3 ms·
Just to give an idea of how bad the stuff is with the IME, I recommend reading up Chapter 4 here: Intel x86 considered harmful by Joanna Rutkowska https://blo
by moppl 10y ago
Just to give an idea of how bad the stuff is with the IME, I recommend reading up Chapter 4 here:
Intel x86 considered harmful by Joanna Rutkowska
https://blog.invisiblethings.org/papers/2015/x86_harmful.pdf https://blog.invisiblethings.org/papers/2015/x86_harmful.pdf
The IME is basically a second computer inside your computer, running as the most privileged component on the platform. It has privileged access to all components of the system, and runs as long as the computer is plugged in or has battery (even if it the computer is switched off). It is under the control of Intel, they decide what the IME does, and it can use the NIC as it pleases, unnoticeable for the host system. It can not be disabled, switched off or removed. The rootkit researcher Rutkowska described it as "an ideal rootkiting infrastructure".
- ddalex 10y agoEven if I would not consider "... considered harmful" essays as screamers for attention, I would still take detraction about ME with a grain of salt, because: * it's easy to counteract, just not use an Intel NIC * it gets a lot of scrutinity * Intel is quite open about what it does, short of releasing signing keys for the firmware * the mobile platforms have similar secure enclaves (think baseband processors on phones), which nobody actually audits All of these make me think Rutkowska found out that bashing x86 gets her attention, and now she uses it as a beating horse.
- Spooky23 10y agoWe need a "Rutkowska Hand-Waving Considered Harmful". This paper is a bunch of insinuation. It goes into great dramatic length to describe how Intel ME is more evil than AMT/vPro, which runs in the same service processor context, but then selectively uses the features of AMT and attributes them to ME. If we were talking about servers, this paper would be talking about how the service processors on HP servers could be used to build a "bad iLO" that phoned home or allowed unauthorized parties to access. Intel devices aren't "phoning home". These claims require evidence... I don't see a network capture. Activated AMT implementations will phone back to your home, and allow things like remote control, remote bricking, or remote repair of management software. Saying that ME is "an ideal rootkiting infrastructure" is a statement without a lot of meaning. You could make the same statement about Windows, Linux or any number of components in a modern computer.