21 ms·
The Intel ME subsystem can take over your machine, can't be audited
- morganvachon 10y agoNice breakdown of how ME works, but nothing new here. Still, I'm glad I hold on to a ton of older, pre Core i-series Intel machines, AMD machines, and ARM boards. If ME is ever truly compromised at least I have a fallback or three.
- yuhong 10y agoIndeed, there was another recent HN thread on this: https://news.ycombinator.com/item?id=11880935 https://news.ycombinator.com/item?id=11880935
- rpgmaker 10y agoWhen people realize that it has been "truly compromised" it will be too late. The whole thing is a huge mess from a security stand-point.
- ashitlerferad 10y agoWatch out for TrustZone. There are definitely flaws in it too, for example: https://bits-please.blogspot.com/2016/06/trustzone-kernel-privilege-escalation.html https://bits-please.blogspot.com/2016/06/trustzone-kernel-pr...
- Grazester 10y agoSeems like this has already been patched
- SXX 10y agoYou use three different platforms and every have backdoors in it.
- morganvachon 10y agoName one that doesn't. Sorry, name a modern, useful hardware platform that is 100% guaranteed not to have a backdoor or vulnerability of some sort. It's about mitigating threats, because it's impossible to do more than that today. If you don't design and build the hardware yourself from the board and chips on up, it's not guaranteed to be safe. Even then, without being tested by the masses, you're bound to accidentally design a weakness in your system that you won't discover until you've been compromised. So yes, I'm happy that I have older platforms with known, documented, manageable vulnerabilities to fall back on should ME's mysterious, undocumented vulnerabilities become compromised by a bad actor.
- orbitingpluto 10y agoIn fact, I still don't see much of a reason to upgrade quad core Yorkfield Q9xxx servers except for cheap SSD upgrades. An 8 year old desktop still compares favorably to a $700 laptop (except, of course, for electricity).
- chriscappuccio 10y agoall intel chipsets since 2006 have had AMT/ME, including yours
- orbitingpluto 10y agoThank you.
- optimiz3 10y agoSerious question: are AMD chips a viable alternative (from a security standpoint)? I hear their new Zen chips are coming soon.
- yuhong 10y agoAMD PSP don't have access to the network (as far as I know).
- SXX 10y agoSource on that? If nobody prove it's have access to all system memory that doesn't mean PSP don't have these access. Otherwise it's will have at least MMIO-based access to the network controllers.
- williadc 10y agoNot really: http://www.amd.com/en-us/innovations/software-technologies/security http://www.amd.com/en-us/innovations/software-technologies/s...
- floatboth 10y agoWell, you can get processors from before these features existed – 2007 Intel chips or 2012 AMD chips — definitely AMD, 2012 isn't that old yet.
- LeoPanthera 10y agoDoes this apply to Macs?
- yuhong 10y agoI think it applies to everything using Intel processors.
- Khalos 10y agoFrom the article: "On some chipsets, the firmware running on the ME implements a system called Intel's Active Management Technology (AMT). This is entirely transparent to the operating system, which means that this extra computer can do its job regardless of which operating system is installed and running on the main CPU." So it sounds like yes, this would effect any OS.
- JumpCrisscross 10y agoI think they are asking if Apple ordered chips without this ME, give the former's penchant for security. I wonder similarly.
- Khalos 10y agoAh, fair enough. That is a good question.
- ploxiln 10y agoI'm pretty sure that, for the last few generations of Intel CPUs, the ME is not optional on any (non-Atom) model. https://www.reddit.com/r/linux/comments/3anjgm/on_the_librem_laptop_purism_doesnt_believe_in/ https://www.reddit.com/r/linux/comments/3anjgm/on_the_librem... https://puri.sm/posts/petition-for-intel-to-release-an-me-less-cpu-design/ https://puri.sm/posts/petition-for-intel-to-release-an-me-le... > All recent Intel systems (made in the last 8 or 9 years) has this. The ME will never be freed
- kawera 10y agoNot sure. ME requires coordination/support from other electronic components to do its job. It only applies to Macs if Apple's motherboards have the necessary circuitry (I couldn't find this info so far).
- Illniyar 10y agoThats crazy talk, in what world is it ok for my cpu to run a tcp stack on its own?
- yuhong 10y agoIt is in the chipset not in the CPU.
- Illniyar 10y agoMaybe I'm missing something, is this chipset on the motherboard? The article makes it seem like its coupled with the cpu.
- yuhong 10y agoYes.
- zf00002 10y agoI don't know how its actually implemented, but normally to enable AMT you have to have both a compatible motherboard and processor. Intel calls it VPRO. Most desktop consumer boards do not have this feature, but quite a few of the i5 processors do.
- Illniyar 10y agoOh, so not very frieghtning then.
- wtallis 10y ago> Most desktop consumer boards do not have this feature, but quite a few of the i5 processors do. Considering how many firmware updates I've installed on gaming-oriented motherboards with Z-series chipsets that have included ME firmware payload, it's worth looking in to what it means for those boards to not have the feature. We know that all the transistors are physically present on both CPU and chipset. Are they truly permanently disabled with on-chip fuses, or are they just left uninitialized on boot when the microcode checks the model numbers? Are there required traces on the motherboard that are definitely being omitted/disconnected?
- vasili111 10y agoWhat about AMD?
- khedoros 10y agohttps://libreboot.org/faq/#amd https://libreboot.org/faq/#amd AMD has some rough equivalents to Intel's ME.
