to that, it also makes code audits impossible. Intel, AMD, ARM, et al: There is zero, and I mean ZERO reason to hide management functionality from users in this day and age. It's 2018, security through obscurity has been proven wrong time and time again. It's foolish to think otherwise…

So it's a back door. And a hamfisted one at that. It's not a coding error. It's built to do exactly what it looks like it's supposed to do: diminish any ordinary person's claim of total control over the behavior of the system, such that, should the need arise, a trained hand can lift the proper latch and intervene, to gain the upper hand, ostensibly so " the good guys " win. The good guys being those that ordered Int…

>The good guys being those that ordered Intel into compliance with such requirements.

There is vast case law surrounding our first amendment right to refuse this kind of coercion. No one can force you to present something as yours against your will (at least, if they want it to hold up in court).

What is more likely is that Intel won a great many more government contracts by doing this. They'd make tons of money doing it, so they did it. And if they didn't do it, their competitor would. That's how the system works in this country.

We shouldn't excuse them so readily.

Re: Intel ME Manufacturing Mode: obscured dangers and MacBook vulnerability

#29
post #23

Earlier quoted context omitted.

And still fail. The state is dysfunctional in many regards.

NSA can't hire the hackers they want because they all smoke weed. China sends all their drug users to the execution van so all the new CS and security grads can go right to work for the govt.

What about countries where drugs have been decriminalized?

Re: Intel ME Manufacturing Mode: obscured dangers and MacBook vulnerability

#30

Earlier quoted context omitted.

So it's a back door. And a hamfisted one at that. It's not a coding error. It's built to do exactly what it looks like it's supposed to do: diminish any ordinary person's claim of total control over the behavior of the system, such that, should the need arise, a trained hand can lift the proper latch and intervene, to gain the upper hand, ostensibly so " the good guys " win. The good guys being those that ordered Int…

>The good guys being those that ordered Intel into compliance with such requirements. There is vast case law surrounding our first amendment right to refuse this kind of coercion. No one can force you to present something as yours against your will (at least, if they want it to hold up in court). What is more likely is that Intel won a great many more government contracts by doing this. They'd make tons of money doin…

That's one option. Another is they got a national "security" letter that said you will do this, and even talking about this letter will get you a few years in the clink.

I don't think the gov goes around doing this willy nilly, but I think it's clear that this is about the only reliable way to defeat block ciphers. And since there are only 2 real CPU manufacturers, it's easier to do this than attack crypto directly. My personal pet theory is that the aes keys are kept on the die for later retrieval. That and/or keystrokes.

Post reply on HN