16 ms·
Disabling the Intel Management Engine
- jadbox 9y agoI bet you that the next generation of Intel processors will have patched this workaround from working, and maybe go as far removing the ability to kill IME unless you use some kind of rotating encryption dongle. Unfortunately for consumers, there's no way to escape this as even AMD has their own IME.
- amelius 9y agoWouldn't it be possible to isolate the processor from the network interface? E.g. by using a network card that requires special access codes? I imagine you could build such network interface using an FPGA module.
- openasocket 9y agoIt already can't communicate with a non-Intel network card IIRC. It would need some kind of driver, and it's not like it can use the OS' network card driver, unless the IME is automagically able to use Windows, OSX, and Linux drivers.
- amelius 9y agoAre you sure? I suppose any network card on the PCI bus can be accessed by the CPU in principle. And leave it to the people of the NSA to install clever software in the IME module that doesn't disrupt the OS's communication with the network card.
- icegreentea2 9y agoSo I guess it comes down to what you think the point of the ME is. If its for what Intel claims, then having the ME have to access the NIC through the OS is useless - the whole point is to bypass the OS, so you can manipulate the computer regardless of its state (as long as its plugged in anyways). If you were worried about NSA spyware that tunnels through your OS... well, then you may as well just be worried about NSA spyware in your NIC. Because in the end, even if the ME was directly connected to the NIC, it still needs to know how to talk to the NIC (thus why NICs have drivers...). When you use an Intel NIC, the ME knows how to talk to it, and everything is hunky dorey. In practice, Intel could probably build a database of common non-Intel NICs and load all of their drivers into the ME. But really, if we assume that the ME exists for business reasons, then its obvious why Intel will just keep it all as Intel. They are nominally selling something that is advantageous to large organizations, and would like said large organizations to buy as much Intel gear as possible. Said large organizations believe that ME provides sufficient value to go with Intel NICs instead of other NICs.
- amelius 9y agoHence my suggestion to build our own NIC using an FPGA board.
- daxorid 9y ago> If its for what Intel claims If it's for what Intel claims, then they would trivially offer an option for the customer to disable it. Hell, they could even make it a selling point for higher-margin chips like Xeon. Does ME have business purposes? Sure. But their staunch refusal to allow disabling by nongovernmental customers does not pass the sniff test. There is clearly some other, non-business reason for it. > then you may as well just be worried about NSA spyware in your NIC If you own my NIC but not my CPU, I can encrypt my traffic and blind you. If you own my CPU (especially my AES-NI ISA), my options are more limited. Much higher-value target.
- gruez 9y ago>If you own my CPU (especially my AES-NI ISA), my options are more limited. Much higher-value target. >especially my AES-NI ISA why aes cpus specifically? you're free to not use aes instructions. besides, if you own the cpu, you load whatever shellcode you want, no need to backdoor the aes instruction.
- mschuster91 9y ago> you're free to not use aes instructions. good luck getting a system compiled that does not use them at all. Might be possible with gentoo and the right configuration as it compiles everything, but with a dominantly binary distro like Ubuntu or Debian you're SOL.
- daxorid 9y agoEspecially, not specifically. I was just saying my options are more limited, and the options for someone unwilling to recompile their own software is very severely limited. But even if I'm running, say, software-only Salsa20 with all compiler optimizations off, if my CPU is still owned, my keys are still at risk of silent compromise. The only real defense is to ascertain the processing limitations of IME and then choose your crypto primitives/implementation for both processing and memory hardness that exceeds the ability of the IME's lower transistor count and/or clock speed to keep up with.
- julian_1 9y agoThe thing is running Minix OS, so it's not inconceivable to configure non-intrusive drivers for third-party NICs sitting on the pci bus.
- tinus_hn 9y agoIf the board supports PXE boot, the bios or UEFI can access the network. No magic required.
