4 ms·
Interdiction could happen with open source hardware too. Swipe the SoC, and no one would be the wiser. Given everything that has to be in place for vPro/the ME
by Sanddancer 10y ago
Interdiction could happen with open source hardware too. Swipe the SoC, and no one would be the wiser. Given everything that has to be in place for vPro/the ME to work, looking at the pcb would give enough information to tell exactly how much, if any, information it could steal, if all the malicious items were in place. All of which could be easily undone by reflashing it, because the write line on the bios is not controlled by the CPU. A lot of steps have to be done, physically and in software in order to exploit it, and that exploit would melt away on the first bios flash. I'd be much more concerned about the security of the software running on the system than any theoretical hack on the ME.
- Karunamon 10y ago>Swipe the SoC, and no one would be the wiser. It would have to get swiped on the way from the manufacturer to the OEM. Once the OEM has sent it out, it's protected against this exact kind of attack. And while it may make sense for interdiction of a single package to a known target, doing the same with an entire batch of chips seems prohibitively expensive. >Given everything that has to be in place for vPro/the ME to work Again, per Intel's documentation. For all anyone here knows, data exfil begins the moment a certain sequence of bits crosses the right registers - and it's not like this is beyond the capabilities of what ME lets you do. There is no good reason that the entire subsystem can't be disabled by the user, permanently. But, come to find out about it, the chips are configured to shut the system down within 30 minutes if the ME firmware doesn't pass checksum. That, in my mind, puts it uncomfortably close to malware territory. Every one of these concerns evaporate if the ME area could be wiped or dumped - it's not as if remote management is some secret competitive advantage.
- Sanddancer 10y agoNo, this is not per the documentation, this is per the physical specifications, the circuitry that needs to be in place, the support that needs to be in each component. The Management Engine is not as all-seeing as you make it out to be.
- bwindels 10y agoFirst time I hear this. Can you elaborate or give a source for this?
- Karunamon 10y agoIt's all seeing enough to poll the installed system for info on installed software, to have keylogger rootkits installed in it, and so on. This is all per the (exhaustively sourced) Wiki article. The point I'm trying to convey here is that every piece of information available on this thing comes straight from the horse's mouth, and the horse is not necessarily a trustworthy actor.