Live data from Hacker News

“We have obtained fully functional JTAG for Intel CSME via USB DCI”

twitter.com

311–320 of 413 posts

Re: “We have obtained fully functional JTAG for Intel CSME via USB DCI”

#311
post #186

Earlier quoted context omitted.

Prior to the NSA contractor Edward Snowden's revelations in 2013, Room-641A had already been exposed by an AT&T employee-turned-whistleblower Mark Klein. The EFF sued the government in 2006 over it. Tape over laptop cameras isn't just a "parents-of-friends" thing, it's a good idea. Buy a set of stickers and support the EFF: https://supporters.eff.org/shop/laptop-camera-cover-set Anyone know somebody at Wired?

> Tape over laptop cameras isn't just a "parents-of-friends" thing, it's a good idea. Buy a set of stickers and support the EFF: https://supporters.eff.org/shop/laptop-camera-cover-set Support the EFF! But I hate the stickers. Everyone puts a sticker on their webcam and completely ignores the hot mic. But you get that false sense of security…

audio only nudies are usually slightly less exciting.

Re: “We have obtained fully functional JTAG for Intel CSME via USB DCI”

#312

Earlier quoted context omitted.

Why would they do something as ridiculous as telling you its true purpose?

They wouldn't. As I said, this is to the best of my knowledge. However, I believe I would know because it's not like one day the CEO came to us with a folder filled with requirements to be implemented. This is something that started very small ("find a way to force reboot a PC remotely if it's non-responsive") and evolved from there over months/years. I endured way too many meetings were design decisions were made. U…

Do you know technical details - like how many processes are even running under the Minix OS?

Also which internal or external groups lead the code development of those processes?

Is the code accessible to any employee/engineer with a technical relationship to IME?

Re: “We have obtained fully functional JTAG for Intel CSME via USB DCI”

#313
post #179

Earlier quoted context omitted.

Right. ME does make sense as a feature for sysadmins. Except . . . . Well, can you shed light on the following: 1. Why did your team deem it necessary to deny the end-user the capability to disable this feature? 2. Why did your team decide to enable ME on ALL consumer grade chips? You could have only enabled it on, say, Xeon, as a value-add - exactly like you do for ECC support. You could have made more money this wa…

> Why did your team decide to enable ME on ALL consumer grade chips? Can you please provide a reference? I've been trying to enable ME forever for my consumer-grade i7 with Intel motherboard for remote management, and I can't seem to be able to.

I looked into something similar recently. The following is based on plenty of research, but Intel's information can be a bit ambiguous and incomplete at times, so I can't promise I have every detail right.

FOR OTHERS: Note that you might be able to disable ME's remote access simply by ordering a computer with "No VPro".

1. ME is a platform with many applications that run on it; AMT (Active Management Technology) is one of them.

2. AMT has many components; remote management is one of them.

3. AMT comes in multiple 'editions' (my word, not Intel's) with different features. The Small Business Technology (SBT) edition does not provide remote access by design, with the idea (AFAICT) that small businesses don't want to setup and manage management servers and therefore remote access is insecure.

4. If in MEBx[0], you see "Small Business Technology", then there's no remote management - unless there's another remote management function in ME that is independent of AMT. Also, the first reference below provides the official method of identifying SBT implementations (via a flag in some table). I discovered it on a system ordered with a "No VPro"[1] network card (I'm still not sure why that's a spec of the NIC and not the processor).

Here are a couple of useful references:

* SBT: https://software.intel.com/en-us/documentation/amt-reference...

* MEBx on i7 processors (the title also specifies a chipset; I'm not sure how much that matters): http://download.intel.com/support/motherboards/desktop/sb/in...

.............

[0] MEBx is Management Engine BIOS Extension: the text-mode, pre-OS console UI for configuring ME

[1] VPro is not a product or technology. It's merely branding for, AFAICT, an ambiguously defined group of products that IT professionals might be interested in. It includes AMT (which is also part of ME and often marketed independently), TXT (Trusted Execution Technology), and more.

