Live data from Hacker News

'Unfixable' security flaw in Intel boot ROM

theregister.co.uk

41–50 of 65 posts

Re: 'Unfixable' security flaw in Intel boot ROM

#41

The labs team at work wrote a bit [0] about why this is over-hyped (more context in the full post): > Arbitrary code execution is bad! But exploiting this vulnerability requires local access at a minimum, compounded by the attacker needing to exploit a relevant device to gain a foothold on the system. This list of valid footholds is quite limited. For instance, an attacker would need to perform code execution in the…

It is limited to any well-monied adversary.

So, every serious company should be concerned that their competition (maybe abroad) will be able to eventually decrypt a lost / stolen laptop with trade secrets. So every corporate laptop needs its full-disk encryption upgraded. It's large.

Re: 'Unfixable' security flaw in Intel boot ROM

#42
post #35

Earlier quoted context omitted.

> When this happens, utter chaos will reign. Utter chaos? I don't think so. > Hardware IDs will be forged Seems like a victory for privacy. Who wants to be tracked via hardware IDs? > digital content will be extracted Any victory over DRM technology is a good thing. The only people shedding any tears will be those in the copyright industry. > data from encrypted hard disks will be decrypted People actually rely on pr…

Anybody who doesn't want their data copied will be shedding tears. Including anybody with private files. You are more than welcome to decline to use DRM if you don't like it. Just don't expect people to give you copies of data they don't want shared by you.

> Anybody who doesn't want their data copied will be shedding tears.

"Their" data? What a ludicrous concept. It's analogous to saying people own numbers.

> Just don't expect people to give you copies of data they don't want shared by you.

I fully expect people to distribute "their" data far and wide to anybody who asks for it. That's what copyright is all about: giving people the illusion they're in control of what happens to that data.

The truth is only one copy of the data is needed. Once it's out there, there are no limits to what can be done with it.

Re: 'Unfixable' security flaw in Intel boot ROM

#43
post #19

Earlier quoted context omitted.

What about physical possession before you own it? Will this potentially sour a used/refurbished market?

this is more about the chipset on the motherboard. to backdoor this you need to saddle a chip or a connector onto the PCH chip and win the race to takeover the bus. or if your intel and you send a firmware update to modify the ME behaviour /state. it would be fairly suspect in most cases but if this was done at the factory, it would be hard to tell for most people. What really matters is just how much of a target you…

How far fetched would nation states performing this at airports be?

Re: 'Unfixable' security flaw in Intel boot ROM

#44
post #38

So it seems that the flaw can’t plausibly be exploited by a remote or adjacent attacker or software. So what’s the impact here? Warez scene wreaking havoc with lossless WEB-DLs?

A ton of warez groups (even a lot of P2P ones) already have a Widewine exploit that works for >=1080p anyway, some groups (BLUTONiUM, PETRiFiED ++) even have a 2160p exploit.

It's actually quite amazing that the 1080p exploit hasn't leaked and been patched yet, considering how widespread it is.

Re: 'Unfixable' security flaw in Intel boot ROM

#45
post #19

Earlier quoted context omitted.

this is more about the chipset on the motherboard. to backdoor this you need to saddle a chip or a connector onto the PCH chip and win the race to takeover the bus. or if your intel and you send a firmware update to modify the ME behaviour /state. it would be fairly suspect in most cases but if this was done at the factory, it would be hard to tell for most people. What really matters is just how much of a target you…

How far fetched would nation states performing this at airports be?

in socratic fashion...

how long does it take for a machine to be opened and booted up, and what sort of charade would be required to make the opportunity.

if someone flatout stole your laptop, how long would it take for you to notice its been replaced by a stand in? would someone have the opportunity to swap your real laptop back to you unnoticed?

and seriously it doesnt need to be a nation state that does this, as all you need to be capable of physically is to inject digital pulses into the bus crafting an exploit is where the skill comes in.

some people are motivated just by the opportunity to stir a pot.

Re: 'Unfixable' security flaw in Intel boot ROM

#46

Earlier quoted context omitted.

> "Internet-of-Things attestation" ?? A poor attempt to stick a refreshing buzzword in front of a fundamentally unwanted user-betraying open-society-undermining technology. While I agree with you at a consumer level, at the industrial level this is a thing. Like, imagine a vertical farm that is controlled by a thousand, networked on-prem robots. An "attestation" mechanism makes setting this up easier and less-error p…

How so specifically, compared to say just imaging the devices? Are we really worried about rogue employees putting rootkits on said robots, and to what end? Remote attestation in general does have positive uses, and would be freedom preserving if the signing keys were controlled by the device's owner. The problem is Intel's design of baking in privileged keys that they themselves control, such that hostile parties ca…

> Are we really worried about rogue employees putting rootkits on said robots, and to what end?

