Live data from Hacker News

“We have obtained fully functional JTAG for Intel CSME via USB DCI”

twitter.com

91–100 of 413 posts

Re: “We have obtained fully functional JTAG for Intel CSME via USB DCI”

#91

Companies like Intel, who are complicit in helping CIA or any intel agency (government, rogue or otherwise) infiltrate and exploit our systems - need to be held accountable by the market. Intel ME and the (assumed [0]) partnership with CIA to design and build this system - should be an absolute travesty blow to the integrity of their business long-term. Will you, as lead engineer or sys admin for your mission critica…

Seriously? A 4chan post?

While the ME is worrying for many reasons, there's absolutely zero evidence that the Intel ME contains a backdoor.

Backdoors don't stay hidden forever.

Re: “We have obtained fully functional JTAG for Intel CSME via USB DCI”

#92

One way to think of ME is, we all woke up one day and discovered we have had high resolution night vision spy cams installed in our bedrooms. The next realization is there is no way to turn them off or remove them. It’s posisble even moving won’t help. And yet we really don’t seem to care much. Lesser issues generate national outrage and high volumes of press coverage. Why? HN may be uniquely positioned to show us th…

> "Apparently, ME is the perfect combination of opaque, obtuse, and obscure. It’s not rocket science, but complicated enough it’s hard to explain well quickly."

The way I see it is Intel ME is a processor-level application that has full control of all computer activity and cannot be blocked or disabled and can be accessed and controlled remotely.

Would like to hear other people's opinions of what it is.

Re: “We have obtained fully functional JTAG for Intel CSME via USB DCI”

#93
post #91

Companies like Intel, who are complicit in helping CIA or any intel agency (government, rogue or otherwise) infiltrate and exploit our systems - need to be held accountable by the market. Intel ME and the (assumed [0]) partnership with CIA to design and build this system - should be an absolute travesty blow to the integrity of their business long-term. Will you, as lead engineer or sys admin for your mission critica…

Seriously? A 4chan post? While the ME is worrying for many reasons, there's absolutely zero evidence that the Intel ME contains a backdoor. Backdoors don't stay hidden forever.

Some would argue the entire design of ME is evidence that it IS a backdoor.

Re: “We have obtained fully functional JTAG for Intel CSME via USB DCI”

#94

Companies like Intel, who are complicit in helping CIA or any intel agency (government, rogue or otherwise) infiltrate and exploit our systems - need to be held accountable by the market. Intel ME and the (assumed [0]) partnership with CIA to design and build this system - should be an absolute travesty blow to the integrity of their business long-term. Will you, as lead engineer or sys admin for your mission critica…

> Intel ME and the (assumed [0]) partnership with CIA to design and build this system

I worked at Intel on ME and the things that came before it until around 2013. I can tell you two things --

1. No, Intel ME wasn't born out of a desire to spy on people nor was it -- to the best of my knowledge but I honestly believe I would know -- created at the request of the US government (or others). It was an honest attempt at providing a functionality that we believed was useful for sysadmins. If it was something done for the CIA, I believe it would probably have been kept secret instead of marketed.

2. It was initially going to be much "worse". Early pilots with actual customers -- such as a large british bank -- were going to run a lot more stuff -- think a full JVM -- and have a lot more direct access to the user land.) Security concerns scrapped those ideas pretty early on though.

In retrospect, I personally believe the whole thing was a bad idea and everybody is free to crap on Intel for it. But the thing was never intended as a backdoor or anything like that.

Re: “We have obtained fully functional JTAG for Intel CSME via USB DCI”

#95
post #32

At first it looks nice "oh now we can get rid of it" but it also opens up a very scary near future security-wise. We've now entered a realm where an attacker could simply plug a device on an usb port of your computer for a few seconds to have it access your cpu's ME through USB JTAG and take over it, allowing him to have full access and control over what you do/read/open/type over the network, without you ever knowin…

The 'evil maid' attack is well known, and states that once someone has physical access to your computer, all bets are off. Anything that has DMA enabled (e.g. Firewire or Thunderbolt) offers an external device direct access to the system RAM that is very difficult to defend against, or they could attach a keylogger or modify your bootloader, basically unleash all manner of havok. USB JTAG is really no different from…

> The concern with the Intel ME is that it has a native network adapter.