- shmerl 10y agoWhy can't Intel implement proper security and open up this blob to begin with? Not opening it and not allowing to disable it, suggests it's intended for something sinister.
- yuhong 10y agoThis reminds me of the anti-theft features. The laptop anti-theft arms race is ridiculous.
- keyme 10y agoAs stated in the article, some researchers have managed to unpack it, and it can now be dissembled. You can't (and hpefully won't) be able to execute your own code there. There are 2 good reasons for this: 1) As per the article, to actually prevent ring -3 malware. The implemented signature is the best way to do this. If we could run our own "libre" code there, so could the attacker. 2) I bet this firmware controlls stuff like wether your CPU is "really" a Core i3 or Core i7, how many cores are activated, etc. Basically, its reasonable to assume that the silicon is the same, but what you pay determines the actual "unlocked" performance.
- duncan_bayne 10y ago> As per the article, to actually prevent ring -3 malware. The implemented signature is the best way to do this. If we could run our own "libre" code there, so could the attacker. That's completely false; allowing the execution of libre software doesn't worsen security, and the security-by-obscurity model doesn't improve it.
- JonathonW 10y agoCodesigning is "security-by-obscurity" now?
- duncan_bayne 10y agoNo, not that, the rest of it. I meant the fact that it's a binary blob which hasn't (recently) been subject to review by users.
- textmode 10y agoTaking another angle: What if the computer's owner wants to use it to access her computer remotely? Are there some instructions how to do this? Is it feasible? If not, then there seems little justification to have a relatively new feature like this turned on by default. Who is this feature really for? If it's not for all users then why is activation mandatory in CPUs after Core2? I mean, if ME has to be active, then the computer's owner should be able to use it, right?
- yuhong 10y agoI think it is intended for enterprises to enable.
- bhrgunatha 10y agoIf that's the case and enterprises ARE using it - why isn't it more widely known about? Even if the enterprise signs an NDA - I find it surprising that it hasn;t leaked given the security implications.
- yuhong 10y agoAFAIK Intel AMT is documented and has been since it was introduced in 2006.
- tmptmp 10y agoIt is intended for the "Intel defined enterprises" to be more precise. Ordinary Joe cannot declare him/her to be an enterprise and do so, unless he/she is willing to pay the Intel "thugs" an inordinate amount upfront.
- stephengillie 10y agoEnterprise console software is likely needed to interface with the chip. And this software is probably priced like most enterprise software.
- hrrsn 10y agoIt's marketed as Intel vPro. Pricing is probably typical enterprise level. This page has more details: http://www.intel.com/content/www/us/en/architecture-and-technology/intel-active-management-technology.html http://www.intel.com/content/www/us/en/architecture-and-tech...
- digler999 10y agoNo doubt various three-letter agencies are having a field-day with this right now. Hopefully a robin-hood type will reverse-engineer the blob and post a permanent fix to disable this thing before a more nefarious person/group uses it to devastate the PC landscape with something even worse than bitlocker.
- paulmd 10y agoIt's impossible to "reverse-engineer" a cryptographic signature. Properly implemented (and you can bet that Intel has had time to finalize this) it's computationally insurmountable.
- Dylan16807 10y agoNot the signature, the payload. It's very complex. I guarantee there are bugs.
- joe_the_user 10y agoIndeed, the blob can be reverse engineered. Even more, an unbreakable signature can have it's private key stolen by hacking, by agencies inserting personnel into the companies, by agencies blackmailing key personnel and by agencies compelling the companies legally or ex-legally to hand them their keys.
- zeta0134 10y agoReally, if someone has gone to the trouble of working out an exploit for Intel ME, the most ironic thing they could pull off would be to use that very exploit against Intel's own systems to steal their key, use it to patch the bugs, and release the patch to the world.
- Bartweiss 10y agoIt'd be a spectacular successor to that router-patching virus that made the rounds a while back.
- cocomutator 10y agoI still don't understand why this ME feature has been created to begin with. Assuming that breaking it is a matter of time (someone clever enough thinking about it for long enough), it seems like a serious security vulnerability, worse still because an attack is undetectable. Why create it in the first place? Are the enterprise uses the article mentions worth the risk?
- yuhong 10y agoYes, I think it was originally intended for enterprises doing remote management.
- khedoros 10y agoThe board needs vPro/AMT for things like remote access. If the board doesn't implement those things (and you'd usually know, because you pay more for them), the ME ends up doing...well, I'm not sure what. I think mostly things like enforcing DRM? Still, the machine needs special support on the motherboard and ethernet controller to enable the features that people are complaining the most about.
- endgame 10y agoWhere can people go if they want a fully-libre machine and are willing to sacrifice x86?
- mappu 10y agohttps://libreboot.org/docs/hcl/ https://libreboot.org/docs/hcl/ If you want to avoid the ME specifically, some other not-100%-libre options you might consider are the TALOS (high performance) or the ODROID C2 (low cost)
- b34r 10y agoArduino
- badsock 10y agohttps://www.raptorengineering.com/TALOS/prerelease.php https://www.raptorengineering.com/TALOS/prerelease.php It's quite expensive, and prerelease, but from what I heard it fits the bill.
- endgame 10y agoOutside of my price range but worth keeping an eye on. Thanks.
- kriro 10y agoPi-top like laptop with your choice of pi3 or BeagleBone running Linux. The performance of a pi3 is actually decent. It's not perfect as there's a GPU BLOB in the pi3 and the BB also has some issue. It's my compromise for now, hoping the blob will be reversed/replaced eventually. Or anything that runs libreboot: https://libreboot.org/docs/hcl/ https://libreboot.org/docs/hcl/ If OpenBSD runs on it that's also a good sign usually as they won't touch anything with BLOBs.