- openasocket 9y agoHmmm, this stumped me for a while. Your argument makes complete sense, but then why do I need drivers for my OS to access the NIC, when it should be able to use the same API exposed to BIOS? So I looked it up: https://en.wikipedia.org/wiki/Preboot_Execution_Environment https://en.wikipedia.org/wiki/Preboot_Execution_Environment It's fairly light on details, but my interpretation is that for a NIC to support PXE boot it has to have firmware that exposes a standardized API so that the boot loader can functions as a DHCP client and a TFTP client. As far as I can tell, the NIC doesn't have to provide some standardized method for general access, just those two things. The NIC could even have a completely different, completely separate API that it expects the OS to use, and just has some firmware that acts as a shim to expose to the boot loader the PXE client API. Assuming this is true, Intel ME could access the NIC using the PXE boot API, but this only gives it the ability to act as a DHCP client and TFTP client, not arbitrary networking operations. I could be completely wrong about that, though. This is, at best, an educated guess.
- tinus_hn 9y agoThe bios and uefi obviously can also access the hard disk, otherwise you can’t boot. The OS still has its own driver though. That’s because (at least the BIOS version) is optimized for a small code size and a limited environment, while in the OS you want speed and features.
- comatose 9y agopxe booting loads a lightweight os, ime can access the networking later when the full os is loaded but has generic or specific drivers for low level net access. ime doesn't use pxe though, afaik
- laurentdc 9y agoI think they already did: https://github.com/corna/me_cleaner/wiki/Intel-Boot-Guard https://github.com/corna/me_cleaner/wiki/Intel-Boot-Guard
- craftyguy 9y agoThat has been around for years, and requires that the CPU + motherboard are paired during manufacturing so the CPU can be fused appropriately.
- Kwastie 9y agointerestingly enough some implementations are broken because of buggy UEFI (AMI) https://embedi.com/blog/bypassing-intel-boot-guard https://embedi.com/blog/bypassing-intel-boot-guard
- revelation 9y agoNo surprise, I mean verifying the integrity of the BIOS is like PlayStation 1 level of crypto chainloading madness. A great scheme that will always fail because whatever software you are verifying will be imperfect. The chance that software produced by companies whose "day job" is putting flashing LEDs and DC-DC converter heatsinks on reference designs is zero.
- Chaebixi 9y ago> I bet you that the next generation of Intel processors will have patched this workaround from working, and maybe go as far removing the ability to kill IME unless you use some kind of rotating encryption dongle. Unfortunately for consumers, there's no way to escape this as even AMD has their own IME. What would be the justification for Intel going through all that trouble to do that (besides a conspiratorial "the NSA needs it to spy on everyone")? The impression I've gotten, to this point, is that Intel just doesn't care enough about people in the general public who are bothered by the IME to publicly support ways to disable it. Governments had enough buying-power to get Intel to implement an unsupported workaround, but I'm not convinced Intel has a motivation to make accessing that workaround hard.
- kuschku 9y ago> What would be the justification for Intel going through all that trouble to do that (besides a conspiratorial "the NSA needs it to spy on everyone")? Well, some companies and users use the IME to enable theft-prevention technology. If you can circumvent the IME, you can easily steal a laptop and disable this theft-prevention technology. If that’s worth building an ever more closed walled garden is another question.
- tree_of_item 9y ago> besides a conspiratorial "the NSA needs it to spy on everyone" Besides the real reason? I dunno.
- Ajedi32 9y agoDo you have any specific evidence that the NSA is directly involved in pushing implementation of IME for the purposes of espionage? That's an extraordinary claim; the mere existence of the NSA isn't sufficient evidence that it's true. Yes, the NSA exists. Yes, it's their job to spy on people. And yes, it's perfectly valid to include mass surveillance in your threat model. But these constant, uncorroborated claims that the NSA boogeyman is hiding behind every rock and tree are starting to become quite tiresome.
- 9y ago
- DannyB2 9y ago> . . . and maybe go as far removing the ability to kill IME unless you use some kind of rotating encryption dongle. Dear Intel, please PLEASE only use a solid state dongle with no moving parts! :-)
- kbenson 9y agoI'm pretty sure at this point what Intel has done is create a way to bypass everyones encryption schemes by hijacking the CPU, which might be prosecutable under DMCA anti-circumvention laws...
