Live data from Hacker News

Secrets of Intel Management Engine – Hidden code in your chipset

slideshare.net

41–50 of 64 posts

Re: Secrets of Intel Management Engine – Hidden code in your chipset

#43
post #3

My second thought on reading this was how can a server be PCI compliant with Intel management engine installed? but a quick search shows that Intel have thought of this: http://www.intel.co.uk/content/dam/www/public/us/en/document... My first thought was that it seems increasingly clear that Stallman has been right all along.

> My first thought was that it seems increasingly clear that Stallman has been right all along. The problem is that being philosophically right doesn't always mean being practically right. In order to create the perfect Stallman-esque machine, one would have to design everything from the logic chips up from scratch, because in the end, no third party can be trusted. He says this himself about the Loongson system he u…

one would have to design everything from the logic chips up from scratch

You mean like http://www.greenarraychips.com/home/products/index.html ?

Stallman's endorsement of Chinese hardware illustrates tho' that he values software freedom over, y'know, political freedom, which puts him on dodgy ground IMHO.

Re: Secrets of Intel Management Engine – Hidden code in your chipset

#44
post #40
post #33

Earlier quoted context omitted.

The ME is on _every_ CPU, and you can't easily disable it (there are ways, but it's unclear how much really shuts down, and you might lose power management features). vPro is merely the larger ME firmware: The small one is 1.5-2MB, the vPro one is 5-7. A non-vPro mainboard probably comes without a SOAP-capable webserver (although I wonder what they need 1.5MB of code for), but the chip to run it is all there.

Oh no. I thought I could select the right chip like you can do to dodge TSX and HT. What if I get an AMD CPU? Do those also have an IPMI in disguise inside the CPU package wired to a network interface?

> What if I get an AMD CPU? Do those also have an IPMI in disguise inside the CPU package wired to a network interface?

AMD implements something similar with DASH in some of its APUs: http://www.amd.com/Documents/out-of-band-client-management-o...

On page 10 in that PDF it says:

> DASH support is available in numerous client platforms, including the HP Elitebook 700 series, HP EliteOne 705, HP EliteDesk 705 Mini, HP EliteDesk 705, HP 6305 and Lenovo M78 ThinkCentre. Support is also available in management consoles, including the Symantec/Altiris Client Management Suite v7.5, and Microsoft System Center Configuration Manager (SCCM)*.

Re: Secrets of Intel Management Engine – Hidden code in your chipset

#45
post #3

My second thought on reading this was how can a server be PCI compliant with Intel management engine installed? but a quick search shows that Intel have thought of this: http://www.intel.co.uk/content/dam/www/public/us/en/document... My first thought was that it seems increasingly clear that Stallman has been right all along.

> My first thought was that it seems increasingly clear that Stallman has been right all along. The problem is that being philosophically right doesn't always mean being practically right. In order to create the perfect Stallman-esque machine, one would have to design everything from the logic chips up from scratch, because in the end, no third party can be trusted. He says this himself about the Loongson system he u…

> The problem is that being philosophically right doesn't always mean being practically right.

"Practical" is a code word people use to mean whatever is convenient for them or is on their agenda. You can use the argument "that's just not practical!" with whatever evidence you can come up with as an objection to almost anything, which makes it a poor argument. That's why we need unambiguous and objective philosophical positions to make decisions in specific circumstances.

What you're really saying is that working against the development of surveillance and control technologies by private capital and government decision makers is hard and so is not "practical."

Re: Secrets of Intel Management Engine – Hidden code in your chipset

#46
post #29
post #4

Why would the newest version of the ME use SPARC ISA? Does someone out there need register windows?

Where did everyone get SPARC from? The slides clearly say ARC, not SPARC.

Different versions of this slideshow have different information. The table titled "ME Core Evolution" (slide 15/16), for example, shows two generations in the version on slideshare, but three generations in the PDF on recon.cx. There is also more discussion of the SPARC architecture in the PDF version.

I did wonder if SPARC refers to the Sun architecture, or if it's an evolution of ARC that simply collides with the other name. He doesn't mention having successfully disassembled any of the BayTrail/TXE versions' firmware yet.

