4 ms·
You are right, also before IME/PSP we trusted the manufacturer to some extent. But the IME/PSP is intentionally and officially implementing an architecture whi
by moppl 10y ago
You are right, also before IME/PSP we trusted the manufacturer to some extent.
But the IME/PSP is intentionally and officially implementing an architecture which ensures that the manufacturer has ultimate control on the platform, and can run any code it pleases anytime on your computer. It runs at the deepest level (below OS, BIOS, VTd, SMM), and has maximum privileges on the platform. It runs all the time, so even as you have your computer switched off.
Have a look at Intel Anti Theft Technology for example.
http://www.intel.de/content/dam/doc/product-brief/mobile-computing-protect-laptops-and-data-with-intel-anti-theft-technology-brief.pdf http://www.intel.de/content/dam/doc/product-brief/mobile-com...
It utilizes the IME. It shows that the IME is able to completely take control away from you. It can be triggered while the computer is switched off by sending it a specific packet over 3G network. And while activated you cannot switch it on anymore and it does whatever it pleases, like continuously sending location data to Intel servers across whatever network it manages to get hold of. Nothing you could do about it.
Less spectacular is the problem that CoreBoot/LibreBoot are facing. It is not possible to install the firmware you wish, because the IME is more powerful than you on the platform and does not allow you to do so.
So you have a second computer sitting inside your computer which has full access to your resources and the manufacturer is controlling what it is doing.
So while we were maybe speculating about trusting the CPU manufacturer before, now we have no choice anymore. We have to trust him, he is the boss on the platform.
- richardwhiuk 10y agoWe weren't speculating before - we were trusting them - Intel has long produced the entire chip and chipset (i.e. the entire path between the CPU and the network interface). They could have implemented backdoors previously. All that's changed is that they are implementing function which makes it obvious that this is possible.
- moppl 10y agoYes right, we were. But we were able to install our own firmware before there was the IME. And it has also changed in the sense that the IME is a full fledged autonomous universal computer which has it's own RAM, ROM, clock etc. It is not just some very specific chip with hard-coded functionality, no, it can e.g. load and run Java applets. So it is a very powerful moving target which can be used for whatever it is programmed to. Rootkit researcher Joanna Rutkowska called it the perfect rootkitting infrastructure.
- shostack 10y agoAre there any documented cases of this vector being used against a user?
- AnimalMuppet 10y agoNot documentation, but... a former co-worker had done some work for intel agencies. He told me about something that was similar to this (though back in the 2008 time frame, so not using IME). If he can be believed (and I can neither confirm nor disprove what he told me, nor can I now prove that he ever said anything), this approach has been used for a long time.