- endgame 10y agoI do actually on a Pi3, so that's an encouraging piece of info. A GPU blob is at least a step up from the ring-negative-3 management engine.
- deleted 10y ago[deleted]
- narrator 10y agoAlmost makes you want to get a Lemote Laptop like Richard Stallman.
- rekado 10y agoYou don't have to. Libreboot is available for some Thinkpads. I use an X200s. There are businesses that offer Libreboot flashing services or sell refurbished Laptops with Libreboot installed.
- yoo1I 10y agoExcept libreboot doesn't help. ME executes below BIOS/UEFI.
- SXX 10y agoThat's not the case. ME code is large and not bundled inside CPU. On old systems it's was possible to not provide ME firmware while keep CPU operational. On modern systems it's will just poweroff every 30 minutes if ME firmware not present and this is why libreboot won't support any newer hardware.
- jacquesm 10y ago> On modern systems it's will just poweroff every 30 minutes if ME firmware not present That's highly suggestive of a hidden agenda.
- kuschku 10y agoYou can still turn ME into "manufacturing test mode", where it will not execute things. But in that mode Intel Network Cards will poweroff every 3 minutes. I wondered why my I219-V didn’t work, until I found it worked with ME in normal mode. Now I’m back on a 2006 100M Realtek NIC
- 10y ago
- Animats 10y agoThe real question is what the firmware can be convinced to do remotely. Probably most of the things in here.[1] Remote management is supposed to be listening on TCP ports TCP 623 for HTTP and 664 for HTTPS. [1] http://www.dmtf.org/sites/default/files/standards/documents/DSP0232_1.1.0.pdf http://www.dmtf.org/sites/default/files/standards/documents/...
- aruggirello 10y agoAre you suggesting that detecting if your system is exposed to remote control is as easy as checking to see if your machine appears to have such ports open? And would the ports appear to be open if checked from the same machine?
- Animats 10y agoUnclear. There are issues such as what IP address the ME is using. IP addresses are an OS level thing, and the ME is below that. Ethernet controllers don't know about IP addresses. The ME has the ability to make DHCP requests, so it can get an IP address of its own.[1] The real question is what the ME does in addition to what it is documented to do. [1] https://software.intel.com/sites/manageability/AMT_Implementation_and_Reference_Guide/default.htm?turl=WordDocuments%2Fconfiguringtheintelamtipaddress.htm https://software.intel.com/sites/manageability/AMT_Implement...
- DiabloD3 10y agoI find people freaking out about this extremely strange. AMT is Intel's equivalent of IPMI. It is a non-standard implementation of it, and does not follow any of the relevant specifications. It does not integrate into most server management platforms. AMT costs extra. Most mobos do not have it enabled as you have to pay Intel's tax on it, even if some of the hardware to enable it is in every northbridge. A motherboard must implement it to be available. Most of the motherboards we own don't have it enabled. You cannot "break into it" if AMT isn't available on your motherboard to begin with. Not all ME chips can run it due to Intel's requirements. Now, is the ME chip a threat? Possibly, not not as much as your cell phone's baseband modem is. The baseband modem can talk to outside networks, ME can't unless it is paired with a NIC it can talk to (Intel does not require mobos that have this; and generally, motherboards meant for AMT ship Intel NICs, but not always). Without AMT, the only thing the ME does is implement management functions that allow you to actually boot and use the machine. In the article, it says "Personally, I would like if my ME only did the most basic task it was designed for, set up the bus clocks, and then shut off," except it is kept running so you can properly sleep and wake up your machine, and also be able to change CPU frequencies at run time (IE, idle the cpu), and also provide access to the sensors on the motherboard. In addition, the ME handles Intel Smart Connect, which is also not available on all boards (Apple uses this to implement Power Nap). It also requires licensing, the same way AMT does, and may mobo manufs simply don't want to license it. ME does not connect to the network if it doesn't have a payload that is able to do so (AMT, Smart Connect). The reason people don't understand what ME is for is because all of the basic tasks the ME does used to be done by lots of custom hardware, much of it not provided by Intel and different on every board, and somewhat a bit of a driver nightmare. I don't like standing up for Intel, but anti-ME articles that continually bring up AMT as if all computers have it is FUD. Very few computers have AMT, very few computers implement this OOB access, very few computers can implement AMT even if Intel let you purchase licensing for it after purchasing the hardware. I'm not saying that ME is not a security hazard (it can be in some cases), but it isn't some ultra awesome NSA backdoor bullshit. Your phone, however, does have the NSA backdoor.
- mappu 10y ago>Now, is the ME chip a threat? Possibly, not not as much as your cell phone's baseband modem is. The baseband modem can talk to outside networks, ME can't unless it is paired with a NIC it can talk to (Intel does not require mobos that have this; and generally, motherboards meant for AMT ship Intel NICs, but not always). The last ~dozen regular (gigabyte/asus/asrock/...) desktop PC motherboards i've seen have all used intel NICs for ethernet.
- arca_vorago 10y agoWhen it comes to hardware backdoors, one particular case seems to keep popping up in my mind, and that is Bill Hamilton of the infamous Inslaw/Promis octopus debacle. A few years ago when I was on Scheiers blog regular, he was claiming they had prearranged the backdoor installation at the silicon manufacturing level... Something about that has never left my mind, and I suspect its generally correct. Heres hoping that power8 workstation Talos gets off the ground...or some risc equiv.