Yep, this is the big deal. After I "discovered" the ME, my first stop on my home network was the switch, to block all that crap. (And I found my storage server, equipped with a Supermicro all-in-one motherboard, helpfully grabbed an IP for the ME to listen on with an 'admin/admin' password.)

I just wish the empire builders at the NSA would care about something other than their own little power center. They knew this would happen - it always does. The NSA is probably the biggest security threat to the U.S. people[1] at this point, because they keep building concentrated, high-value targets and then lose control of them.

[1] Not to be confused with 'U.S. government interests'.

Re: “We have obtained fully functional JTAG for Intel CSME via USB DCI”

#96
post #91

Companies like Intel, who are complicit in helping CIA or any intel agency (government, rogue or otherwise) infiltrate and exploit our systems - need to be held accountable by the market. Intel ME and the (assumed [0]) partnership with CIA to design and build this system - should be an absolute travesty blow to the integrity of their business long-term. Will you, as lead engineer or sys admin for your mission critica…

Seriously? A 4chan post? While the ME is worrying for many reasons, there's absolutely zero evidence that the Intel ME contains a backdoor. Backdoors don't stay hidden forever.

That's a bad argument. Firstly, it's my understanding that there have already been root-access 0 days discovered in the ME (and since patched since exposed). AND The USB jtag backdoor is the whole point of this post.

Secondly, a security hole and a backdoor are interchangeable these days. So we'll never be able to prove which new 0-days are deliberate, and as far as impact it kinda doesn't matter if they're deliberate.

Re: “We have obtained fully functional JTAG for Intel CSME via USB DCI”

#97

I think many don't realise that DCI is not supposed to be activated on production CPUs.

Sure, but this makes it possible to dump the firmware for further analysis. I think that's the big news here. Think we might read about a few new bugs over the coming months. Also it might be possible to flash new firmware (to lock it down).

It's a nice thought, but I don't think it'll allow us to flash new firmware. We can already flash firmware on Intel chips, but the firmware has to be signed using Intels keys. The signing verification still happens on the mask rom which is impossible to overwrite.

Maybe this discovery will help us understand more how the verification step works. But I think the best we can hope for is a way of overwriting Intel ME very quickly after it's booted every time.

Re: “We have obtained fully functional JTAG for Intel CSME via USB DCI”

#98

Earlier quoted context omitted.

2013 was the greatest 'WE TOLD YOU SO' in history for the tin-foil-hat brigade...

Why 2013 specifically?

Presumably because of https://en.wikipedia.org/wiki/Edward_Snowden#Publication

Re: “We have obtained fully functional JTAG for Intel CSME via USB DCI”

#99
post #95

Earlier quoted context omitted.

The 'evil maid' attack is well known, and states that once someone has physical access to your computer, all bets are off. Anything that has DMA enabled (e.g. Firewire or Thunderbolt) offers an external device direct access to the system RAM that is very difficult to defend against, or they could attach a keylogger or modify your bootloader, basically unleash all manner of havok. USB JTAG is really no different from…

> The concern with the Intel ME is that it has a native network adapter. Yep, this is the big deal. After I "discovered" the ME, my first stop on my home network was the switch, to block all that crap. (And I found my storage server, equipped with a Supermicro all-in-one motherboard, helpfully grabbed an IP for the ME to listen on with an 'admin/admin' password.) I just wish the empire builders at the NSA would care…

Am curious how and what exactly you blocked?! What precautions can be taken to make systems more secure?!

Re: “We have obtained fully functional JTAG for Intel CSME via USB DCI”

#100
post #81
post #33

Earlier quoted context omitted.

I think you're being overly paranoid. If the attacker has physical access to the machine, chances are you're compromised anyway, even before this vulnerability.

As I said above; I think I didn't make my point clear enough: my concern was not about it making it easier to be comprised, but about it making the clean up pretty impossible, on a hardware level. Software do-over is a very well accepted solution (don't bother cleaning the rootkit, just format reinstall), but hardware do-over (change the cpu) is going to be a hard pill to swallow.

This was a problem even before Intel ME. Modern server motherboards (and several workstations) have a second Linux installation on your motherboard (known as a "baseboard management controller" or BMC) that cannot be removed. There have been many exploits found in the software running on BMCs, and if you want to "clean up" an infected server then you have to throw out the hardware if you want to be 100% certain.
Post reply on HN