Live data from Hacker News

Why is the latest Intel hardware unsupported in libreboot? (2017)

libreboot.org

81–90 of 132 posts

Re: Why is the latest Intel hardware unsupported in libreboot? (2017)

#81
It would be nice if all these Intel engineers that comment on all kinds of social and technological issues also commented on these topics regarding their company. Last time that I asked one of them if there is any plan to let us disable ME or make it foss I got no reply.

Re: Why is the latest Intel hardware unsupported in libreboot? (2017)

#82

Earlier quoted context omitted.

No SSL => MITMer can definitely read your traffic trivially. Broken SSL => MITMer can possibly negotiate insecure and read your traffic anyway. MITMer can also possibly cause a denial-of-service, or get arbitrary code execution on that one chip that controls your entire CPU . If I had to choose, I would take the first option. (This precludes options like removing the IME entirely, or updating it to a version with non…

I'm coming from a place of good faith here so bear with me. My understanding is that any vulnerability here would also exist in accessing any HTTPS website. I'm assuming you wouldn't choose to browse the web without SSL/TLS, so I'm assuming the difference here is that it's the CPU management chip instead of your browser? I suppose that if you broke SSL/TLS you could commandeer arbitrary AWS/GCP/Azure instances. For t…

My browser is sandboxed. The worst it can do is ransomware my files – and the Tor Browser can't even do that thanks to the AppArmor rules. (If I set my machine up properly, it wouldn't even be able to ransomware my files.)

The CPU management chip can ransomware my files while the computer is "off", corrupt my backups as I load them, steal my passwords, steal my bank details, dynamically modify the traffic to make it look like my bank balance hasn't gone down

Re: Why is the latest Intel hardware unsupported in libreboot? (2017)

#83
post #69

Earlier quoted context omitted.

The mere fact that you would expect a system process or anything else visible to the operating system, indicates that you haven't read much about Intel ME :/

> indicates that you haven't read much about Intel ME :/ I wrote in my comment: > I already know a little about Intel ME and proprietary silicon So yes this is true, I know only 'a little'. I have only understood that it is a small proprietary OS running underneath the user's OS. I guess from your comment I learned now that this means it is something you can only get at with a diagnostic tool, and it is outside the c…

Usually, snark remarks like "really?" mean that all venues for learning are excluded. Why would someone step in to teach in this case?

Re: Why is the latest Intel hardware unsupported in libreboot? (2017)

#84

Earlier quoted context omitted.

> indicates that you haven't read much about Intel ME :/ I wrote in my comment: > I already know a little about Intel ME and proprietary silicon So yes this is true, I know only 'a little'. I have only understood that it is a small proprietary OS running underneath the user's OS. I guess from your comment I learned now that this means it is something you can only get at with a diagnostic tool, and it is outside the c…

Usually, snark remarks like "really?" mean that all venues for learning are excluded. Why would someone step in to teach in this case?

> Usually, snark remarks like "really?" mean that all venues for learning are excluded. Why would someone step in to teach in this case?

Text does not translate intention well... It was a 'really?' filled with curiosity, and an eagerness to try to understand what the original poster was basing his statements on (that the NSA and others can all use this backdoor). I feel that there is within me an eagerness to learn more. It was not meant as a snarky comment at all. Thanks for telling me how my comment came across to you! (not snarky again.)

Re: Why is the latest Intel hardware unsupported in libreboot? (2017)

#85

This is why I have an Apple Powermac G5 or two stored in my basement. These run entirely free of that backdoor.

Can you build a modern browser to run on PPC? Say, latest fully patched firefox? Because using the browser that comes with Ubuntu 16.04 is not an option, security wise.

Re: Why is the latest Intel hardware unsupported in libreboot? (2017)

#86

Scrolling up they recommend avoiding Purism hardware because > In particular, the Intel Management Engine is a severe threat to privacy and security, not to mention freedom, since it is a remote backdoor that provides Intel remote access to a computer where it is present. However, the Intel ME has been disabled in Purism hardware since 2017. https://puri.sm/posts/purism-librem-laptops-completely-disab...

Pretty sure that write up was done around 2009

[deleted]

Re: Why is the latest Intel hardware unsupported in libreboot? (2017)

#87
post #69

Earlier quoted context omitted.

The mere fact that you would expect a system process or anything else visible to the operating system, indicates that you haven't read much about Intel ME :/

> indicates that you haven't read much about Intel ME :/ I wrote in my comment: > I already know a little about Intel ME and proprietary silicon So yes this is true, I know only 'a little'. I have only understood that it is a small proprietary OS running underneath the user's OS. I guess from your comment I learned now that this means it is something you can only get at with a diagnostic tool, and it is outside the c…

> I have only understood that it is a small proprietary OS running underneath the user's OS.

It's not running underneath the user's OS. Both Intel ME and AMD's equivalent run on on a completely separate processor; think of it as a small CPU hidden next to the main CPU. This means that, for instance, "increased CPU usage" will not happen.

Re: Why is the latest Intel hardware unsupported in libreboot? (2017)

#89
post #69

Earlier quoted context omitted.

Really? I am curious to know what observations or evidence you base your arguments/predictions on? Do you believe they have an (even better than 'post-Snowden leaks') search-engine like PRISM, but for private networks all around the world? Could a user tell it's happening? What signals would indicate this? Is it increased CPU usage disguised as a system process? And are you talking about mainstream proprietary OS'es…

The mere fact that you would expect a system process or anything else visible to the operating system, indicates that you haven't read much about Intel ME :/

I agree with @thulecitizen here, in that his questions were not met constructively. You could have posted a few words and a link or 2 for a newbie.

Re: Why is the latest Intel hardware unsupported in libreboot? (2017)

#90
post #63

Earlier quoted context omitted.

Yea, that was disappointing indeed. After reading the first several paragraphs, I was hoping that the answer would be get an AMD processor instead of Intel , but nope. I hope that in the future some manufacturer(s) start making fully open source verifiably secure RISC-V (or ARM) processors, and that we have a migration over to that.

Feel free to call it a conspiracy theory, but I firmly believe the IME/PSP is an operation by one of those three letters. Intel Management Engine is abbreviated as IME, and AMD Platform Security Processor is abbreviated as PSP. Those are each same abbreviation as Input Method Editor, a mandatory keyboard input layer for East Asian languages, and PlayStation Portable, Sony’s game console which cryptographic security i…

Ok, I'll bite. I call it(the chosen names) a conspiracy theory. I'll explain.

Search for "intel me" or "amd psp" or "ime psp" and you will find what you're looking for. If you're reading about it or hearing about it you will most likely also know the brand or the company behind it. If you're searching for psp and only find Sony stuff then of course you will repeat your query with more context. Is that not the first thing you will learn when you google something?

More importantly, they could have chosen much better words/abbreviations for not being "googleable". But they didn't because the IME/PSP is also something they sell to enterprise customers and very openly so.

Don't get me wrong. I'm still skeptical if those features are needed on consumer hardware and of the intentions behind it but the name being intentionally hard to search for is not something I'm worried about.

Post reply on HN