5 ms·
Where is the suggestion that Intel ME isn't a backdoor? The article states: > In this article, we describe how we discovered this undocumented mode and how it
by Triesault 9y ago
Where is the suggestion that Intel ME isn't a backdoor? The article states:
> In this article, we describe how we discovered this undocumented mode and how it is connected with the U.S. government's High Assurance Platform (HAP) program.
> Googling did not take long. The second search result said that the name belongs to a trusted platform program linked to the U.S. National Security Agency (NSA).
>We believe that this mechanism is designed to meet a typical requirement of government agencies, which want to reduce the possibility of side-channel leaks. But the main question remains: how does HAP affect Boot Guard? Due to the closed nature of this technology, it is not possible to answer this question yet, but we hope to do so soon.
- kogepathic 9y ago> We believe that this mechanism is designed to meet a typical requirement of government agencies, which want to reduce the possibility of side-channel leaks. Interesting that Intel will provide this to the US government for enough money, but wouldn't offer it as an additional $50 or $100 option for end-customers to disable the ME. I think there are probably enough privacy conscious people who would be willing to buy a Skylake or newer platform from Intel if they could easily disable the non-BUP components of the ME for a reasonable fee.
- dingo_bat 9y ago$50 or $100 for turning off the spyware in my own CPU is hardly reasonable.
- daxorid 9y agoSure it's unreasonable, but at least charging for it would be better, and make more business sense, than the current "Fuck You, Plebe" they offer to us prisoners of the FVEY panopticon.
- onli 9y agoYou are seeing this wrong. Intel has two reasons to have ME: 1. It is useful in business settings 2. It enables the US spy agencies complete surveillance of all PCs It's the second point that explains why they can't make it optional. And that makes business sense. That way they ensure backing from the NSA, instead of having to fight against them.
- codedokode 9y agoIt can be useful for other purposes too, for example for enforcing DRM so that DRM code runs on a ME engine. And of course DRM code can be backdoored too so playing a specially crafted video would run code from it.
- cyphar 9y agoIntel ME is not an effective DRM scheme. You need to be exceptionally careful when you mention DRM, because if it becomes commonly believed that Intel ME could be used to implement DRM all of a sudden the DMCA comes into play. Research into Intel ME vulnerabilities becomes a federal crime.
- owenmarshall 9y agoThis isn't necessarily true: https://www.ftc.gov/news-events/blogs/techftc/2016/10/dmca-security-research-exemption-consumer-devices https://www.ftc.gov/news-events/blogs/techftc/2016/10/dmca-s... Of the four criteria in the exemption, I wouldn't put it past the government trying to make the case that exposing a NSA spy program somehow falls afoul of good faith investigation - but the general view that "any DRM research is a crime" is no longer accurate.
- cyphar 9y agoThe good-faith requirement also means that likely you could not publish a way for someone to disable the "effective anti-circumvention measure". Even if you could, anyone who used that research to disable their own devices is arguably not conducting "good faith security research". While researchers might be safe, nobody will be able to use the results of their research legally except the companies that produce DRM (so that they can make it more secure). I don't think that's actually an improvement to be honest.