- nitrogen 10y agoIs this the company you are referencing? https://en.wikipedia.org/wiki/Inslaw https://en.wikipedia.org/wiki/Inslaw
- arca_vorago 10y agoIndeed it is.
- deleted 10y ago[deleted]
- captainmuon 10y agoVery naively, I wonder what happens if you just call Intel and complain about this. Say you want a way to remove the ME completely. They won't help you, but I wonder how they will justify making it compulsory if pressed. Now if I call them, I wouldn't reach anybody important. But surely there are a couple of people on HN who are lawyers, CEOs, with the government etc.? If you have an imposing job and a few minutes to spare, I'd like to see what Intel has to say about this.
- confounded 10y agohttps://puri.sm/posts/petition-for-intel-to-release-an-me-less-cpu-design/ https://puri.sm/posts/petition-for-intel-to-release-an-me-le...
- techdragon 10y agoAnother lame petition won't get the same kind of results as a well connected question. The PR department lives to shield a company from such negative external noise, a well connected question can surface inside the company and be heard by people with the capability to actually do things.
- foodstances 10y ago> allowing Purism to provide this petition to our Intel Partner Account Manager It's at least worth a shot to see what they have to say about it...
- nl 10y agoThere are plenty of reasons why this is useful. See slides 7 and 8 from http://www.slideshare.net/codeblue_jp/igor-skochinsky-enpub http://www.slideshare.net/codeblue_jp/igor-skochinsky-enpub If this functionality is a good trade-off is a different question.
- Dolores12 10y agoNon-enterprise customers need not any of those. Hence they should be allowed to turn ME off if they wish so. That ME thing actually mean i don't have full control of my computer anymore. Anybody can access my hardware even when its turned off. Scary sh*t.
- oolongCat 10y agoBest way to deal with issues like this, make them care. How? we need to get this message to the masses, to get enough people know about this potential issue, that it becomes an organisational issue for Intel.
- kriro 10y agoJoanna Rutkowska has written a nice paper on the topic, highly recommended: http://blog.invisiblethings.org/papers/2015/x86_harmful.pdf http://blog.invisiblethings.org/papers/2015/x86_harmful.pdf Edit: There's also a talk from 32c3 for those more inclined to watch a video. I am pretty worried ever since I watched that: https://www.youtube.com/watch?v=rcwngbUrZNg https://www.youtube.com/watch?v=rcwngbUrZNg (which is why I have researched non-Intel laptop alternatives..cliffnotes: GPUs without BLOBs are hard to find and there will be some severe tradeoffs which is expected)
- SXX 10y ago> GPUs without BLOBs are hard to find Any devices without firmware are hard to find. Even if only some have option to upload firmware almost every device on market have closed-source firmware inside it: NICs, USB controllers, hard drives and especially modern SSD, sound cards, etc.
- creshal 10y agoNICs exist, occasionally: Atheros Wifi chips work with open-source firmwares. And it shouldn't be too hard to find a GBit ethernet NIC without. Everything else is a lost cause right now. Keyboards, mice, displays, … Everything is running proprietary firmware blobs.
- SXX 10y ago> And it shouldn't be too hard to find a GBit ethernet NIC without. Just wonder how exactly you going to check if hardware have firmware inside it.
- creshal 10y agoGood point. Usually the criterion is "can we send it a firmware blob? Can we send it an open-source firmware blob?". If you have a firmware that can't be replaced at all, it's usually handwaved away.
- rdtsc 10y agoI think this is time for AMD or IBM's POWER8/9 to step in. If anything a little good PR vis-a-vis the "rootkit nightmare waiting to happen in your server" would be nice.
- supbpeerr 10y agoAMD have their counterpart, called Platform Security Processor (PSP) see https://libreboot.org/faq/#amdpsp https://libreboot.org/faq/#amdpsp for more info.
- SXX 10y agoSince 2013 AMD have it's own technology called "Platform Security Processor" (PSP) which is ARM TrustZone core running signed closed-source code. It's efficiently have all the same access ME have. Of course any processor that have PSP support not going to work without PSP firmware.
- harshreality 10y agoIf you don't need high-end single-thread performance, RISC-V will help.
- edwintorok 10y agoSee "The World Beyond x86" presentation for a presentation of alternatives, focusing on POWER8: https://raptorengineering.com/TALOS/op_twbx86.php https://raptorengineering.com/TALOS/op_twbx86.php https://static.rpteng.com/TALOS/assets/the_world_beyond_x86.pdf https://static.rpteng.com/TALOS/assets/the_world_beyond_x86....
- rdtsc 10y agoThanks,that was a good presentation. Yap basically POWER for mid to high end and ARM for low to mid. And it looks like AMD has its own equivalent of ME...
- akerro 10y agoUnfortunately, AMD follows all bad and destroying trust practices that were developed in Intel.
- markokrajnc 10y agoIt may be, that Intel didn't plan this as an NSA/XYZ back door - but it doesn't actually matter. What matters is that we know 1) Intel has such technology implemented in allmost all desktops/servers currently running 2) you can access those machines remotely (even over GSM) and perform reads/writes. Example misuse: somebody can put illegal stuff on your machine and then sue you... (Intel has marketed this feature for big companies so they can format the HDD remotely over GSM in case laptop was stolen.)