- cyphar 9y agoNot sure that's correct. If you disable ME then DRM that depends on it just won't work. So it would be like saying that a power button is a DRM circumvention tool.
- kbenson 9y agoI'm saying that the ME, by nature of the access to the CPU, memory and IO that it has, is likely capably of circumventing almost all software encryption run on the CPU through surreptitious gathering of information as the system runs encryption/decryption routines. Whether Intel intended to or not, they've built the mother of all circumvention tools, and circumvention is specifically not allowed in the DMCA.
- cyphar 9y agoIntel ME is used as a component of DRM (see PAVP), which is what I was referring to. But this is quite an odd argument, by that definition your CPU would be a circumvention measure. And while you can use a CPU to circumvent DRM, just having a CPU isn't enough. Also, a normal user of a computer cannot do whatever they like with Intel ME, so its the least useful circumvention measure I've ever heard of. GDB is infinitely better. Not to mention that most DRM depends on the encryption being done outside of the computer's CPU. HDMI's DRM relies on the local computer not being aware of the contents of the stream and the monitor itself does the decryption with burned-in keys.
- cl289 9y agoIf I were in charge of collecting encrypted data at the NSA, I would make sure that whatever keys were used by the CPU's AES instruction set would be copied and saved using the CPU firmware. Then that data could be sent out with the ME, or simply stored in case that computer was ever an object of interest. In that way, anything encrypted (using hardware) could be decrypted. Seems like it would be malpractice by the NSA not to collect AES keys at the hardware level.
- leggomylibro 9y agoNot yet, but does SiFive's RISCV offerings have any sort of 'management engine'? If ARM continues to supplant x86, and an open ISA like RISCV starts to nip at ARM's heels...
- monocasa 9y agoSort of? They do have a simpler core off to the side for SoC management on their newer 64bit design. You're going to be hard pressed to find a moderately complex SoC without something like that. At a bare minimum, reset and power state sequencing is complex enough to offload to a microcontroller style core these days. The iMX6 is the biggest, most reent SoC I an think of without that.
- silversmith 9y agoWhat caught my eye was "removes (...) Java VM" - I had imagined the ME to be some kind of very basic maintenance task runner, not a full-blown dynamic app environment.
- craftyguy 9y agoIt's basically a tiny computer, with its own OS. Seeing JVM is used on it through, yea, that's surprising. I guess it was cheaper to beef up the IME to run Java than it was to hire someone to re-code whatever functionality the java app(s) provide. (Edit, in response to all of the comments in reply to this) Wow, I had no idea so many tiny devices ran java..
- Zigurd 9y agoJVMs can be simple and tiny. Pre-smartphone handsets run Java apps on 20Mhz 32-bit ARM application processors. Some of the JVMs are so simple there is no thread preemption - just round-robin. A 64kb jar is big for that kind of device.
- Fnoord 9y agoYubikey Neo seems to run Java as well [1] [2]. I guess there was a good reason why Schwartz renamed SUNW to JAVA. [1] https://www.reddit.com/r/yubikey/comments/6ji8ag/updating_yubikey_neo_javacard_openpgp_applet/ https://www.reddit.com/r/yubikey/comments/6ji8ag/updating_yu... [2] https://en.wikipedia.org/wiki/Java_Card https://en.wikipedia.org/wiki/Java_Card
- kuschku 9y agoEvery modern credit/debit/EC card, and every modern ID card also runs Java – in fact, that’s how the smart functionality in ID cards, drivers licenses and insurance cards is implemented: http://www.personalausweisportal.de/EN/Citizens/German_ID_Card/German_ID_Card_node.html http://www.personalausweisportal.de/EN/Citizens/German_ID_Ca...
- 9y ago
- deleted 9y ago[deleted]
- craftyguy 9y agoDoes this require a system with coreboot support? If not, I'm super tempted to try this on my Dell XPS 13 9333..
- zanny 9y agoIt doesn't, but because the IME is so undocumented and most firmwares are so horribly written its dangerous to remove these parts of the firmware image because it might brick your system for completely nonsense reasons (all it takes is the firmware randomly misaddressing into an IME area where there is now no data and failing to make your system unrecoverable without the ability to operate on the flash chip by hand). Make sure someone else has managed it with your same board to know it works.
