3 ms·
True Key makes use of the Intel Management Engine (IME). It gives a hint at what Intel is up to with the IME. One of the intended uses is "identity protection",
by moppl 10y ago
True Key makes use of the Intel Management Engine (IME). It gives a hint at what Intel is up to with the IME. One of the intended uses is "identity protection", storing secrets like e.g. biometric data in the realm of the IME, and to ultimately get rid of passwords.
Considering the security concerns regarding the IME, I doubt that it is a good idea to hand your passwords over to Intel (ME). At least I don't want to support this technology by using apps that utilize the IME.
To read up on the IME there is a free book by one of the developers on it...
http://link.springer.com/book/10.1007%2F978-1-4302-6572-6 http://link.springer.com/book/10.1007%2F978-1-4302-6572-6
Inside is an entire chapter on Intel's identity protection.
- seanp2k2 10y agoInteresting that Apple is doing similar things with the embedded ARM stuff in the new touchbar MBPs.
- wyager 10y agoThe thing is that Apple actually has a pretty good track record for security and not violating the privacy or integrity of customers' products. I have a lot more trust in Apple doing this correctly. I'd be fine with Intel taking on secure computing, but there's been some pretty bad stuff with the IME (like sending data to the internet outside of user control when using intel NICs), so I'm skeptical of this approach (especially when they're talking about facial recognition as a security measure).
- paulddraper 10y agoiTunes
- wolfgke 10y ago> but there's been some pretty bad stuff with the IME (like sending data to the internet outside of user control when using intel NICs) That's also a typical concern about baseband processors - and Apple has a baseband processor integrated into their iPhones and iPads. OK, there is a difference: While for ethernet ports (and with a little bit more effor WiFi connections) you can at least theoretically analyze whether there is dubious traffic, this is nearly impossible for connections over mobile networks.
- wyager 10y agoThat's sort of the FCC's fault; it's very hard to get a high-bandwidth device certified under FCC regs (e.g. part 15) if it doesn't have a locked-down processor that controls radio functionality. See this article about the FCC intentionally/unintentionally locking down Wifi routers due to licensing requirements: https://www.wired.com/2016/03/way-go-fcc-now-manufacturers-locking-routers/ https://www.wired.com/2016/03/way-go-fcc-now-manufacturers-l... I'm sure if it were up to apple they'd be putting high-level radio functionality in the main CPU. It's cheaper that way, and matches with Apple's security/privacy-oriented marketing.
- moppl 10y agoJust to give an idea of how bad the stuff is with the IME, I recommend reading up Chapter 4 here: Intel x86 considered harmful by Joanna Rutkowska https://blog.invisiblethings.org/papers/2015/x86_harmful.pdf https://blog.invisiblethings.org/papers/2015/x86_harmful.pdf The IME is basically a second computer inside your computer, running as the most privileged component on the platform. It has privileged access to all components of the system, and runs as long as the computer is plugged in or has battery (even if it the computer is switched off). It is under the control of Intel, they decide what the IME does, and it can use the NIC as it pleases, unnoticeable for the host system. It can not be disabled, switched off or removed. The rootkit researcher Rutkowska described it as "an ideal rootkiting infrastructure".
- ddalex 10y agoEven if I would not consider "... considered harmful" essays as screamers for attention, I would still take detraction about ME with a grain of salt, because: * it's easy to counteract, just not use an Intel NIC * it gets a lot of scrutinity * Intel is quite open about what it does, short of releasing signing keys for the firmware * the mobile platforms have similar secure enclaves (think baseband processors on phones), which nobody actually audits All of these make me think Rutkowska found out that bashing x86 gets her attention, and now she uses it as a beating horse.
- Spooky23 10y agoWe need a "Rutkowska Hand-Waving Considered Harmful". This paper is a bunch of insinuation. It goes into great dramatic length to describe how Intel ME is more evil than AMT/vPro, which runs in the same service processor context, but then selectively uses the features of AMT and attributes them to ME. If we were talking about servers, this paper would be talking about how the service processors on HP servers could be used to build a "bad iLO" that phoned home or allowed unauthorized parties to access. Intel devices aren't "phoning home". These claims require evidence... I don't see a network capture. Activated AMT implementations will phone back to your home, and allow things like remote control, remote bricking, or remote repair of management software. Saying that ME is "an ideal rootkiting infrastructure" is a statement without a lot of meaning. You could make the same statement about Windows, Linux or any number of components in a modern computer.
- greglindahl 10y agoApple went a lot farther with the iPhone a few years ago.