4 ms·
That reddit post was mine. I just created a new account there, but somehow my comment doesn't show up, no idea why. But fortunately there is HN :) I would not
by moppl 10y ago
That reddit post was mine. I just created a new account there, but somehow my comment doesn't show up, no idea why. But fortunately there is HN :)
I would not call it an enterprise security solution. It is also very much aimed at the ordinary user's machine. It is important for DRM (the infamous TPM chip is now basically an app running inside the IME/PSP). Decryption of DRM content takes place inside the IME and it is presented using a protected media path. So the content industry wants to have that on your computer.
Intel also tries to market it by offering security solutions like 'Intel Anti Theft Technology' or its 'True Key' App which utilizes the IME. It makes your machine uniquely identifiable and it should serve as a store for all your secrets (like biometrics, passwords etc).
Intel is also opening the IME up for third parties to create software for it. So your bank might e.g. run it's software inside the (considered safe and secure) IME. But of course such software has to be signed by Intel before.
Ruan even hints in his book at the possibility that one day the IME might become just as powerful as the user system. So it would be possible to run e.g. a game completely inside the IME, absolutely safe from the malicious user who might try to copy it. All you get is the output on the screen and the speakers. So the (considered unsafe) ordinary user space would just remain for running and storing trivial tasks and information. Everything else runs hidden away from you.
And all of this is supposedly for your own good and security. I would call it a dual use technology which (dis)owns the user.
- Ajedi32 10y ago> I just created a new account there, but somehow my comment doesn't show up, no idea why. Probably just got detected as spam by Automod and removed. If you message the mods for /r/linux they'll probably approve it for you.
- madez 10y agoBut then I don't get why they wouldn't market two different CPU's, one backdoored and user-controlling one and a normal maliciousness-free one. It's then up to the game developers to require a system of the former type to play their game. Then gamers get these and people who mind their privacy and security in computing get the latter. Win-win, right? I mean, people will anyways get computers that obey them. Either an ARM-based or something completely different. There are (at least) two different markets here. People who just want to enjoy products and media (which might be DRM'ed but they don't care) and people who want a computer they can trust. Why should AMD or Intel restrict themselves to the former market?