- partycoder 9y agoHaving to build a modchip for your PC exacerbates the need for open source hardware.
- Sir_Cmpwn 9y agoSince you're playing with your Flash chip anyway, install Coreboot too: https://github.com/bibanon/Coreboot-ThinkPads/wiki/ThinkPad-X200 https://github.com/bibanon/Coreboot-ThinkPads/wiki/ThinkPad-...
- GlenTheMachine 9y agoCan someone point me to an explanation of exactly what this is, and whether I need to worry about it? Particularly on a home server I built myself from parts?
- zaggynl 9y agoIn short, the Intel Management Engine and AMD Platform Security Processor, which are on many motherboards, allow for remote power on and remote control of a PC if connected to Ethernet, are closed source and have known vulnerabilities.[1] This website has a more elaborate explanation: https://libreboot.org/faq.html#intel https://libreboot.org/faq.html#intel [1]: https://www.intel.com/content/www/us/en/architecture-and-technology/intel-amt-vulnerability-announcement.html https://www.intel.com/content/www/us/en/architecture-and-tec...
- GlenTheMachine 9y ago...but this varies depending on motherboard? ie if I buy an Intel CPU, and (say) an ASRock motherboard, is this still a thing?
- corna 9y agoAny Intel CPU has Intel ME, independently from the MB vendor
- criddell 9y agoIf the machine has two network interfaces, the management engine will only be active on one of them (always the lower numbered interface). If you don't need both, disable NIC #1 and only use NIC #2. You will get the benefits of the management engine without any external exposure.
- mmjaa 9y agoIf you ever do something revolutionary that would upset the apple cart, yes: you do need to be worried about this. Its a computer, within your computer, which you do not control - and it can be used for any secret purpose your enemies may desire. Don't have any enemies? Well then, you've got nothing to fear. But lets say you do something big, which will change society, perhaps disrupt an existing American Military-Industrial player .. well then, that small component is going to keep you down, brother.
- moonbug 9y agoAww, Gentoo's still a thing, how cute.
- gerdesj 9y agoYes it bloody well is. This laptop runs it for starters (and keeps my lap warm). You also get to see some damn fine hackery in the OP, in the finest spirit of Gentoo. Although it is pretty advanced for those of us who habitually end up repairing broken toolchains without breaking a sweat 8)
- 0x6c6f6c 9y agoEven if enthusiast Gentoo wasn't a thing, Google's ChromeOS is a customized Gentoo[1] which has grown in market share fairly drastically in K-12 schools especially in the US[2]. [1]: https://wiki.installgentoo.com/index.php/ChromeOS https://wiki.installgentoo.com/index.php/ChromeOS [2]: https://9to5mac.com/2017/03/02/apple-ios-market-share-k-12-education-chrome-os/ https://9to5mac.com/2017/03/02/apple-ios-market-share-k-12-e...
- dang 9y agoYou've posted many uncivil and/or unsubstantive comments to HN and we've asked you before to stop. If you can't or won't stop, we will ban you. Please read https://news.ycombinator.com/newsguidelines.html https://news.ycombinator.com/newsguidelines.html and fix this going forward.
- wheresmyusern 9y agoi remember when it was found that me had a "kill switch," wasnt it found that this kill switch still leaves a rather lot of power in the hands of the IME?
- hoodoof 9y agoReally Intel/Apple/Microsoft should provide an official and reliable way to do this. We see you Intel... with your stinky spies peeping out from the depths of our computers....
- jordigh 9y agoI think it's very likely that the order to backdoor all hardware came from the government and Intel decided to market it as some kind of advanced management benefit for the consumer. Evidence in favour is reverse-engineered functions in Intel ME that have NSA's name in them: https://www.bleepingcomputer.com/news/hardware/researchers-find-a-way-to-disable-much-hated-intel-me-component-courtesy-of-the-nsa/ https://www.bleepingcomputer.com/news/hardware/researchers-f... There's no way that both Intel and AMT simultaneously decided to backdoor their hardware out of consumer demand. The order must have come from above. (Okay, sorry, that's as much of a conspiracy theorist as I get to be.)
