Live data from Hacker News

Uncorrectable freedom and security issues on x86 platforms (2016)

decentralize.today

51–60 of 141 posts

Re: Uncorrectable freedom and security issues on x86 platforms (2016)

#51

This needs more attention. Particularly now that AMD may actually look into cooperating with the community on this matter somewhat. I wouldn't get my hopes up yet though, as this was a Reddit AMA done during a time when AMD is keen to please the community. This matter must not go away for something to be done about it.

Here's the context, for anyone who didn't see the AMA:

https://www.reddit.com/r/Amd/comments/5x4hxu/we_are_amd_crea...

This is currently the top-voted question with almost four thousand upvotes. AMD gave a noncommittal "we'll look into it" response, but now at least they're aware that a lot of people actually do care about things like this.

Re: Uncorrectable freedom and security issues on x86 platforms (2016)

#52
post #8

Isn't it sci-fi-level incredible, and frankly both scary and shady, that every modern x86 CPU has this forced sub-ring-0 control program? And that the CPU vendors apparently go to extreme lengths in hiding its functionality? Why would even large vendors like Apple or Dell agree to this? The 30-minute timeout is particularly mischievous. It's like they REALLY want to slow down any effort at patching out the ME. Are we…

NSA 100% . Some time around 10 years ago governments decided the internet was too "dangerous" to be free. Arab spring cemented that into their minds, and now a bastion of free thought has become the worlds biggest spying apparatus.

Try using Intel ME. Than come back and tell us that's a tool for mass surveillance.

If you think there's a evil NSA front for this type of stuff -- its Absolute Software. Their bits have been embedded in most BIOS packages since the 90s, and nobody has heard of them.

Re: Uncorrectable freedom and security issues on x86 platforms (2016)

#53
post #31

Earlier quoted context omitted.

So why not build our own network with crypto, blackjack & hookers on libre hardware? Say on an OrangePi PC2 with a bunch of high gain USB 5GHz radios attached, and throw some spinning rust on there so you can run a Nextcloud instance and/or join your local Ceph cluster/IPFS. We have CJDNS (which salsa20's all your data & can VPN legacy networks to ya), fully FLOSS SBCs for under $20ea, and 802.11n and AC outdoor radi…

I'm a software engineer myself - but I can't even contribute to projects such as lowRISC - is way beyond my abilities. Right now I'm learning to program microcontrollers, and I want to learn about FPGA's as the next step. I also work at a company that has exactly this focus - to sell, and eventually produce devices that can be run with free software from top to bottom - but I don't see ourselves producing our own dev…

Yeah, I'm not advocating for building our own SoC, as just taping out a chip is tens of millions, instead I'm advocating for using inexpensive Arm64 chips that already are a known quantity (firmware free, mainlined drivers) to build a fast & secure network, and scale from there.

Re: Uncorrectable freedom and security issues on x86 platforms (2016)

#54

... I confess I'm very frustrated reading about how trusted computing modules hurt the cause of FOSS but no alternatives to actually try and carry out cryptography to execute trusted code. Inevitably the complaint is, "Well if they have physical access you're screwed anyways." And I just don't understand how anyone can maintain that farce when the last year has shown that it's a genuine challenge even for the US FBI…

The FBI issue wasn't a technical issue. When they gave up on grandstanding, the phone was cracked in hours.

Re: Uncorrectable freedom and security issues on x86 platforms (2016)

#55
post #31

Earlier quoted context omitted.

NSA 100% . Some time around 10 years ago governments decided the internet was too "dangerous" to be free. Arab spring cemented that into their minds, and now a bastion of free thought has become the worlds biggest spying apparatus.

So why not build our own network with crypto, blackjack & hookers on libre hardware? Say on an OrangePi PC2 with a bunch of high gain USB 5GHz radios attached, and throw some spinning rust on there so you can run a Nextcloud instance and/or join your local Ceph cluster/IPFS. We have CJDNS (which salsa20's all your data & can VPN legacy networks to ya), fully FLOSS SBCs for under $20ea, and 802.11n and AC outdoor radi…

Check out hyperboria

Re: Uncorrectable freedom and security issues on x86 platforms (2016)

#56
post #19

Earlier quoted context omitted.

> And I just don't understand how anyone can maintain that farce when the last year has shown that it's a genuine challenge even for the US FBI to unlock a mobile device without the owners say-so Difficulty? Yes. But the FBI is not the NSA, they don't specialize in such attacks. It's like asking your plumber to do heart surgery. So they commissioned it to else who does, and boom, they had access. Strong cryptographic…

I feel like you danced around the central point of my post: there is no suggestions for how to secure and harden devices without refining these trusted computing techniques. We need to harden these devices. Your argument is no one can be trusted to make them. But my argument is that if you believe that then you know you can't trust anyone to make anything one way or the other. Surely rather than botch the whole thing…

> there is no suggestions for how to secure and harden devices without refining these trusted computing techniques. We need to harden these devices.

