Live data from Hacker News

Why is the latest Intel hardware unsupported in libreboot? (2017)

libreboot.org

91–100 of 132 posts

Re: Why is the latest Intel hardware unsupported in libreboot? (2017)

#91
post #4

Since Intel/AMD also designs the processor they can also put in backdoors beyond ME, microcode updates, etc. If you don’t trust proprietary blobs, I respect that. But you can’t trust proprietary silicon either.

Yeah, microcode updates are proprietary software too. The weird result is that if you want a system with no proprietary software, you end up having to use the original microcode which is burned onto the chip and counts as hardware.

It's not a perfect solution but maybe it's a reasonable place to draw the line, until we have open source hardware processors using RISC-V or something.

Re: Why is the latest Intel hardware unsupported in libreboot? (2017)

#92
post #3

By now, it's probably reasonable to assume that NSA, GCHQ, the FSB, the Third Department, and Mossad can all use that backdoor.

I wonder if they have to take turns on my PC. Maybe they kick each other off for a laugh.

mom says it's my turn on the RAT

Re: Why is the latest Intel hardware unsupported in libreboot? (2017)

#93
post #63

Earlier quoted context omitted.

Yea, that was disappointing indeed. After reading the first several paragraphs, I was hoping that the answer would be get an AMD processor instead of Intel , but nope. I hope that in the future some manufacturer(s) start making fully open source verifiably secure RISC-V (or ARM) processors, and that we have a migration over to that.

Feel free to call it a conspiracy theory, but I firmly believe the IME/PSP is an operation by one of those three letters. Intel Management Engine is abbreviated as IME, and AMD Platform Security Processor is abbreviated as PSP. Those are each same abbreviation as Input Method Editor, a mandatory keyboard input layer for East Asian languages, and PlayStation Portable, Sony’s game console which cryptographic security i…

This is conspiracy theory level stuff

Re: Why is the latest Intel hardware unsupported in libreboot? (2017)

#94
post #3

By now, it's probably reasonable to assume that NSA, GCHQ, the FSB, the Third Department, and Mossad can all use that backdoor.

Really? I am curious to know what observations or evidence you base your arguments/predictions on? Do you believe they have an (even better than 'post-Snowden leaks') search-engine like PRISM, but for private networks all around the world? Could a user tell it's happening? What signals would indicate this? Is it increased CPU usage disguised as a system process? And are you talking about mainstream proprietary OS'es…

> Could a user tell it's happening? What signals would indicate this? Is it increased CPU usage disguised as a system process?

Intel AMT allows redirecting graphics output and keyboard/mouse/USB input over network connection. It's like a hardware device connected to HDMI port to capture screen and to USB ports to send inputs, but it's built right into the motherboard. It doesn't spawn a process in the operating system or use resources to any meaningful degree. The OS knows about AMT only what the hardware tells it, if anything at all.

Unlike software-based remote desktop solutions (VNC, TeamViewer), it's independent from the operating system. As long as the system is connected to power, AMT can run. You can log into a fully shut down computer, power it on and see boot logos and access BIOS before the OS even begins to load. You can use AMT to install operationg system on a PC with completely empty hard drive by virtually attaching a CD/DVD or USB install media.

It's extemely powerful management interface, but it's close-sourced and has a history of serious security flaws.

Re: Why is the latest Intel hardware unsupported in libreboot? (2017)

#95
post #4

Since Intel/AMD also designs the processor they can also put in backdoors beyond ME, microcode updates, etc. If you don’t trust proprietary blobs, I respect that. But you can’t trust proprietary silicon either.

Yeah, microcode updates are proprietary software too. The weird result is that if you want a system with no proprietary software, you end up having to use the original microcode which is burned onto the chip and counts as hardware. It's not a perfect solution but maybe it's a reasonable place to draw the line, until we have open source hardware processors using RISC-V or something.

Then you have to accept all the bugs with the original...

Re: Why is the latest Intel hardware unsupported in libreboot? (2017)

#96
post #87

Earlier quoted context omitted.

> indicates that you haven't read much about Intel ME :/ I wrote in my comment: > I already know a little about Intel ME and proprietary silicon So yes this is true, I know only 'a little'. I have only understood that it is a small proprietary OS running underneath the user's OS. I guess from your comment I learned now that this means it is something you can only get at with a diagnostic tool, and it is outside the c…

> I have only understood that it is a small proprietary OS running underneath the user's OS. It's not running underneath the user's OS. Both Intel ME and AMD's equivalent run on on a completely separate processor; think of it as a small CPU hidden next to the main CPU. This means that, for instance, "increased CPU usage" will not happen.

> a completely separate processor; think of it as a small CPU hidden next to the main CPU

Damn that seems a sneaky strategy by Intel, especially since they retain the master key. So are all these big chipset manufacturers selling chips with this massive backdoor that not many people know about? Scary stuff.

Thank you for sharing this! If you know of any beginner-friendly sources on this, I'd be grateful to see those.

Do non-US based chipmakers like Samsung have a similar systems in their chips?

Re: Why is the latest Intel hardware unsupported in libreboot? (2017)

#97

After all this time, I'm still trying to work out what is in it for Intel and AMD to force these technologies into their chips with no supported option to disable them and then to be so secretive about what they're doing and exactly who has access to what. I'm not generally one for crazy conspiracy theories, but I have to wonder what is going on behind closed doors that this is still being done by both of the two big…

Negative press is still likely too small to register on business radar. They might be heavily lobbied by movie industries, as they need these features for DRM.

Re: Why is the latest Intel hardware unsupported in libreboot? (2017)

#98
Hypothetical: The keys are available one way or another, now anyone can sign firmware.

... Is this even worse?

Sure we can get our SPI programmers out and be sure whats on there, but what about 99% of all other users who are now exposed not only Intels potential abuse of ME, but all vendors and anyone who intercepts devices. I obviously don't like IME/PSP but perhaps the only safe option is to push for removal not opening.

Re: Why is the latest Intel hardware unsupported in libreboot? (2017)

#99
post #66

Earlier quoted context omitted.

There are modern alternative systems with an open firmware stack, for example the Talos II running Power9. Granted, it is not available as a cheap, slick and slim power efficient laptop, but it is real, only twice as expensive and very capable. https://en.m.wikipedia.org/wiki/POWER9 See performance benchmarks incomparison with AMD/Intel at: https://www.phoronix.com/scan.php?page=article&item=power9-t... https://www.p…

There's also the Blackbird which is even more affordable - https://raptorcs.com/content/BK1B01/intro.html . It's still sadly more than I could justify spending - for my non-portable needs I use a ~5 year old Intel NUC which was cheap as chips and still going strong. But if that ever changes a Talos POWER-based system is at top of my list. The Talos guys pop up in the comments on HN now and then and they're very pleas…

> https://raptorcs.com/content/BK1B01/intro.html

That motherboard + cpu bundle costs $1732 (plus shipping, I guess).

I mean... Okay, it's super cool, but... I doubt that most people can affort that.

Post reply on HN