Live data from Hacker News

“We have obtained fully functional JTAG for Intel CSME via USB DCI”

twitter.com

61–70 of 413 posts

Re: “We have obtained fully functional JTAG for Intel CSME via USB DCI”

#61
post #37
post #33

Earlier quoted context omitted.

I think you're being overly paranoid. If the attacker has physical access to the machine, chances are you're compromised anyway, even before this vulnerability.

I wonder how long it will take until an attack over the network is found.

You mean another one? [1]

1. https://thehackernews.com/2017/05/intel-amt-vulnerability.ht...

Re: “We have obtained fully functional JTAG for Intel CSME via USB DCI”

#62

Earlier quoted context omitted.

Here's hoping. Intel did a great job hiding the thing and making it all but impossible to remove (at present if you nuke the firmware, the CPU will totally fail to initialise. Thanks Intel!). That said, we're talking about an embedded device with very low-level code, and any 'disabling' code is probably going to be distributed in binary form. Stands to reason somewhere along the lines, someone is going to turn that a…

I just get tired of being ridiculed and then 10 years later vindicated. In Faraday cages we trust.

2013 was the greatest 'WE TOLD YOU SO' in history for the tin-foil-hat brigade...

Re: “We have obtained fully functional JTAG for Intel CSME via USB DCI”

#63
post #32

At first it looks nice "oh now we can get rid of it" but it also opens up a very scary near future security-wise. We've now entered a realm where an attacker could simply plug a device on an usb port of your computer for a few seconds to have it access your cpu's ME through USB JTAG and take over it, allowing him to have full access and control over what you do/read/open/type over the network, without you ever knowin…

The 'evil maid' attack is well known, and states that once someone has physical access to your computer, all bets are off. Anything that has DMA enabled (e.g. Firewire or Thunderbolt) offers an external device direct access to the system RAM that is very difficult to defend against, or they could attach a keylogger or modify your bootloader, basically unleash all manner of havok. USB JTAG is really no different from…

> Anything that has DMA enabled (e.g. Firewire or Thunderbolt) offers an external device direct access to the system RAM that is very difficult to defend against

IOMMU effectively solves the "DMA is completely broken" problem, as far as I'm aware.

Evil Maid attacks are mostly worrisome because even UEFI cannot protect you against some bootloader attacks (what if you disable UEFI or reflash the firmware and then have a bootloader that just looks like a UEFI boot). There are some usages of TPMs that seem quite promising (they revolve around doing a reverse-TOTP-style verification of your laptop to ensure that the TPM has certified the entire boot chain).

It's quite a hard problem, made significantly harder by the fact that every fucking hardware vendor seems to want to make our machines even less secure.

Re: “We have obtained fully functional JTAG for Intel CSME via USB DCI”

#65
post #32

At first it looks nice "oh now we can get rid of it" but it also opens up a very scary near future security-wise. We've now entered a realm where an attacker could simply plug a device on an usb port of your computer for a few seconds to have it access your cpu's ME through USB JTAG and take over it, allowing him to have full access and control over what you do/read/open/type over the network, without you ever knowin…

Many people will now start to dig in. War is started and I hope somebody will find a way to totally remove/replace(with a stub) Intel ME before some critical vulnerability will be discovered in the Intel ME's network stack. In white hats we trust :)

me_cleaner already exists[1], and it takes advantage of several flaws in Intel ME's signing to remove large sections of the code thus neutering it. Some code still exists, but Intel ME cannot actually fully initialise on "cleaned" systems. Older machines used to have a bug where if you filled the first half of the Intel ME firmware with zeros the machine would boot but ME wouldn't start at all.

But yes, I hope that with this it'll be possible to completely remove the remaining few hundred kB of Intel ME code remaining.

[1]: https://github.com/corna/me_cleaner

Re: “We have obtained fully functional JTAG for Intel CSME via USB DCI”

#66

Companies like Intel, who are complicit in helping CIA or any intel agency (government, rogue or otherwise) infiltrate and exploit our systems - need to be held accountable by the market. Intel ME and the (assumed [0]) partnership with CIA to design and build this system - should be an absolute travesty blow to the integrity of their business long-term. Will you, as lead engineer or sys admin for your mission critica…

> Companies like Intel, who are complicit in helping CIA or any intel agency (government, rogue or otherwise) infiltrate and exploit our systems - need to be held accountable by the market.

At the same time as "buy American"? You're aware that any American chipmaker will be gag-ordered to help the CIA?

Re: “We have obtained fully functional JTAG for Intel CSME via USB DCI”

#67
post #3

Can someone explain like I have a degree in computer science from a good university, but opted for a career as a software engineer in some relatively high level languages?

I'm going to assume "relatively high level languages" are for example Python, Ruby, C#, Javascript...

