4 ms·
The article is dated. The game changed fundamentally with the introduction of the Intel Management Engine (or the AMD Platform Security Processor) on the x86 p
by moppl 10y ago
The article is dated.
The game changed fundamentally with the introduction of the Intel Management Engine (or the AMD Platform Security Processor) on the x86 platform. The system is now "deep pwned" as described in point 3.1.1 of the article. The manufacturer has ultimate control of the platform, the user has been disowned.
https://mail.fsfeurope.org/pipermail/discussion/2016-April/010912.html https://mail.fsfeurope.org/pipermail/discussion/2016-April/0...
https://youtu.be/rcwngbUrZNg?t=17m41s https://youtu.be/rcwngbUrZNg?t=17m41s
https://blog.invisiblethings.org/papers/2015/x86_harmful.pdf https://blog.invisiblethings.org/papers/2015/x86_harmful.pdf
https://link.springer.com/book/10.1007%2F978-1-4302-6572-6 https://link.springer.com/book/10.1007%2F978-1-4302-6572-6
- ryukafalz 10y agoWorth noting, it is possible to disable this on certain systems that come with Intel ME out of the box: https://libreboot.org/docs/hcl/gm45_remove_me.html https://libreboot.org/docs/hcl/gm45_remove_me.html There's work in progress on removing the ME blob on the Thinkpad x220 and the Librem 13. But for most modern systems, yes, you're right.
- moppl 10y agoYes right, but the gm45 chipset is a core2Duo chipset. And the X220 features Sandy Bridge (2011). While it is possible to mess around with older implementations of the IME it is pretty much impossible with recent versions. It sits now on the CPU die and is inaccessible. An it is only removing the ME blob in the system's flash memory. The ME has also it's own internal ROM which contains firmware which cannot be altered or read.
- robotmay 10y agoIn the recent AMD AMA thread on Reddit there was a highly upvoted comment asking AMD to look into working with the Coreboot/Libreboot community to improve the PSP situation. It's nothing solid but the AMD guys did answer and say that they would discuss it internally. Better than nothing I guess.
- moppl 10y agoYes, AMD was asked if they would release the PSP source code. But IMHO that doesn't change anything as discussed here: https://news.ycombinator.com/item?id=13781408 https://news.ycombinator.com/item?id=13781408
- justifier 10y agoThanks for the links but your claim against the article is a bit heavy handed The article is much larger than CPU level access and control..It discusses high level issues worth thinking about such as communications and social elements The article lacks any real actionable advice to date it too much.. when will it be out of vogue to suggest reading 1984 to aide in 'anticipation'? But the value of the article aside.. your language: dated; made me interested in finding out when ME was first introduced and I was having trouble finding any concrete dates of introduction A lot of your links and their references date around 2015+, yet the authors of your linked book worked at Intel around 2007 and failed to discuss introduction dates Then I found this at the libreboot FAQ that states ME was introduced into all Intel chips 2006+(o) with the real issues after implementations dating after ~2009+ Also in my search I found some promising leads on overcoming the ME issue: http://hackaday.com/2016/11/28/neutralizing-intels-management-engine/ http://hackaday.com/2016/11/28/neutralizing-intels-managemen... https://libreboot.org/faq/#thinkpads https://libreboot.org/faq/#thinkpads What an unfortunate and reason defying battleground (o) https://libreboot.org/faq/#intelme https://libreboot.org/faq/#intelme
- moppl 10y agoWell, you are right that it is slightly heavy handed. I also thought that a lot of the higher level stuff in it might still be valid. But at the fundamental level the battle is lost, you will never own your (x86 based) PC as long as there is an IME/PSP in it. Concerning the introduction of the IME/PSP, it says already in the first link that I provided: "All post-2013 (AMD) and virtually all post-2009 (Intel) systems". I think we are very far from neutralizing the IME. Earlier implementations can be manipulated to some degree (not "neutralized" though), but recent versions are rather fool proof. The book is written by one of the engineers of the IME. While it might not discuss introduction dates it discusses pretty much everything else and is THE reference when studying the IME :)
- Arizhel 10y agoShouldn't it be possible to effectively neutralize the IME/PSP by controlling the data that enters or exits it, so that it can't be activated remotely, or communicate with the "mother ship"?
- richardwhiuk 10y agoI'm not quite sure why the IME/PSP is relevant. Unless you've inspected the silicon on your CPU, then you are inevitably trusting the manufacturer of the chip to some extent. What new threat model does the Intel ME add?
- moppl 10y agoYou are right, also before IME/PSP we trusted the manufacturer to some extent. But the IME/PSP is intentionally and officially implementing an architecture which ensures that the manufacturer has ultimate control on the platform, and can run any code it pleases anytime on your computer. It runs at the deepest level (below OS, BIOS, VTd, SMM), and has maximum privileges on the platform. It runs all the time, so even as you have your computer switched off. Have a look at Intel Anti Theft Technology for example. http://www.intel.de/content/dam/doc/product-brief/mobile-computing-protect-laptops-and-data-with-intel-anti-theft-technology-brief.pdf http://www.intel.de/content/dam/doc/product-brief/mobile-com... It utilizes the IME. It shows that the IME is able to completely take control away from you. It can be triggered while the computer is switched off by sending it a specific packet over 3G network. And while activated you cannot switch it on anymore and it does whatever it pleases, like continuously sending location data to Intel servers across whatever network it manages to get hold of. Nothing you could do about it. Less spectacular is the problem that CoreBoot/LibreBoot are facing. It is not possible to install the firmware you wish, because the IME is more powerful than you on the platform and does not allow you to do so. So you have a second computer sitting inside your computer which has full access to your resources and the manufacturer is controlling what it is doing. So while we were maybe speculating about trusting the CPU manufacturer before, now we have no choice anymore. We have to trust him, he is the boss on the platform.
- richardwhiuk 10y agoWe weren't speculating before - we were trusting them - Intel has long produced the entire chip and chipset (i.e. the entire path between the CPU and the network interface). They could have implemented backdoors previously. All that's changed is that they are implementing function which makes it obvious that this is possible.