The ridiculous shit that needs to be done just to rid of some blob. RISC-V can't take the market over fast enough.
Will the RISC-V based CPU in your computer be Open Source?
A parallel example is while WebKit is Open Source Chrome isn't
41–50 of 81 posts
The ridiculous shit that needs to be done just to rid of some blob. RISC-V can't take the market over fast enough.
Will the RISC-V based CPU in your computer be Open Source?
A parallel example is while WebKit is Open Source Chrome isn't
This appears to be a legitimate ME neutralization. The ME is purportedly placed in "recovery" mode: According to Nicola Corna, the current ME state should have been changed from “normal” to “recovery”. Since the MEI interface is disabled (not visible from a PCI bus scan), there is no way to activate the ME at runtime, even after a full system compromise. It would still be possible to rewrite the BIOS flash chip with…
The ridiculous shit that needs to be done just to rid of some blob. RISC-V can't take the market over fast enough.
Just for example, you are using OpenBSD and full disk encryption and you think you are safe? What if the firmware on your NIC can be altered to scan your RAM (using DMA) and send the interesting data (big prime numbers, passwords, etc.) home? What if firmware on your keyboard can be modified (or pre-programmed in factory) to record the last x thousands of keypresses (which will include your boot disk password) on its own flash memory which can be later extracted? There are so many attack vectors.
This appears to be a legitimate ME neutralization. The ME is purportedly placed in "recovery" mode: According to Nicola Corna, the current ME state should have been changed from “normal” to “recovery”. Since the MEI interface is disabled (not visible from a PCI bus scan), there is no way to activate the ME at runtime, even after a full system compromise. It would still be possible to rewrite the BIOS flash chip with…
Earlier quoted context omitted.
Just reboot after neutralization. "With ME neutralized, the MEI interface disappears from the PCI bus, and the integrated NIC ceases to work, but will resume to work after a reboot."
The phrasing there is confusing. Does the NIC break because the ME is neutralized? Then rebooting again with the ME neutralized will break the NIC again. Why would the NIC only break once after the ME is neutralized? The system is started from a fully powered-off state after the ME firmware is updated. Maybe the NIC has some sort of non-volatile state that gets updated when the ME fails to initialize, and then the NI…
Earlier quoted context omitted.
Their discussion may have consisted of "too bad these extremists don't realize that the ME is harmless if you don't have an Intel NIC".
There is a device visible on the PCI bus. How hard is it to imagine that userland programs could somehow pass requests to that device, and have the ME do bad things to the CPU or the RAM? How hard is it to imagine some special string in RAM could trigger the ME in a similar way? (so many CPU instructions - I would be surprised if there wasn't one to talk to the ME) Exploits and vulnerability are mitigated by proper a…
The ridiculous shit that needs to be done just to rid of some blob. RISC-V can't take the market over fast enough.
A rootkit can be anywhere on the PCIe bus. Just for example, you are using OpenBSD and full disk encryption and you think you are safe? What if the firmware on your NIC can be altered to scan your RAM (using DMA) and send the interesting data (big prime numbers, passwords, etc.) home? What if firmware on your keyboard can be modified (or pre-programmed in factory) to record the last x thousands of keypresses (which w…
The ridiculous shit that needs to be done just to rid of some blob. RISC-V can't take the market over fast enough.
RISC-V is Open Source. Will the RISC-V based CPU in your computer be Open Source? A parallel example is while WebKit is Open Source Chrome isn't
Of course there will be both proprietary and open implementations of RISC-V.