Not about rogue employees, but adversary states, just think of Stuxnet. Messing up a nation's food supply can induce everything from mild unrest to full scale civil war and mass migration. For now (!) we have the lucky advantage that most farm labor is still manual / the machines that exist can either be trivially replaced with older non-smart machines or by manual labor... but imagine 20, 30 years in the future?

Re: 'Unfixable' security flaw in Intel boot ROM

#47

The useful gist: > "To fully compromise EPID, hackers would need to extract the hardware key used to encrypt the Chipset Key, which resides in Secure Key Storage (SKS)," explained Positive's Mark Ermolov. > "However, this key is not platform-specific. A single key is used for an entire generation of Intel chipsets. And since the ROM vulnerability allows seizing control of code execution before the hardware key genera…

> When will it stop? How deep run the flaws in Intel's platform? Is AMD equally exposed? We're seeing the tide turn from x86 to ARM pretty quick in both the datacenter and laptop markets. AMD should come through relatively unscathed as they're pretty diversified, but Intel is fucked. Graviton2 (Amazon's proprietary ARM stack) absolutely crushes x86 from a $/performance perspective, and there are plenty of other compa…

ARM is a joke on raw computing. Also, RISC-V will crush down ARM on servers once it begins to grow a little.

Re: 'Unfixable' security flaw in Intel boot ROM

#48
post #35

Earlier quoted context omitted.

Anybody who doesn't want their data copied will be shedding tears. Including anybody with private files. You are more than welcome to decline to use DRM if you don't like it. Just don't expect people to give you copies of data they don't want shared by you.

> Anybody who doesn't want their data copied will be shedding tears. "Their" data? What a ludicrous concept. It's analogous to saying people own numbers. > Just don't expect people to give you copies of data they don't want shared by you. I fully expect people to distribute "their" data far and wide to anybody who asks for it. That's what copyright is all about: giving people the illusion they're in control of what h…

> "Their" data? What a ludicrous concept. It's analogous to saying people own numbers.

Oh. In that case, where have you posted your bank credentials?

Re: 'Unfixable' security flaw in Intel boot ROM

#49
post #9

Earlier quoted context omitted.

the problem is the hardware being replaced to begin with. The ME is not needed for the end user to operate thier machine in a secure manner. The ME is a trojan that allows intel to manipulate your system and lock you into the whole DRM nonsense. the only reason Intel platforms havent become as bad as mobile platforms is because there isnt enough fear of system compromise from the average user. https://en.wikipedia.or…

You know if your did less FUD there's a chance people may actually engage in a conversation with you. Anyone from enterprise knows his much of a timesaver amt is. I make a call andi don't have to wait for the IT dude to appear on my desk- he clicks a few buttons from his desk and my problem is fixed.

OK, but the user with physical access should have the option to disable it (without damaging the rest of the system).

Re: 'Unfixable' security flaw in Intel boot ROM

#50

The useful gist: > "To fully compromise EPID, hackers would need to extract the hardware key used to encrypt the Chipset Key, which resides in Secure Key Storage (SKS)," explained Positive's Mark Ermolov. > "However, this key is not platform-specific. A single key is used for an entire generation of Intel chipsets. And since the ROM vulnerability allows seizing control of code execution before the hardware key genera…

> When this happens, utter chaos will reign. Utter chaos? I don't think so. > Hardware IDs will be forged Seems like a victory for privacy. Who wants to be tracked via hardware IDs? > digital content will be extracted Any victory over DRM technology is a good thing. The only people shedding any tears will be those in the copyright industry. > data from encrypted hard disks will be decrypted People actually rely on pr…

>> Hardware IDs will be forged

>Seems like a victory for privacy. Who wants to be tracked via hardware IDs?

Those are probably not the hardware ids you're thinking about. They're the hardware ids used in trusted computing (eg. remote attestation, TPM sealing), not the ones used for fingerprinting.

>People actually rely on proprietary hardware encryption? They should have learned the lesson when built-in SSD encryption turned out to be worthless.

This is a very naive take on what's at stake. With disk encryption, there's the risk of an evil maid attack (where the attacker replaces the bootloader with a malicious one and intercepts your key next time it boots). One way of preventing this is by using trusted computing to ensure that the encryption keys are only released when the system is at a known good state (ie. bootloader hasn't been tampered with). This applies to both proprietary solutions (bitlocker) and free ones (tpm-luks).

Post reply on HN