- coderdude 10y agoThey can remotely wipe my stolen machines? That's the one cool thing I've heard. How come I haven't received that email in my spam box? Poor marketing attempt if that's what they're aiming for. I'm not running a huge company but they could at least try targeting the SMB sector (I think I qualify for that). I'm against the ME vector up until it's actually useful to me. P.S. fbi please don't hax0r me for commenting. Actually, go ahead, ya bastards.
- akerro 10y ago>1) Intel has such technology implemented in allmost all desktops/servers currently running Ever wondered why Google is working on their own CPU?
- macns 10y agoWondering - when that happens - if their firmware is open source but monitored for ad targeting should we be OK with it?
- wolfgke 10y agoFreedom 1 of the FSF is (https://www.gnu.org/philosophy/free-sw.html https://www.gnu.org/philosophy/free-sw.html): "The freedom to study how the program works, and change it so it does your computing as you wish" In this sense you should be able to change the firmware (since it is open source in the sense of the OSI definition) and remove the monitoring for ad targeting. If this is not possible, Google's firmware is not open source (see https://opensource.org/osd https://opensource.org/osd).
- nneonneo 10y agoIgor Skochinsky (of IDA Hex-Rays fame, among others) has been studying Intel ME for quite some time. He gave a nice talk at Breakpoint summarizing what he'd discovered (slides here [pdf]: https://github.com/skochinsky/papers/blob/master/2014-10%20%5BBreakpoint%5D%20Intel%20ME%20-%20Two%20Years%20Later.pdf https://github.com/skochinsky/papers/blob/master/2014-10%20%...). Among other things, he finds that ME is capable of running signed Java code which is pushed to the device. Due to the complexity and size of the Java code, it's quite likely to have bugs. ME is a bit scary partly because it's a totally closed-source and proprietary component of your computer with full and essentially unfettered access to everything - RAM, peripherals, and network I/O. Any bug in a publicly-accessible component would have the potential to do serious damage. For example, a bug in the network stack might make it possible for attackers to remotely own your box.
- jakeogh 10y agoVery interesting presentation. Is the video available? I had no luck with the standard searches. http://2014.ruxconbreakpoint.com/speakers/#Igor%20Skochinsky http://2014.ruxconbreakpoint.com/speakers/#Igor%20Skochinsky
- tim333 10y agohttps://www.youtube.com/watch?v=4kCICUPc9_8 https://www.youtube.com/watch?v=4kCICUPc9_8 seems to be basically the same talk given at Montreal rather than Melbourne
- Animats 10y agoME is capable of running signed Java code How much firmware is in the thing? Is there a whole JVM in there? An OS? That's a lot of attack surface.
- creshal 10y agoThe ME contains a fully-featured CPU and several MB worth of firmware. That should be able to fit a full Java ME, I think.
- 10y ago
- confounded 10y agoI'm very surprised that no-one on HN has talked about their experiences of using AMT for enterprise IT management. Aside from the security problems, I've personally never encountered or seen it's use, which makes the ME's inclusion (on all chips, for about 6 years) seem like an odd decision from Intel.
- wolfgke 10y ago> I've personally never encountered or seen it's use, which makes the ME's inclusion (on all chips, for about 6 years) seem like an odd decision from Intel. I consider it as quite plausible that the reason why Intel included ME into all chips is that it is much cheaper to add those unnecessary gates to any chip than to create two different versions of it. The much more interesting question is why ME cannot be disabled. It is clear (see http://www.intel.com/content/dam/doc/product-brief/mobile-computing-protect-laptops-and-data-with-intel-anti-theft-technology-brief.pdf http://www.intel.com/content/dam/doc/product-brief/mobile-co...) why Intel has a reason why ME should not be possible to disable on some chips. I can imagine that Intel fears that if it can be disabled on some chips, hackers will find a backdoor to also disable it on those chips where it shouldn't be possible.
- acqq 10y ago> it is clear why Intel has a reason why ME should not be possible to disable on some chips. Only "under some conditions" should not be possible, that is, once you as a user turn on the anti-theft protection. Theoretically, turn-on-once, afterwards-no-turn-off technology can be implemented.
- Dolores12 10y agoIt could be hardware switch on motherboard.
- andrewaylett 10y agoMy previous employer used it, and it was pretty useful. When we got a new PC, we'd enroll our local keys by booting with a USB drive with the keyfile in the root of the filesystem. The firmware would offer to enroll the keys, after which (remote) sysadmins could remotely administer the machine through AMT -- basically a remote KVM. The firmware has an on-screen indication that's happening, so it couldn't be used for spying. Plus for most day-to-day purposes, we could use AD to administer the machines (which probably could be used for spying, if that were necessary). But when things broke enough that AD stopped working (or when first setting up a box), much of the time AMT meant that we didn't need a physical presence to fix them again.
- elchief 10y agoHas anyone on here actually used this at work?
- hoodoof 10y agoStrange that Intel gives people more reason to go to other processors like ARM when Intel is under such pressure from competition.
- PythonicAlpha 10y agoSuch decisions are not made in the face of pressure. I think, they are made years ago and now they are (still) executed. In the corporation centers, nobody thinks of critical users that look very carefully on things. They mostly think about the average user, that just wants more "power".
- ferbivore 10y agoWho does this give reason to move to ARM? End-users generally don't have a choice (good luck running AutoCAD on ARM) and OEMs either don't seem to care or list ME as one of the selling points of their systems. You could make the case that this might convince people to use AMD CPUs, but from what I hear AMD has all the same issues with worse performance to boot.
- Dolores12 10y agoI am pretty sure you can run VirtualBox on Linux. And you can run Linux on ARM.