Imagine that you have your high level program. When you execute it, it goes through a just-in-time compilation (whether that's script parsing or bytecode conversion, or actual compilation, or whatever) before reaching the CPU which actually executes your code. Now imagine that your interpreter has the capability of reading and monitoring everything you do.

Nothing wrong with that, it's supposed to do that, it's how it works. But imagine if it had an exposed, unlogged, unmonitored, API which allowed a third party to be able to interact with whatever you do. Say that it's there "for debugging purposes".

You want to encrypt an HTTPS session? This API allows them to grab your key without ever notifying you. Or, even if you use custom encryption, it allows them to grab your specific instructions and the data used in processing to reverse your encryption.

It allows a remote party to inject their own flow of execution into your program. So you're sitting there waiting for the next user event to occur in your event loop while, instead, the interpreter simply handed the whole event loop to a third party. They could inject user events for you to process that the user never actually performed; they could modify data in ways that you can never detect.

Except that it's not the interpreter. It's a side-channel, an additional hidden core on your CPU (it's actually a completely hidden and separate secondary CPU). Your processor still runs and executes your code. But another processor is simultaneously running and executing its own code with its own RAM that you can't access. It has access to your RAM as if it were a file open on your hard disk.

You can't disable it. You can't interact with it. It's even running when your computer is "shut off". If there's power on the motherboard, then this hidden processor is running.

That, in a nutshell, is Intel ME...

... This sounds _really_ paranoid and alarmist. But it's not all bad. Intel has usually done really well with "security through obscurity" in this case and there aren't many known exploits for Intel ME. That said, those that do or could exist, gain all of the capabilities of Intel ME.

Most people consider "game over" for physical access anyway, so I'm not sure that pwning it with physical access is a new problem; instead it's a secret basement in a bank; it's only a problem if someone figures out it's there and starts digging a tunnel to it.

Also, remember that a lot of motherboards these days come with built-in wifi or bluetooth adaptors. Intel ME has access to those too; you can't just rely on an upstream firewall for your physical ethernet. With the right (wrong?) exploit, all it takes is an adversary to be within directional antenna distance (which is actually really far) to be able to pwn your system. The best way to prevent abuse over that channel is to physically break the antenna connection (lol warranty voided because you've damaged your motherboard).

Re: “We have obtained fully functional JTAG for Intel CSME via USB DCI”

#68
post #12
post #3

Can someone explain like I have a degree in computer science from a good university, but opted for a career as a software engineer in some relatively high level languages?

Intel CPUs have an embedded supervisory CPU called the Management Engine. It can read all of memory, control power states on the main CPU, and generally has super-root privileges on everything. You, an end-user, aren't allowed to program it. The current MEs run a form of Minix. They represent an incredible security and privacy risk, because we don't know what code they run and it is widely believed that the NSA or ot…

Is it known/suspected that AMD have an equivalent?

Re: “We have obtained fully functional JTAG for Intel CSME via USB DCI”

#69

Earlier quoted context omitted.

Here's hoping. Intel did a great job hiding the thing and making it all but impossible to remove (at present if you nuke the firmware, the CPU will totally fail to initialise. Thanks Intel!). That said, we're talking about an embedded device with very low-level code, and any 'disabling' code is probably going to be distributed in binary form. Stands to reason somewhere along the lines, someone is going to turn that a…

I just get tired of being ridiculed and then 10 years later vindicated. In Faraday cages we trust.

http://physicsworld.com/cws/article/news/2015/sep/15/are-far...

Have a nice day.

Re: “We have obtained fully functional JTAG for Intel CSME via USB DCI”

#70

Companies like Intel, who are complicit in helping CIA or any intel agency (government, rogue or otherwise) infiltrate and exploit our systems - need to be held accountable by the market. Intel ME and the (assumed [0]) partnership with CIA to design and build this system - should be an absolute travesty blow to the integrity of their business long-term. Will you, as lead engineer or sys admin for your mission critica…

> Companies like Intel, who are complicit in helping CIA or any intel agency (government, rogue or otherwise) infiltrate and exploit our systems - need to be held accountable by the market. At the same time as "buy American"? You're aware that any American chipmaker will be gag-ordered to help the CIA?

Fair point, but let's not paint such a bleek picture. Gag-orders are an unfair (unconstitutional?) weapon of tyrannical regimes and should be condemned as so. Aside from taking political action to remove that tool from big brother's arsenal we as hacker/entreprenuers can build systems and strategize on how to mitigate and avoid gag-order scenarios altogether.

Perhaps this is pie in the sky but a future where open hardware is as ubiquitous/accessible/easy to use as open source software would make it easier to change chips or gut your laptop and re-build it with hardware that you can trust.

Post reply on HN