- deleted 9y ago[deleted]
- openasocket 9y agoThat's a blatant misinterpretation of that article. Here's the main quote: "According to a highly technical blog post, Positive Technologies experts revealed they discovered a hidden bit inside the firmware code, which when flipped (set to "1") it will disable ME after ME has done its job and booted up the main processor. The bit is labelled "reserve_hap" and a nearby comment describes it as "High Assurance Platform (HAP) enable." High Assurance Platform (HAP) is an NSA program that describes a series of rules for running secure computing platforms. Researchers believe Intel has added the ME disabling bit at the behest of the NSA, who needed a method of disabling ME as a security measure for computers running in highly sensitive environments." TL;DR the evidence is that the NSA made Intel give them a way to DISABLE the management engine on their machines, not a backdoor.
- jordigh 9y agoI know, I didn't say that they found an NSA backdoor smoking gun, but it still seems suspicious to me that the NSA got to dictate anything about what should happen in ME. I remain a conspiracy theorist. I really don't see a market demand for all hardware since 2007 to have this built-in by both duopolists.
- std_throwaway 9y agoWhat advantage do I, as a lowly user, have from the ME?
- na85 9y agoYou can sleep soundly at night, soothed by the knowledge that your system is fully compliant with the surveillance apparatus.
- aaronaarzelbart 9y agoAhhhh. I do feel soothed. For so long I felt unwatched, unseen, sadly unspied on and left out.....
- criddell 9y agoThe management engine is the little computer that is used to get the big computer running. Back when I was a kid, after hiking to school in 4 feet of snow uphill with no shoes, if I were building a PC or adding a new card, I would spend a bunch of time flipping little DIP switches to set things like addresses and assign IRQs. I'd reboot and my Gravis Gamepad controller would work, but the SoundBlaster wouldn't. So I'd power down, flip some switches and try again until I could get everything working. Those switches went away, but the underlying issues remained. The new method was some firmware that did a bunch of pre-boot configuration. That was refined over the years and now today there's an entire computer running it's own OS that manages all this stuff. It works amazingly well. However, once the machine is up and running, most people (especially consumers) have no need for it after that. It would be nice if it just powered down and waited for the next reboot. However, a little hidden computer was too useful to be ignored and it's used for a bunch of things including DRM (it can have secure-enclave-like functionality) and remote management. I'm not sure we have an exhaustive list of what it can do.
- temac 9y ago> Those switches went away, but the underlying issues remained. The new method was some firmware that did a bunch of pre-boot configuration. That was refined over the years and now today there's an entire computer running it's own OS that manages all this stuff. I'm really impressed about how people manage to self-convince themselves so much about something they don't know about to the point they can explain their imaginary tech stack with such aplomb. The ME is not needed to do PnP conf (or whatever it has been renamed too those days), and to the best of my knowledge is not used to do that and has never been. ACPI/EFI & their friend are sufficiently hosted on the CPU, and can run platform code at so called negative privilege level at runtime. I expect those computers with ME disabled to run as well as if ME would not have been disabled, including if you add or remove an extension card. However you are right about remote management (that's the main advertised application of ME) and probably DRM stuff.
- jordigh 9y agoIt makes me so unhappy that this is what things have come to. They make hardware that we can't control, there's no real alternative to buy, and now we gotta rely on volunteers and wiki pages to give instructions that might work but who knows you might brick it. I wish there was more widespread outrage over ME and PSP and "trusted computing" so we could collectively tell them to stop selling this garbage. There's so much cynicism out there, though, that I think the public would hardly bat an eye if they knew that all hardware since 2008 or so has secret backdoors. We're just used to this kind of abuse and control. I haven't bought a new computer since 2007 because I don't want backdoored hardware. If it really is For My Own Safety, as they advertise it to us, then let me control it!