- kevincox 10y agoBut VirtualBox doesn't emulate different instructions sets, so you would have to run ARM windows inside of it and an ARM build of AutoCAD (which I don't believe exists). Also I'm not sure that VirtualBox supports ARM at all.
- therealjumbo 10y ago>AMD has all the same issues with worse performance to boot. AMD chips aren't just slower to boot, they're slower overall!
- 10y ago
- wfunction 10y agoCan someone tell me if people have actually spotted the Intel ME doing unauthorized communication? I imagine it should be easy to spot in any network firewall log (note I said network, not OS), and in reality, if it's never been observed to communicate with the outside world without explicitly being told to then do people really need to worry?
- deleted 10y ago[deleted]
- hoodoof 10y agoIf you get a microscope and manage to peer into this secret hidey hole in the CPU you will see a bunch of tiny little NSA spooks, Russian and Chinese hackers scuttle away to hide in other dark hidden secret corners of the Intel CPU.
- goodplay 10y agoYup. It's a good thing that we live in a universe where companies and all their employees are completely trust-worthy, and will flat-out refuse to do something illegal if asked (or incentivised) by others. It's a good thing that all governments act within the confines of the law (both wittingly and otherwise). It's a good thing that all software we write is correct and sound, and that no bug ever existed nor the desire to exploit such a bug should it have existed. Paranoid people with their tinfoil hats. Shesh!
- bArray 10y agoMy question is whether alternatives are secure, such as AMD or ARM? I imagine the ARM architecture to be too scrutinised and low power to get away with that sort of thing? Personally I want to buy a laptop that is secure due to travelling to questionable places, I am wondering now whether it will include an Intel CPU in light of this.
- SXX 10y agoAs mentioned in comments already they are both not secure: every new AMD CPU have ARM TrustZone core in it. For ARM I can't tell since there might be SOCs without TrustZone. Best usable hardware is old Intel laptops except you want something like MIPS laptop from Lemote.
- bArray 10y agoThanks, I'll check it out.
- lazyjones 10y agoPossibly the Loongson 3B (https://en.wikipedia.org/wiki/Loongson#Loongson_3B https://en.wikipedia.org/wiki/Loongson#Loongson_3B - MIPS64 with hardware-assisted x86 emulation) - but someone has to take a closer look and audit it first.
- bArray 10y agoLooks promising, I'll keep my eye out for machines with this processor.
- happycube 10y agoAmusingly, the ARC core in the Intel ME is a descendant of the SNES SuperFX chip.
- Thoreandan 10y agoI was quite tickled to read that bit. The guy who made Starglider for the Atari ST, and Star Fox! :-) Apparently newer chips have had other architectures, at least one I think was actually SPARC.
- sspiff 10y agoI knew about ME, but I didn't know it had an ARC processor in it. Odd that Intel didn't opt for an in-house design, like one of their older cores backported to a newer process. (like a P54 or 386).
- Philipp__ 10y agoAnd this is why monopoly of one giant monolith is bad, in any area or case! They get to the whatever the f they want! It's not like everything is made today to track, and give access to "authorities" when they want it. But what really drives me mad is that I feel tricked! You put trust into someone and it's work, and give them money for that, but they do this, without you even knowing. I was always making fun of sworn GNU guys, always thought they were overblowing things out of the context. But maybe they were on the track! Anyhow, I want more competitive CPU space, we need AMD to get back into game, IBMs Power9, ARM, anything. But as things are standing right now, we won't see that anytime soon.
- jug 10y agoI think AMD and ARM have similar features though. ARM with TrustZone for example, hiding the "secure world" from knowledge by the "normal world".
- Philipp__ 10y agoYeah I thought so, but I hoped competition would make things different, where one of leaders would go like full transparent, without these "spy" sectors, and it would give it edge over others. And it's not about securing, it's about control! Who owns the thing I bought, that I use. It's not only they can watch, but now they can control whole computer. That's what bugs me the most. :(
- Natanael_L 10y agoSee the USB Armory, which gives you the keys to control the TrustZone system (or rather, you give your public key to it so that it will only run code YOU signed).
- tremon 10y agoTrustzone in itself is not closed though, and FAFAIK is not a separate engine. Trustzone is more like IOMMU on steroids, and runs on the main processor (it relies on hardware support to fence off system resources).
- fineforyouo 10y agoI wish the European Commission study this problem and if found guilty impose a fine in such a way and quantity that in no way those firms can continue exposing their clients to possible economic damage. The previous imposed fine was of EUR 1.06 billion. Someone with the required knowledge should submit a detailed record of this potential hazard to the European Commission emphasizing how this system could expose clients to possible threats, its anticompetitive nature, since it could allow hackers gain access to economic secrets, and many other important points. The FSF should stand up and speak clearly. I hope and wish that the FSF execute its mission, that is to gain and gather the necessary strength to expose the nature and extend of these problems and how to fight against them. Those that impose on us tools that allow them to control our business, steal our ideas and plans, and ruin our enterprises plaguing with chaos. Those that thrive to submit our future to their will should be fined. I certainly hope that a new economic fine be imposed. That initiative and measure would set up a strong message and a new precedent targeted to those threating our liberty and economy. A message encoded into an economic hammer with the power to make them shape their will to respect our freedom and integrity. To be Free and Survive we should Fight. FSF.
- touristtam 10y agoUnfortunately even these kind of fines are still pocket chance for such large corporation. Moreover, this is always the same issue of imposing a penalty without offering an alternative. In this case offering a hardware/software platform competing with the long established Wintel.
