7 ms·
JTAG is used as a debug interface, so the implication is that full access to intels AMT (where minix3 is said to be running) has been achieved
by tty7 9y ago
JTAG is used as a debug interface, so the implication is that full access to intels AMT (where minix3 is said to be running) has been achieved
- hoodoof 9y agoCan you explain what this means?
- SAI_Peregrinus 9y agoFull control over the Intel backdoor / remote administration engine that's on all their modern CPUs. (It may not be an intentional backdoor, but it's certainly looking as if it's been usable as one by intelligence agencies.)
- hoodoof 9y agoOK so the implication being that with this thing found, someone could make a USB device that when plugged into an intel machine immediately gets control?
- deleted 9y ago[deleted]
- deleted 9y ago[deleted]
- mtnygard 9y agoPrecisely so. At least for the Intel machines that have IME features. So all the enterprise, data-center boxes but not every laptop. Edit: I read some more. It looks like this is going beyond what I thought and affects way more machines.
- Someone 9y agoReading http://www2.lauterbach.com/pdf/dci_intel_user.pdf http://www2.lauterbach.com/pdf/dci_intel_user.pdf, there are two ways to debug over that connector; one using the USB protocol and the other using a proprietary protocol. If this uses the latter, that device, technically, wouldn’t have to be a USB device (but of course, it could still masquerade as one) That PDF also says your BIOS must support this kind of debugging, and, for the ‘OOB’ protocol, your hardware must support it. So, your BIOS may be configurable to make this attack impossible, and your hardware may already be protected against it.
- baybal2 9y agoThen you simply have to replace the bios with one that has USB debugging enabled. Or change registers on a working machine
- mkempe 9y agoGiven what we know of the NSA's past predation, why would one think this is not intentional?
- zokier 9y agoIntels own guidelines say that DCI should be disabled by default, although on some systems that was not true[1], afaik (would like to be corrected if wrong) this does not impact vast majority of systems. This seems more like a frontdoor that is supposed to be locked tight rather than an backdoor. The bugs that actually enable DCI could be more likely candidates to be considered backdoors. [1] https://security-center.intel.com/advisory.aspx?intelid=INTEL-SA-00073 https://security-center.intel.com/advisory.aspx?intelid=INTE...
- chx 9y agoThis link is broken.
- extra88 9y agoThey probably removed the languageid parameter, thinking it was optional. https://security-center.intel.com/advisory.aspx?intelid=INTEL-SA-00073&languageid=en-fr https://security-center.intel.com/advisory.aspx?intelid=INTE...
- phkahler 9y agoBut once that front door is open, people will be able to walk around in the house and figure out how to 1) finally disable the thing for good, or 2) find a more universal attack that doesn't use that door.
- comandillos 9y agoAs long as I know, is not in 'all' their modern CPUs. Just all the CPUs with vPro feature, that aren't the ones used in domestical environments but large businesses.
- deleted 9y ago[deleted]
- hypervis0r 9y agoYou're talking about AMT (which runs on the Intel ME - Management Engine). The ME itself, however, is on every CPU (running Minix on Skylake and later CPUs, ThreadX on earlier models), because one of the responsibilities of the ME, apart from being a backdoor, is to manage the CPU: power it on, handle power signals, etc. The CPU wouldn't run without the ME, so it's necessary that it's on all CPUs.
- kusmi 9y agoExcellent, where can I trade in my ducky for this upgraded version?
- NathanWilliams 9y agoWith physical access to a machine’s USB 3 port, someone could insert running code beneith the operating system, and it wouldn’t know. You could spy on user activity, sniff encryption keys etc
- gpm 9y agoAs well as physical access do you also need to set a bios setting? It isn't entirely clear to me but the background information article linked in this thread seems to suggest yes.
- NathanWilliams 9y agoSorry, I’m not sure, this stuff largely goes over my head. I just understand the basics. If I had to guess, I wouldn’t be surprised if a different exploit is found that bypasses the bios setting to compliment this one.
- beamatronic 9y agoAll your CPU are belong to us