- chongli 9y agoI hear you! It's frustrating to me, too. Having said that, I think it's but one manifestation of a larger phenomenon. People, in general, believe in a just world. They implicitly trust the mechanisms of society and government. They either can't or don't want to take responsibility for every detail of their lives. They trust the police. They trust big companies like Apple, Facebook, and Google. They trust the government! I honestly believe that a lot of people would be capable of taking responsibility for all of this themselves. I think they just don't want to. They have neither the time nor the energy to put constant pressure on all of these organizations. They have so much other stuff to worry about in their lives.
- abraae 9y agoI think most people trust their government, large companies etc. to some degree, but much more so they trust others who are in "their tribe". e.g. if I read a story on HN about some police brutality, posted by some familar, karma-rich HN user, I'd quite possibly give it more credence than a report from said police department denying it. Just because I'm in the HN tribe. This effect is why posting deliberately inflammatory fake news on platforms like Facebook is so damn effective. The typical pattern is (a) establishing the author's tribe (e.g. gun-toting 50-something male living in a southern state) and then (b) launching the attack. I really like to think that, as a rational person, my bullshit detectors would fire... but its an interesting thought experiment as to what I'd give credence to just because it was uttered by a respected HN poster.
- internalfx 9y agoDoes anyone know if AMD PSP can be disabled?
- nissimk 9y agoThe op says no in the linked article.
- platinumrad 9y agoIt's entirely possible that there exists something analogous to the HAP bit[1] or that something like me_cleaner could be developed for the PSP but AMD is not the market leader (and is frankly negligible when it comes to laptops) so much less research has been done on the AMD PSP. I remember that when excitement was building for the release of Ryzen there were petitions for AMD to open source the PSP and some talk that it might actually happen but they eventually shut the idea down during a Q&A.[2] It's a shame because it would have given AMD something to really distinguish itself from Intel and would have been viewed very positively by a lot of different communities/market segments. Really makes you think about why they didn't do it... [1] http://blog.ptsecurity.com/2017/08/disabling-intel-me.html http://blog.ptsecurity.com/2017/08/disabling-intel-me.html [2] https://news.ycombinator.com/item?id=14803373 https://news.ycombinator.com/item?id=14803373
- binaryapparatus 9y agoLet's say I disable or pull out all the network/wireless cards I have. Then what? Any ideas how to connect to the internet otherwise? I am seriously thinking going Stallman because of this and not connecting to the internet at all, at least not from all the machines.
- Skunkleton 9y agorfc1149 is your last option. https://tools.ietf.org/html/rfc1149 https://tools.ietf.org/html/rfc1149
- binaryapparatus 9y agoThis is much closer to what I have in mind then what you can expect :) Current draft involves two monitors, two cameras, and protocol crazy enough to confuse any firmware.
- Skunkleton 9y agoIf you are serious, I would recommend using local firewall rules to modify your outgoing packets so that they are in some way non-standard, and then filtering all but the non-standard packets at your networks firewall.
- dredmorbius 9y agoIf you don't mind a fairly slow connection, there's PLIP or SLIP. The latter is point-to-point only, though at 9600 baud it is indeed slow. If you're relying only on text-based transfers, these may be acceptable. (I've run systems, at least for a time, relying on both.) Otherwise, airgapping and read-only media might be an option, for transfers you need / want to perform.
- listic 9y agoI wonder how should I go about finding a service center/technician competent enough to do that for me?
- noobermin 9y agoCan I get a serious alternative view on this? What purpose does Intel have for things like this exactly? Also, are AMD chips an alternative that can help here?
- platinumrad 9y agoThe IME, like Computrace which is similarly awful[1], is intended to be used for enterprise management. It's nice for someone in IT to be able to remotely wipe a company laptop that was left in an airport, but there's absolutely no reason why consumer devices should be burdened with these backdoors. AMD has something called the PSP which essentially serves the same purposes of the IME which is also undocumented and cannot be disabled. [1] https://securelist.com/absolute-computrace-revisited/58278/ https://securelist.com/absolute-computrace-revisited/58278/
- JumpCrisscross 9y ago> there's absolutely no reason why consumer devices should be burdened with these backdoors Intel's advantage is built and defended on economies of scale. Making a hundred million of one thing [1] is more profitable than making 50 million of two things. Particularly if enterprises' demand for IME is stronger than consumers' demand for non-IME chips (assuming no strong externalities, e.g. NSA corruption). I think the Intel Management Engine is crap. But there's a comprehensible reason it's there. [1] https://www.ft.com/content/beff6e56-53ed-11e4-80db-00144feab7de https://www.ft.com/content/beff6e56-53ed-11e4-80db-00144feab...