- throw2016 10y agoThis adds a whole new dimension to 'Intel Inside'. It says exactly what anyone needs to know. If it's for enterprise features as 'innocently' suggested that those who do not need or want this feature should be able to put it off simply without drama, debate or discussion. Its not surprising that both AMD and ARM have it. This is an orchestrated effort signifying the win of paranoia and security over privacy in the western world. This war is being fought on too many fronts by well resourced and paranoid security agencies with all the tools to influence and the only defense would be individuals and our sense of right and wrong. But it seems individuals have been completely disempowered and reduced to survival mode and are not in a position to stand up for the right thing or even talk about it. If 'moral' individuals can so easily be quietened in well off economies then one wonders what happens in other economies where basic survival is a day to day fight. Who will fight the privacy war? The silence is deafening. It seems all the activism and racket from media, academics, NGOs and human rights organizations only come into play when a western political or strategic objective needs to be met. There are many who believe that by working with and supporting security agencies they are somehow in the forefront of a nebulous fight of survival and freedom in a dark world. This 'dark world' is a self created and self serving fantasy and comedy for grown, well adjusted and well read individuals to fall for that push humanity into a negative space. It can be taken for granted unless conclusively proved otherwise with the burden of evidence swaying the other way that any technology coming out of the USA and Europe is compromised completely and the fight for privacy here has been lost.
- AnthonyMouse 10y ago> the win of paranoia and security over privacy The win of paranoia over security and privacy.
- qb45 10y agoThis cruft doesn't need three letter agencies to exist. Big customers pay for it so it's done. Once it's done, it's easier to leave it there and soft-disable for people who haven't paid for it than to actually build two versions of the chip, with and without this feature. However, speaking of spooks, I heard rumors that either Intel AMT or BIOS or some drivers (don't remember which exactly) is sold to the Chinese market with castrated crypto. Reportedly it's because the Chinese government requires imported crypto to be just strong enough to resist average guy, but not their supercomputers.
- ohitsdom 10y agoMaybe I missed it in the article, but why is this only present on x86 chips? How do 64-bit processors from Intel offer the same management functionality without this ME subsystem?
- qb45 10y agoExcept for the Itanic (is this thing still made?), 64-bit processors from Intel are x86 ;) It's common to apply this label to x86-64 too, in other words.
- schlowmo 10y agoIn this case x86 means both 32bit x86 (also referred as IA-32) and x86_64. From https://en.wikipedia.org/wiki/Intel_Active_Management_Technology https://en.wikipedia.org/wiki/Intel_Active_Management_Techno... "The Management Engine (ME) is an isolated and protected coprocessor, embedded as a non-optional part in all current (as of 2015) Intel chipsets."
- deleted 10y ago[deleted]
- hugdru 10y agoOh my god it began with the oems installing a bunch of spyware on the default install. Many of which with vulnerabilities. Not to mention "modern" OSes not respecting users privacy. To make matters worse the hardware companies decided to follow suit and thus added unwanted and compromising features to everyday systems. Way to go! It seems I'll have to switch to stone age hardware just to have a little peace of mind. Evolution! >(
- whamlastxmas 10y agoThis has been in every Intel CPU since 2008
- oneplane 10y agoWhile that article is correct, it's full of FUD with the constant littering of 'secret' and 'take over' in the text. We already know about Igor's research and the published ARC CPU reverse engineering, "Ring -3" rootkits and the DEF CON presentations. This is bad, and this needs even more reverse engineering so at some point we might add an 'open' replacement for the required ME functions and run it together with say, LibreBoot/CoreBoot. I wonder why there haven't been any NDA ME or ARC docs leaked yet, even some of the Broadcom SOCs had those leaked and via cleanroom design proper FOSS drivers for some of the wireless parts were created... this should be possible with the Intel ME as well. Hell, even a FOSS version or at least partially reverse engineered and modified version of laptop EC firmwares have popped up on the 'net.
- more_corn 10y agoYeah, the language is a bit excessive, but this is downright terrifying. Given the absurd security protections implemented in IPMI I can't imagine the successor being trustworthy enough to satisfy serious security requirements. Anyone remember the infamous cypher zero bug/feature in IPMI where you could specify an undocumented connection encryption mode which made authentication optional?
- brudgers 10y agoThe thing about scale is that it doesn't look like ordinary individual experience. It ain't enough to run Core2/\Piledriver/\Power/\open source microcode: ME enabled computers are connected en masse to the network. The choices are air gap or head in the sand. ME was inside before Snowden. Google, Facebook, Amazon, Ebay, Microsoft,, 百度 etc. buy Xeons by the bucketful. They're Intel's customers that matter. The retail box that comes with a fan for sale at NewEgg is just exhaust fumes. 42 or "It's the cloud": take your pick. Managing a gazillion server data center by hand just ain't practical. Intel's customers that matter replace CPU assets on the IRS's three year depreciation schedule. It's why this [0] and why ME. Security by obscurity isn't so bad when dumping the vulnerable subsystem lowers overall costs for other reasons [performance boosts and lower power consumption]. ME is a good reason that Microsoft has been striving toward multiplatform. It no longer has such a big say in Intel's roadmap. Yes UEFI and the Windows 10 upgrade process kinda suck, but Microsoft ain't pwn'ing anyone's computer because Intel already pwn'd it. ME going sideways at scale would hurt and Microsoft would be the handy victim. There's a strategic reason Apple is making it's own chips. [0]: http://www.techspot.com/review/1155-affordable-dual-xeon-pc/ http://www.techspot.com/review/1155-affordable-dual-xeon-pc/
- ssebastianj 10y agoI wasn't aware about Intel ME until recently bought a brand new Lenovo ThinkPad and saw the "Intel Management Engine" on BIOS/UEFI boot menu. The thing is: how can I configure this ME thing in order to avoid (or minimize, at least) possible attacks?
