Live data from Hacker News

How Purism avoids Intel’s Active Management Technology

puri.sm

61–70 of 121 posts

Re: How Purism avoids Intel’s Active Management Technology

#61
post #53
post #48

Earlier quoted context omitted.

Yeah, that was strange. Sounds like there is some argument history behind it.

It does read like that, but even so, the initial question from Raptor Computing Sys was very well worded and not disrespectful at all. The inability to at a minimum leave it as "We've covered this before, and disagree on some items. We'll have to agree to disagree and leave it at that." or even "I'm doing what I can, we'll see where it ends up in the end" or "See the official account for official statements" is the t…

To be fair, I can see why

> Even if you do port coreboot

was read as abrasive; that tweet can be read as a snarky attack that belittles the efforts of the porter, to which the "so what?" response is apt – in fact, a de-escalation.

And yet, in reality, it wasn't one. (This is why you assume good faith, people!)

Re: How Purism avoids Intel’s Active Management Technology

#62
post #7

Earlier quoted context omitted.

I know it isn't possible. Half measures are attractive short term but can serve to normalize failure, as is currently happening. Most people I know view Purism favorably and think it has actually made ME irrelevant. It hasn't, all the hardware is still there and can be enabled. You still are not the de facto owner of the machine.

> It hasn't, all the hardware is still there and can be enabled. Can it be enabled by Intel? A system that has ME installed with a NIC the ME can't access (non-Intel) seems like it makes the ME irrelevant via suffocation. I'm not sure of the technical details of this board or if the ME can access non-Intel NICs.

Well, if ME was activated by the byte sequence PLEASE_ENABLE_ME_42 being present in RAM, which caused it to look for the Firefox / Chrome network stack in memory and use that to send passwords to Intel…

Unlikely? Amazingly so. Technically possible? Yes.

Re: How Purism avoids Intel’s Active Management Technology

#63

I've been hearing about Intel’s Active Management Technology for years, but I'd like to see a demonstration of how an attack would work. I have an unused laptop with: 1. an Intel CPU that supports the vPro feature set 2. an Intel networking card 3. the corporate version of the Intel Management Engine (Intel ME) binary (well, definitely, a corporate laptop that used to get updates, but how do I check for ME?) Is there…

Absence of evidence is not the evidence for absence. If the backdoor exists you will need to know a secret to open it. Currently, the public obviously doesn't know this secret or the doors would be wide open for virtually anybody. Because we don't know the secret key, we cannot open them to prove that they exist. So we don't know for sure if the backdoors exist. But the way the IME is designed and handled makes it po…

>It's up to Intel to prove that they don't exist.

That seems a bit over the top to ask them to prove a negative.

Re: How Purism avoids Intel’s Active Management Technology

#64

Earlier quoted context omitted.

Absence of evidence is not the evidence for absence. If the backdoor exists you will need to know a secret to open it. Currently, the public obviously doesn't know this secret or the doors would be wide open for virtually anybody. Because we don't know the secret key, we cannot open them to prove that they exist. So we don't know for sure if the backdoors exist. But the way the IME is designed and handled makes it po…

>It's up to Intel to prove that they don't exist. That seems a bit over the top to ask them to prove a negative.

Releasing the code would allow people to verify it.

Re: How Purism avoids Intel’s Active Management Technology

#65

I've been hearing about Intel’s Active Management Technology for years, but I'd like to see a demonstration of how an attack would work. I have an unused laptop with: 1. an Intel CPU that supports the vPro feature set 2. an Intel networking card 3. the corporate version of the Intel Management Engine (Intel ME) binary (well, definitely, a corporate laptop that used to get updates, but how do I check for ME?) Is there…

https://www.blackhat.com/docs/us-17/thursday/us-17-Evdokimov...

https://www.youtube.com/watch?v=ubmKdOMRhLk

Re: How Purism avoids Intel’s Active Management Technology

#66
post #40

Earlier quoted context omitted.

that's like saying having a flimsy house door lock lying in your kitchen drawer is a security problem. you have hardware on the cpu no longer accessible by software. you have a mellanox network card the me can't talk to. it's there, in the kitchen drawer. it's no longer in the door -so not a security problem. the 'issue' requires physical access to the machine, and for you to be logged in with an admin account. if so…

No, this is more akin to having a flimsy plywood door with a plastic lock right next to your real one but acting like you've solved the issue by taping a "please don't use" sign over it. Intel ME is still there. It is still potentially remotely configurable and remotely updateable. That those features are not advertised is irrelevant, they can be assumed to be there or easily added.

'It is still potentially remotely configurable and remotely updateable.'

and there's the issue. it is literally not remotely anything, since in the stated configuration it is not possible to get to it unless you are physically sitting at your computer and logged in. you are making stuff up and saying the thing you made up is dangerous.

Re: How Purism avoids Intel’s Active Management Technology

#68

Earlier quoted context omitted.

Absence of evidence is not the evidence for absence. If the backdoor exists you will need to know a secret to open it. Currently, the public obviously doesn't know this secret or the doors would be wide open for virtually anybody. Because we don't know the secret key, we cannot open them to prove that they exist. So we don't know for sure if the backdoors exist. But the way the IME is designed and handled makes it po…

>It's up to Intel to prove that they don't exist. That seems a bit over the top to ask them to prove a negative.

[deleted]

Re: How Purism avoids Intel’s Active Management Technology

#69

Earlier quoted context omitted.

It's certainly one of those "acquired tastes", though like with 3.5mm elimination, I don't understand the sheer vitriol against it by those who happen not to use it. Why do you care? If everything else in Thinkpad appealed to you, why would an eminently ignorable feature be such a HUGE ("single reason") deal breaker? In my mind, either a) There are other reasons and this is a convenient conscious or subconscious scap…

The trackpoint is ugly. It's a giant throwback pimple in the middle of the keyboard, which there's no way to get around looking at all the time. Thinkpads being ugly is kind of their thing, so it doesn't surprise me that lots of Thinkpad people don't mind it or even see it as a plus, but to me seeing a trackpoint is like seeing a floppy drive. I used one for years, and I'm really happy that trackpads have gotten good…

But display notches obscure the display, they're a functional issue. There's literally a hole in the image. (I have a top centre notch, and curved corners, on my A70. When watching content, wherever possible I letterbox the corners and notch out so that I'm not missing anybody the actual frame.)

Most typists aren't touching the nipple when they're typing, so is it an objection that's purely aesthetic, as opposed to notches?

Re: How Purism avoids Intel’s Active Management Technology

#70
post #38

I hear a lot about disabling the management engines... what about activating them for yourself?

Your computer could run Linux or Doom even while it's off!

The idea of gaining control of the management hardware like this is really exciting. Can anyone here comment on whether it could plausibly happen? I’m guessing it would require leaks from Intel because otherwise whoever develops the capability would presumably keep it close to the vest or sell it for major $ right?
Post reply on HN