5 ms·
The truth is that we can't trust INTEL. Their CPU micro-code or ME (Management engine) can and does "phone home" to the internet, grab updates and update the C
by HashThis 10y ago
The truth is that we can't trust INTEL. Their CPU micro-code or ME (Management engine) can and does "phone home" to the internet, grab updates and update the CPU. They don't allow the customer to turn this OFF, which betray's the customer who purchased the CPU. Anyone who can sign the update and intercept the download channel can update your CPU with you having no ability to protect yourself. We can't trust intel.
Intel needs to allow 3rd parties to build a small piece of hardware for private key storage, generation, signing and encryption, with self-distruction upon tampering. Then customers need to be able to go to the store, pick which vendor they want, and they plug it into their motherboard. By selling them in the store when the customer can make a surprise purchase, then that prevents tampering upon shipping withe ecommerce deliverables.
- akerl_ 10y agoWhat are some good resources to learn more about the phone-home functionality in their microcode? I've been trying to find more details and have been unable to do so.
- temptel 10y agoYou've been unable to find that information because no such "functionality" exists. Microcode just patches bugs or configuration details of the CPU; it doesn't "phone home".
- akerl_ 10y agoThat was my initial understanding, but I figured I'd give the parent commenter the benefit of the doubt in case my understanding was flawed. Some more searching seems to lead back to where I started: the microcode itself isn't phoning home, the only phoning "home" that occurs is the normal process of "when you pull down an update for something, it requires phoning to the repository holding the updates".
- micheljones 10y agoME does have ability to do that, tho.
- akerl_ 10y agoJust like IPMI, or any other standard for allowing hardware-level admin of a system.
- micheljones 10y agoBy using the word 'standard' you're trying to legitimize something that's fully encrypted, impossible to code-audit and fully under control of Intel, while pretending to be your property and controlled by you. So yes, it's a standard. I believe there was also a standard on how to tie a noose for hanging a human, but that didn't mean much to the one getting hanged.
- comboy 10y agoDo you think you could fit drivers for all common ethernet/wifi cards in there and proper TCP/IP implementation? It's below assembly abstraction level.
- moppl 10y agoThe ME is basically an independent universal computer in its own right, it comes with its own clock, RAM, CPU etc... It is like a Matryoshka doll sitting inside the Intel CPU of your computer. Therefore, yes, it can contain all of that. For further details see my other two posts.
- comboy 10y agoSorry I was just thinking about microcodes and you are talking about ME. Scary stuff indeed[1] 1. https://en.wikipedia.org/wiki/Intel_Active_Management_Technology https://en.wikipedia.org/wiki/Intel_Active_Management_Techno...
- Sephr 10y ago
- benchaney 10y agoHow could it possibly patch bugs without phoning home? Are you claiming that it is self modifying code?
- akerl_ 10y agoI wouldn't consider "running an update where it pulls new code" to be "phoning home", any more than my car is "phoning home" when I drive it to the dealership for repairs. The implication the comment I was replying to gave was that the device sent unexpected network traffic back to Intel HQ, with the connotation that it was doing so to leak information about my system.
- benchaney 10y ago"Running an update where it pulls new code" is definitely an example of phoning home, and it opens the door to all sorts of vulnerabilities, such as the one featured in the Apple vs the FBI case.
- twr 10y agoIntel microcode updates on Linux are provided through regular distribution repositories. There is no phoning home feature.
- benchaney 10y agoDo they get updated when you run the package manager, or do they update automatically?
- akerl_ 10y agoEither via the package manager or via the user manually downloading and loading the microcode update of their choosing. For example: http://askubuntu.com/questions/545925/how-to-update-intel-microcode-properly http://askubuntu.com/questions/545925/how-to-update-intel-mi...
- 10y ago
- jpalomaki 10y agoA more subtle way to communicate with the mother ship would be to ship an update that makes the CPU leak some desired information. For example change how some specific cryptographic operation works under certain conditions to make it possible for eavesdropper to break the encryption. Or just make some funny things with memory and make certain information available to be retrieved via web browser when user visits malicious page.
- dkraft 10y agohttps://www.wired.com/2015/02/nsa-firmware-hacking/ https://www.wired.com/2015/02/nsa-firmware-hacking/
- witty_username 10y agoSource on CPU micro-code phoning home?
- duskwuff 10y ago> Anyone who can sign the update and intercept the download channel can update your CPU with you having no ability to protect yourself. We can't trust intel. Intel's microcode updates are cryptographically signed; the CPU will not accept an update without Intel's signature. The format is not publicly documented, but independent research [1] suggests that it's 2048-bit RSA. [1]: http://inertiawar.com/microcode/ http://inertiawar.com/microcode/
- mtgx 10y agoThe nice thing about that is the Intel and NSA could just share that key and everyone would be none the wiser.