- foodstances 10y agoYou can't. The whole point of the thing is that it can't be disabled and will always be running to let your theoretical IT department take over your machine.
- effie 10y agoI got ME disabled in BIOS on my Lenovo S30 (manufactured around 2012 I think). Do you think this option in BIOS setup insufficient to turn it off? Is the ME still running and listening to commands coming from the network?
- pmarreck 10y agoYo dawg...
- milkey_mouse 10y agoFinally, the ME is getting the exposure it deserves. Seems like just two weeks ago nobody knew it existed.
- SeanDav 10y agoOnce a malicious 3rd party gets the keys to this kingdom it is game over.
- corndoge 10y agoPreviously: https://news.ycombinator.com/item?id=10458318 https://news.ycombinator.com/item?id=10458318 (233 days) https://news.ycombinator.com/item?id=11422531 https://news.ycombinator.com/item?id=11422531 (73 days) https://news.ycombinator.com/item?id=8813029 https://news.ycombinator.com/item?id=8813029 (534 days) https://news.ycombinator.com/item?id=11880935 https://news.ycombinator.com/item?id=11880935 (5 days) Among many, many others...
- ksk 10y agoI think at this point pretty much anything on your PC is backdoorable. I can't think of a single device in my computer that doesn't respond to "magic I/O packets" which are undocumented (obviously) and prone to bugs (possibly). Gaming mouse? Yeah send some I/O packets and you can change the DPI, USB update rate, whatever. A write-protected USB device? Uh-huh, send some magic-packets to the controllers to reset it/format it/whatever (Recently did this with one of those Dell USB Mentor Media drives that they ship the OS on). Access point? Yeah, send some magic packets and you can set the password/SSID/whatever. Hard Disk? undocumented SATA commands allows for reprogramming. This is just the 'easy' way, without going into JTAG and other diagnostic interfaces.
- jorblumesea 10y agoIt's probably safe to say that every device you own or ever owned has a back door, intentional or not. The false sense of security people had about their machines was a myth, glad to see it finally die.
- nthcolumn 10y agohttp://www.tomshardware.co.uk/vpro-amt-management-kvm,review-32283-7.html http://www.tomshardware.co.uk/vpro-amt-management-kvm,review... jesus wept, how do I turn it off?
- slasaus 10y agoFWIW, there is a petition for Intel to release an ME-less CPU design: https://puri.sm/posts/petition-for-intel-to-release-an-me-less-cpu-design/ https://puri.sm/posts/petition-for-intel-to-release-an-me-le... (as mentioned in a comparable thread five days ago: "Intel and ME, and why we should get rid of ME" (fsf.org) https://news.ycombinator.com/item?id=11880935 https://news.ycombinator.com/item?id=11880935)
- EdSharkey 10y agoThe fact that the ME microcontroller can run arbitrary Java code, uploaded at runtime rather than read from ROM is pernicious. The intel private key can sign any blob, and ME would run it. It makes me wonder, could an Java program uploaded to ME crash it or put it into an infinite loop? What would the effect be on the host OS if ME suddenly became unresponsive? Perhaps a "Kill ME" binary could be developed as open source, and perhaps we could get Intel to sign it? If there was a strong enough request to Intel by consumers, why wouldn't they go ahead and sign it for us? No skin of their noses what we do with our consumer-grade boxes, right?
- xlayn 10y agoI would use thunderbolt as it has DMA, create a CRC/F(x) cpu (external unit connected thru thunderbolt) that converts/encrypt code/data to a expected format by modified code generated by a compiler. making act the intel cpu as surrogate to it, delegating control to the CRC/F(x) cpu. Extra points, make all the cpus work, and create extra tasks to run at the non used cpus to obscure the actual process running (yeah I know it's not energy efficient but someones has to give Intel inspiration to improve).
- dingdingdang 10y agoOne thing, OK, so we have this super fantastic network enabled Java platform running autonomously from within around 3 billion devices across the globe since 2006 with the capability to read everything from the systems they are running completely unnoticed.. shouldn't this generate a FAIR amount of network traffic (and resulting suspicious log files, if not on the computers then on the routers) or am I missing something here?!
- niftich 10y agoMost are not enabled/activated or connected through the NIC.
- dingdingdang 10y agoOK (sources on that being the case?), but the issue then remains that we have no way of knowing whether it is activated or could be activated, is that correct?
- niftich 10y agoSure, here's some documentation on how to enable remote management in the Intel Management Engine, if it's supported: [1] http://www.tomshardware.com/reviews/vpro-amt-management-kvm,3003-6.html http://www.tomshardware.com/reviews/vpro-amt-management-kvm,... [2] http://www.howtogeek.com/56538/how-to-remotely-control-your-pc-even-when-it-crashes/ http://www.howtogeek.com/56538/how-to-remotely-control-your-... [3] https://communities.intel.com/thread/21261 https://communities.intel.com/thread/21261 The lack of independent audit of this chip and firmware is legitimate concern. But as you can see, if you obtain a fresh computer with access to the BIOS/UEFI, you have control over whether this functionality is enabled. If you don't have access to your BIOS/UEFI then you're correct that you won't know if it's on.