Re: Secrets of Intel Management Engine – Hidden code in your chipset

#47

ARC[1], not SPARC. It evolved from the SuperFX chip used in some SNES games. [1]: http://en.wikipedia.org/wiki/ARC_International

Take a look at the PDF version on recon.cx linked by jesrui— it's substantially different from the slideshare version in a few places, notably that it talks about a third generation (Bay Trail TXE) which uses SPARC and drops the pesky Huffman coder entirely in favor of LZMA.

Re: Secrets of Intel Management Engine – Hidden code in your chipset

#48
post #45

Earlier quoted context omitted.

> My first thought was that it seems increasingly clear that Stallman has been right all along. The problem is that being philosophically right doesn't always mean being practically right. In order to create the perfect Stallman-esque machine, one would have to design everything from the logic chips up from scratch, because in the end, no third party can be trusted. He says this himself about the Loongson system he u…

> The problem is that being philosophically right doesn't always mean being practically right. "Practical" is a code word people use to mean whatever is convenient for them or is on their agenda. You can use the argument "that's just not practical!" with whatever evidence you can come up with as an objection to almost anything, which makes it a poor argument. That's why we need unambiguous and objective philosophical…

> "Practical" is a code word people use to mean whatever is convenient for them or is on their agenda.

I don't see it as a "code word", I see it as it is defined: In practice, as opposed to in theory. And I don't have an agenda, I'm just making an observation.

> What you're really saying is that working against the development of surveillance and control technologies by private capital and government decision makers is hard and so is not "practical."

No, I'm not saying that at all; you're putting words in my mouth that I never uttered. I'm simply saying that in theory, fully Free and Open Source methodology is the best way to ensure that we live fully Free digital lives. In practice this is difficult (but not impossible) to achieve, and it certainly is worth striving for.

I'm not saying you don't have a valid viewpoint, but you don't have to make up your own version of what I said and attribute it to me to make your point. You can argue on your own merits and not resort to grade school tactics (at least I hope you can).

Re: Secrets of Intel Management Engine – Hidden code in your chipset

#49
post #43

Earlier quoted context omitted.

> My first thought was that it seems increasingly clear that Stallman has been right all along. The problem is that being philosophically right doesn't always mean being practically right. In order to create the perfect Stallman-esque machine, one would have to design everything from the logic chips up from scratch, because in the end, no third party can be trusted. He says this himself about the Loongson system he u…

one would have to design everything from the logic chips up from scratch You mean like http://www.greenarraychips.com/home/products/index.html ? Stallman's endorsement of Chinese hardware illustrates tho' that he values software freedom over, y'know, political freedom, which puts him on dodgy ground IMHO.

> Stallman's endorsement of Chinese hardware illustrates tho' that he values software freedom over, y'know, political freedom, which puts him on dodgy ground IMHO.

Show me a laptop or desktop computer not made wholly in China, or at the very least, containing a majority of parts not made in China, and you might have an argument here. The fact of the matter is, non-Chinese-made hardware meeting all of his requirements is scarce to the point of extinction. Maybe (maybe!) a couple of Korean phones and tablets have no DRM, no NDAs attached, no hidden features, no binary blobs required for full utilization.

Or in other words, if you're so worried about political freedom, you'd best throw out that smartphone, that laptop, that desktop, that gaming console, that car stereo, and so on. Dodgy ground indeed, isn't it?

Re: Secrets of Intel Management Engine – Hidden code in your chipset

#50

tldr: Intel's remote management capabilities are obscurely baked into every chipset. The ME has out of band access to the network card and main memory. Since ME also has its own flashable memory in principle a machine could be compromised in a nearly undetectable way. The presentation shows that a lot of interesting details of ME have been brought to light but it has also withstood a first round of attacks. No rootki…

Lets just hope that intel security teams are better than Sony Pictures' ones. After the sony hack ... lets say that I feel less secure about anything.

What was exceptional about the Sony hack? Lots of companies have been owned due to various oversights.
Post reply on HN