Re: “We have obtained fully functional JTAG for Intel CSME via USB DCI”

#315
post #179

Earlier quoted context omitted.

Right. ME does make sense as a feature for sysadmins. Except . . . . Well, can you shed light on the following: 1. Why did your team deem it necessary to deny the end-user the capability to disable this feature? 2. Why did your team decide to enable ME on ALL consumer grade chips? You could have only enabled it on, say, Xeon, as a value-add - exactly like you do for ECC support. You could have made more money this wa…

> Why did your team decide to enable ME on ALL consumer grade chips? Can you please provide a reference? I've been trying to enable ME forever for my consumer-grade i7 with Intel motherboard for remote management, and I can't seem to be able to.

The ME is already enabled. Maybe you're referring to AMT [0,1] (which might not be included)?

[0]: https://en.wikipedia.org/wiki/Intel_Active_Management_Techno...

[1]: https://www.intel.com/content/www/us/en/architecture-and-tec...

Re: “We have obtained fully functional JTAG for Intel CSME via USB DCI”

#316
post #192

Earlier quoted context omitted.

They wouldn't. As I said, this is to the best of my knowledge. However, I believe I would know because it's not like one day the CEO came to us with a folder filled with requirements to be implemented. This is something that started very small ("find a way to force reboot a PC remotely if it's non-responsive") and evolved from there over months/years. I endured way too many meetings were design decisions were made. U…

Having worked for Intel (in the open source org) I trust you. I've seen first hand how a cool, small, simple feature is blossoming into something dr. Frankenstein would be proud of. Also, I think people here severely underestimate the red tape and huge efforts needed to implement something mildly complex, Intel scale. Developing ME under wraps with full CIA-like functionality is staggeringly difficult - I've seen the…

How about this scenario.. there is now a common unified interface for all computers. If a vulnerability is discovered then all systems are vulnerable and must be patched. How are those patches delivered? It's protection may lie with a single signing-key. How well controlled is that signing key?

Re: “We have obtained fully functional JTAG for Intel CSME via USB DCI”

#317

Earlier quoted context omitted.

Some would argue the entire design of ME is evidence that it IS a backdoor.

AMT (server grade ME) is definitely a door of some sort, but as an advertised feature, I don't know that Intel is hiding it in the back. https://www.intel.com/content/www/us/en/architecture-and-tec...

> AMT (server grade ME)

AMT is an application that runs on ME, and it's on very many (most? all?) Intel-based desktop/laptops.

Re: “We have obtained fully functional JTAG for Intel CSME via USB DCI”

#318

Earlier quoted context omitted.

> Intel ME and the (assumed [0]) partnership with CIA to design and build this system I worked at Intel on ME and the things that came before it until around 2013. I can tell you two things -- 1. No, Intel ME wasn't born out of a desire to spy on people nor was it -- to the best of my knowledge but I honestly believe I would know -- created at the request of the US government (or others). It was an honest attempt at…

Man, anybody with a remote idea of how IT works would have said it was a very bad idea. I can't believe in genuineness here. Nobody smart enough to design that system is dumb enough no not understand the consequences. So it's been knowingly decided to create this monster and ship it to the entire world.

Unfortunately, in the real world, many times those of us who do have a remote idea suggest that things are "very bad ideas" but nonetheless get ignored by those who actually make the decisions.

Re: “We have obtained fully functional JTAG for Intel CSME via USB DCI”

#319

Earlier quoted context omitted.

> > Intel ME and the (assumed [0]) partnership with CIA to design and build this system Then why do you need security clearance to work on Intel ME?

Do you have a citation for that? That sounds interesting

The "citation" is a Twitter post [0] that included a screenshot of an anonymous post to 4chan by a supposed Intel employee who claims to have worked on the Management Engine team for the last three years. It was linked upthread.

[0]: https://twitter.com/9th_prestige/status/928740294090285057

Post reply on HN