5 ms·
You've been unable to find that information because no such "functionality" exists. Microcode just patches bugs or configuration details of the CPU; it doesn't
by temptel 10y ago
You've been unable to find that information because no such "functionality" exists. Microcode just patches bugs or configuration details of the CPU; it doesn't "phone home".
- akerl_ 10y agoThat was my initial understanding, but I figured I'd give the parent commenter the benefit of the doubt in case my understanding was flawed. Some more searching seems to lead back to where I started: the microcode itself isn't phoning home, the only phoning "home" that occurs is the normal process of "when you pull down an update for something, it requires phoning to the repository holding the updates".
- micheljones 10y agoME does have ability to do that, tho.
- akerl_ 10y agoJust like IPMI, or any other standard for allowing hardware-level admin of a system.
- micheljones 10y agoBy using the word 'standard' you're trying to legitimize something that's fully encrypted, impossible to code-audit and fully under control of Intel, while pretending to be your property and controlled by you. So yes, it's a standard. I believe there was also a standard on how to tie a noose for hanging a human, but that didn't mean much to the one getting hanged.
- comboy 10y agoDo you think you could fit drivers for all common ethernet/wifi cards in there and proper TCP/IP implementation? It's below assembly abstraction level.
- moppl 10y agoThe ME is basically an independent universal computer in its own right, it comes with its own clock, RAM, CPU etc... It is like a Matryoshka doll sitting inside the Intel CPU of your computer. Therefore, yes, it can contain all of that. For further details see my other two posts.
- comboy 10y agoSorry I was just thinking about microcodes and you are talking about ME. Scary stuff indeed[1] 1. https://en.wikipedia.org/wiki/Intel_Active_Management_Technology https://en.wikipedia.org/wiki/Intel_Active_Management_Techno...
- Sephr 10y agoIntel ME has independent NIC access and usually cannot be disabled by the user. It has only been six days since it has become possible to neutralize the ME firmware for Sandy Bridge and Ivy Bridge[1]. [1]: https://news.ycombinator.com/item?id=13056997 https://news.ycombinator.com/item?id=13056997
- imtringued 10y agoHow else would you implement remote server management that works even when the hardware is shut down (put still connected to power) if not with a seperate CPU that has access to the NIC?
- benchaney 10y agoHow could it possibly patch bugs without phoning home? Are you claiming that it is self modifying code?
- akerl_ 10y agoI wouldn't consider "running an update where it pulls new code" to be "phoning home", any more than my car is "phoning home" when I drive it to the dealership for repairs. The implication the comment I was replying to gave was that the device sent unexpected network traffic back to Intel HQ, with the connotation that it was doing so to leak information about my system.
- benchaney 10y ago"Running an update where it pulls new code" is definitely an example of phoning home, and it opens the door to all sorts of vulnerabilities, such as the one featured in the Apple vs the FBI case.
- twr 10y agoIntel microcode updates on Linux are provided through regular distribution repositories. There is no phoning home feature.
- benchaney 10y agoDo they get updated when you run the package manager, or do they update automatically?
- akerl_ 10y agoEither via the package manager or via the user manually downloading and loading the microcode update of their choosing. For example: http://askubuntu.com/questions/545925/how-to-update-intel-microcode-properly http://askubuntu.com/questions/545925/how-to-update-intel-mi...
- 10y ago
- jpalomaki 10y agoA more subtle way to communicate with the mother ship would be to ship an update that makes the CPU leak some desired information. For example change how some specific cryptographic operation works under certain conditions to make it possible for eavesdropper to break the encryption. Or just make some funny things with memory and make certain information available to be retrieved via web browser when user visits malicious page.