Because the thing you are asking for is not possible. You have a bad premise:

> And I just don't understand how anyone can maintain that farce when the last year has shown that it's a genuine challenge even for the US FBI to unlock a mobile device without the owners say-so and it's getting harder all the time.

Which has two flaws. First, it wasn't a challenge for them, they were just using it as an excuse to whine about the second one that actually is. And second, the only real security is math (encryption), but it doesn't require any special support from the hardware.

If you have full disk encryption with a strong passphrase and the device is currently locked (i.e. the key is not in memory), the only way to get that data is to have the passphrase or break the encryption, and breaking the encryption is not expected to be possible.

The problem is, if someone has physical access to your device and can compromise your firmware, they can record your passphrase the next time you unlock the device, and then they don't need to break the encryption.

But this is not a thing you can do anything about. If someone has physical access to your device they can just steal it and leave you with one that looks the same up to the point of you entering your passphrase and then transmits it to the attacker. Nothing about the original device can fix that because it isn't the original device.

Similarly they can install a surveillance device in your room that can record you entering your passphrase and then come back tomorrow to take your device.

The only answer to these attacks is physical security. Secure boot does nothing.

Re: Uncorrectable freedom and security issues on x86 platforms (2016)

#57
post #31

Earlier quoted context omitted.

So why not build our own network with crypto, blackjack & hookers on libre hardware? Say on an OrangePi PC2 with a bunch of high gain USB 5GHz radios attached, and throw some spinning rust on there so you can run a Nextcloud instance and/or join your local Ceph cluster/IPFS. We have CJDNS (which salsa20's all your data & can VPN legacy networks to ya), fully FLOSS SBCs for under $20ea, and 802.11n and AC outdoor radi…

tomesh is literally doing CJDNS+OrangePiZero+5GHz+WAP+802.11s to get the most inexpensive yet performant meshing node. Come chat via Matrix at #software:tomesh.net

Mmm, how is throughput? I know that on an OrangePi PC (same Allwinner H3) I was getting 5MB/s for a point to point transfer, didn't check relay throughput though. I assume the H5 would do better with gigabit and 2.5x better NEON performance, but I've yet to test (just got kernel 4.10 built for it & booting Debian reliably).

Re: Uncorrectable freedom and security issues on x86 platforms (2016)

#58

Earlier quoted context omitted.

I feel like you danced around the central point of my post: there is no suggestions for how to secure and harden devices without refining these trusted computing techniques. We need to harden these devices. Your argument is no one can be trusted to make them. But my argument is that if you believe that then you know you can't trust anyone to make anything one way or the other. Surely rather than botch the whole thing…

> there is no suggestions for how to secure and harden devices without refining these trusted computing techniques. We need to harden these devices. Because the thing you are asking for is not possible. You have a bad premise: > And I just don't understand how anyone can maintain that farce when the last year has shown that it's a genuine challenge even for the US FBI to unlock a mobile device without the owners say-…

They don't need physical access to compromise your firmware. I thought that was one of the things the original article claimed, at least. The EMs firmware can be updated remotely if the system is plugged in (whether powered on or not).

Re: Uncorrectable freedom and security issues on x86 platforms (2016)

#59
post #4

Would love to see and ARM or MIPS setup get within shouting range of Intel. I have yet to hear any explanation of the IME that makes sense without the presence user-hostile intent.

You need a PKI infrastructure to implement AMT/IME.

I used it a few years ago to automatically build classroom computers for training classes. The trainer would pick a configuration, and a complete server and workstation environment would be installed.

You can also do KVM from a powered down state, brick the device, or validate that management engines are present.

Re: Uncorrectable freedom and security issues on x86 platforms (2016)

#60

I was struck by the following passage: >including Secure Boot, which even now requires FOSS users to purchase a license from Microsoft to boot FOSS on affected machines that lack an appropriate Secure Boot override." Can someone explain this to me, would this be for instance be Lenovo laptops making a deal with Microsoft since Windows is the default OS installed on these laptops? Is Microsoft mandating all OEMs/hardw…

Secure boot has 4 types of keys: The signature database (db) and forbidden signature database (dbx) contain a whitelist and blacklist respectivly of keys, signatures, and hashes that are trusted to run. Updates to either of the above lists must be signed by a Key Exchange Key (KEK). Most implementations allow multiple Key Exchanges Keys. Updates to the list of Key Exchange Keys must be signed by the Platform Key (PK)…

People are calling the old BIOS "PC BIOS" and UEFI "UEFI BIOS" nowadays. So feel free to continue to call it a BIOS.
Post reply on HN