- platinumrad 9y agoIntel doesn't have to ship IME-less chips. All it has to do is provide a way for users[1] to disable features that compromise their security but Intel doesn't, for whatever reason. [1] I'm aware that a "High Assurance Program" bit exists that disables most functions of the IME but you can't expect the average consumer (or even the majority of technically-inclined consumers) to own an SPI flash programmer and to be willing and able to use one on their motherboard. Furthermore, researchers believe that setting this bit would cause any computer with the Verified Boot fuses set (i.e. pretty much any recent laptop) to fail to boot[2]. [2] https://github.com/corna/me_cleaner/issues/53#issuecomment-325589606 https://github.com/corna/me_cleaner/issues/53#issuecomment-3...
- achillean 9y agoThe feature is sometimes also available over the Internet btw. Here is an overview of publicly-accessible Intel Active Management services: https://www.shodan.io/report/PuIRbQpt https://www.shodan.io/report/PuIRbQpt
- Fice 9y agoWe know that Intel CPUs have IME and AMD CPUs have PSP, but is anything known about VIA processors (https://www.viatech.com/en/silicon/processors/ https://www.viatech.com/en/silicon/processors/) and boards (https://www.viatech.com/en/boards/ https://www.viatech.com/en/boards/)? Are there any other producers of x86-64 CPUs?
- jlgaddis 9y agoI think I'm gonna order the hardware and finally do this on my T420 and W530.
- bubblethink 9y agoIf you port coreboot to w530, please post it somewhere. I am interested in it, but the information about coreboot on w530 is a bit scarce.
- j_s 9y agoThis is particularly relevant in light of the pending BlackHat EU presentation (Dec 2017): How to hack a turned-off computer, or running unsigned code in Intel ME | https://news.ycombinator.com/item?id=15298833 https://news.ycombinator.com/item?id=15298833 (Sep 2017, 239 comments)
- hilmipilmi 9y agoIf there is a IME firmware update popping up before this talk, dont apply it if you want to be able to run unsigned code yourself.
- kxyvr 9y agoI'm wondering if someone could clear something up for me. There's the me_cleaner project that the above guide relies on in order to generate the new BIOS image. However, I thought me_cleaner could be run directly without dumping, modifying, and reflashing an image using the Pi. What's the difference in efficacy between the above guide and just using me_cleaner directly?
- corna 9y agome_cleaner is Python script that operates on a dump, it can't modify the firmware without the help of other tools; this guide just explains in detail the complete process of using me_cleaner.
- earenndil 9y agoIt says raspberry pi 3b. Can I do it on a pi 0?
- bromonkey 9y agoI don't see anything that would make it specific to version 3, except that you might have to build your own version of gentoo. It would be nice if anyone else has an idea because I'd like to do this with the raspberry pi2 I already have.
- earenndil 9y agoWell again, I don't see why the pi has to run gentoo. It could run any other linux.
- gigatexal 9y agoMakes me happy I am moving to AMD not systems and staying away from their pro line that has this nonsense built in.
- deleted 9y ago[deleted]
- subway 9y agoReading through this thread, I can't help but long for the days of it only being a crackpot theory that everything everywhere is owned.
- Sephr 9y agoIn order to test if this breaks any silicon workarounds, someone should run comprehensive benchmarks on their CPU pre and post-IME disabling.
- fdchn2016 9y agoI don't know why everyone thinks doing this much is safe. If I was the NSA/CIA director, I would put this in as a first level and if anyone figured out how to hack this backdoor, I would have a 2nd and 3rd hidden backdoor or maybe more. Maybe a particular sequence of instructions which opened a backdoor.
