4 ms·
One thing I asked before but didn't get a definitive answer on: IIRC the IME images are cryptographically signed, right? If so, how can they modify the images w
by SimplyUnknown 10y ago
One thing I asked before but didn't get a definitive answer on: IIRC the IME images are cryptographically signed, right? If so, how can they modify the images without breaking the signature? Or can they resign it?
- mid-kid 10y agoAs far as I know, only the code is signed, not the partition table. This means that you can freely modify the partition table and completely remove some modules.
- mid-kid 10y agoPlease check the wiki for more detailed information: https://github.com/corna/me_cleaner/wiki/How-does-it-work%3F#why-does-it-work-arent-the-partitions-signed-how-can-you-modify-them https://github.com/corna/me_cleaner/wiki/How-does-it-work%3F...
- ysleepy 10y agoWell, what happens if you break the signature? - the IME does not start up... - Exactly what we wanted.
- nowaynohow 10y agoNo, if you break the signature, something (processor microcode or the IME boot block?) will notice, and the system will either not start, or shutdown after ~30min. There is microcode-level integration between the IME and the system processor in an Intel system. It also involves the platform TPM (which could be an IME module), on systems where Intel SGX or Intel TXT is active. OTOH, if the non-critical IME modules are missing, the system boots and goes on working just fine. Since the IME "partition table" is not signed, this allows you to remove the undesired modules such as Intel AMT. It is actually possible for a system integrator/motherboard factory to request from Intel a minimal IME build that lacks AMT, you know. It is also rather trivial to disable the (documented) IME path to the network: don't use the chipset-embedded ethernet MAC (as in midia access controller, not MAC address). That requires adding a full LOM NIC chip and taking up precious PCIe lanes, instead of just adding a (much cheaper) LOM PHY.