- hilmipilmi 9y agoIt feels reassuring that you can actually get access and read the assembly of the IME now, thanks to https://github.com/ptresearch/unME11 https://github.com/ptresearch/unME11. For instance using the the Gigabrix-BSi5ha-6200 IME Firmware update archive: 1. Download and unzip the Gigabrix-BSi5ha-6200 IME update archive (http://download.gigabyte.us/FileList/BIOS/brix_bios_bsi5-h-a-l-6200_f5.zip http://download.gigabyte.us/FileList/BIOS/brix_bios_bsi5-h-a...). Use F5_BIOS/image.bin from that archive. 2. Start "python unME11.py image.bin" 3. The uncompressed modules are located in image/00004000.FTPR/* after that 4. You can i.e. load image/00004000.FTPR/kernel.mod in IDA using 80486 in 32bit real-mode or use "objdump -m i386 -b binary -D kernel.mod --adjust-vma=0x80000" with entry point being 0x80000 or "objdump -m i386 -b binary -D bup.mod --adjust-vma=0x2d000" with entry point being 0x2D04C
- celeritascelery 9y agoAny insights from the code?
- hilmipilmi 9y agoI used it to look into Gigabytes response to Intel SA 00075 described in https://embedi.com/files/presentations/BH-Las-Vegas-2017-Intel-AMT-Stealth-Breakthrough-presentation.pdf https://embedi.com/files/presentations/BH-Las-Vegas-2017-Int.... before: http://download.gigabyte.us/FileList/BIOS/brix_bios_bsi5ha(a)-6300_f3.zip http://download.gigabyte.us/FileList/BIOS/brix_bios_bsi5ha(a... after: http://download.gigabyte.us/FileList/BIOS/brix_bios_bsi5ha(a)-6300_f4.zip http://download.gigabyte.us/FileList/BIOS/brix_bios_bsi5ha(a... You can see that there is an extra function call added that tests for response.length. Given the easy availability of the assembler dump you can expect progress towards demystifying IME. I'm not a professional in the security field, but I sense that there is lots of possibilities by just doing a "strings image/00275000.NFTP/amt.mod". Gigabyte might be special, but they have left their assert prints in the code and you can get a sense what the thing is doing...
- thresh 9y agoDoes that ruin the BMC/iLo/IPMI?
- jkxyz 9y agoThis is off-topic, but the Gentoo installation guide that this page is a part of is one of the most comprehensive and accessible Linux guides I've ever read. It taught me a lot of Linux concepts that I never needed to use before when setting up cloud VMs, and now I have a fully working installation of Gentoo + GNOME (with an encrypted root partition) that I'm confident in managing and upgrading. I definitely recommend checking out the rest of the guide. https://wiki.gentoo.org/wiki/Sakaki%27s_EFI_Install_Guide https://wiki.gentoo.org/wiki/Sakaki%27s_EFI_Install_Guide
- e12e 9y agoImagine the havoc if (when?) Intel's code signing keys for IME are leaked? Sure it might be possible to update keys in all the world's post-2006 Intel computers. But in reality it'd be a free for all that makes botnets of home routers look like a needle on a football field...
- squarefoot 9y agoDisabling IME and similar bugging subsystems is only a temporary solution: vendors will create a different one with next gen CPUs and all those brave folks dedicating their time to the task of removing/disabling it will be forced to go back to square one: study again, reverse engineer, reflash, brick, try again, etc. That way CPU makers will always be ahead. We instead need a platform (CPU+peripherals) which is open by design; no more ME or closed device drivers, blobs etc. No matter if it's 10 times slower than the equivalent by Intel or AMD or draws 10 times more current than the corresponding ARM processor; the point is funding such a development, producing it and selling it even to a small fraction of users will send a heck of a message. Also a well crafted PR campaign could do the rest (does your boss know that all his/her files and communications can be accessed by Intel, AMD and every government with ties to them? What about making him/her aware?). If someone starts a project like that, I'm pretty sure I won't be the only one ready to donate a few quid right now.
- trendia 9y agoNew Intel chips have only had minimal improvements to previous chips, so there isn't a huge incentive to upgrade if you don't mind giving up a little performance in exchange for security.
- sexlove12 9y agoShush SC sffndvkecjdlvkelvk