28 ms·
“We have obtained fully functional JTAG for Intel CSME via USB DCI”
- Asdfbla 9y agoAny reason Intel doesn't just offer IME-free CPUs too? There's obviously interest considering the lengths organisations like Google go to to disable it and Intel supposedly already has such offers for governments.
- microcolonel 9y agoME is a useful part of the system. It is in charge of watchdog timers (I think) and mid-level power management. The problem is that it is persistent and opaque. If the operating system were responsible for configuring and managing ME, it would allow it to perform these tasks without being so odious.
- majewsky 9y agoWhy does it need access to all RAM for watchdog timers and mid-level power management?
- cyphar 9y agoIt also facilitates some hardware bring-up, and has management (hence the name) functionalities. So it's not really surprising that it has access to everything. That's not to say that it's at all acceptable that modern machines have such a gigantic security flaw.
- exikyut 9y ago> the lengths organisations like Google go to to disable it TIL about this detail. Where can I learn more? EDIT: So this is now at 0 points. Interesting...
- jjevanoorschot 9y agoA recent talk [0] by Ronald Minnich from Google gives a nice overview of their efforts to replace parts of Intel ME and UEFI with Linux, mostly for security reasons. [0] https://www.youtube.com/watch?v=iffTJ1vPCSo https://www.youtube.com/watch?v=iffTJ1vPCSo
- drewg123 9y agohttps://firmwaresecurity.com/tag/google/ https://firmwaresecurity.com/tag/google/
- mathattack 9y agoThe govt may have forced them into putting it there.
- retrac98 9y agoCan someone explain like I have a degree in computer science from a good university, but opted for a career as a software engineer in some relatively high level languages?
- drdaeman 9y agoIf I got it right, they got a debugger access to the processor that runs ME, via an USB port. So they can mess with ME (dump its code, analyze it, observe how it runs, modify it live) as they see fit.
- Sharlin 9y agoDoesn't help if you don't know what ME is (I didn't). But a sibling comment explained it well.
- vog 9y agoFor a very good explaination on that topic, see the following 32C3 presentation: "Towards (reasonably) trustworthy x86 laptops" https://media.ccc.de/v/32c3-7352-towards_reasonably_trustworthy_x86_laptops https://media.ccc.de/v/32c3-7352-towards_reasonably_trustwor... Also, the paper by the author is worth a read: "State considered harmful - A proposal for a stateless laptop" https://blog.invisiblethings.org/papers/2015/state_harmful.pdf https://blog.invisiblethings.org/papers/2015/state_harmful.p...
- v4n4d1s 9y agoI don't understand your question. Please clarify.
- maxhallinan 9y agoThis is a funny variation on "Explain to me like I'm five years old".
- jimmyswimmy 9y agoI'll give a try. Someone else can correct me later. These guys have used a JTAG f debugging dongle to access the Intel management engine. They can now read every bit of code. Which means that secrets stored within the code including keys and bugs are available to them and anyone who can replicate their work. Since the management engine is in nearly all of Intel chips, we're screwed. AMD have something similar so no help there.
- spchampion2 9y agoDiscussed previously here: https://news.ycombinator.com/item?id=15656931 https://news.ycombinator.com/item?id=15656931
- jlgaddis 9y agoThis particular submission is a dupe: https://news.ycombinator.com/item?id=15656931 https://news.ycombinator.com/item?id=15656931 This one has a bit more info (although not much as far as details go): https://news.ycombinator.com/item?id=15668363 https://news.ycombinator.com/item?id=15668363
- revmoo 9y agoGood.
- dvfjsdhgfv 9y agoOn an unrelated note, did anyone hear about any answer from Intel to Prof. Tanenbaum's open letter? It's high time they pulled their heads out of the sand and started explaining the whole issue.
- onli 9y agoThere wasn't really a pressing issue in there, was there? If we talk about the same letter that was just a "would've been nice if you had told me", now that he knows there is not much left to do for Intel.
- nolok 9y agoWhy do you think would they have to answer him anything? He published something, using a license saying you could use it without telling anyone nor giving back changes, and that's exactly what Intel did. And in his letter he acknowledged that. There was no call nor need for an answer...
- exikyut 9y agoI agree. I think this was Minix's first real-world use case (read: ego validation), and Andrew Tanenbaum was just unimpressed he learned about it by proxy.
- dvfjsdhgfv 9y agoIt's an interesting question. Legally, they don't owe him anything. But from the point of view of social interaction, it's just extremely weird. Imagine someone using the project of your life in something huge, contacting you about some minor details - and then disappearing, so that you learn about it by accident from someone else. It's just strange. Not to mention that if you contact them about it, they should respond. In whatever way. Like, "we're sorry but it was an internal project that we weren't allowed to disclose" kind of way. (Intel guys reading this, it's a good hint!)
- CalChris 9y agoIn principle, how is the Intel Management Engine different from the Apple Secure Enclave coprocessor on iOS devices?
- jzl 9y agoME can see everything coming in on your ethernet port, with no accountability to the host OS. It's like a wiretap, ostensibly for remote control commands, but again with no accountability for what it is up to.
- Confiks 9y agoDoes anyone know if Intel ME being compromised and the recent Tanenbaum letter have anything to do with each other? For example if the researchers discovered the use of Minix through this compromise. The articles referenced in Tanenbaum's blog post don't really reveal the source of the Minix discovery, other than it was due to some recent discovery.
- anovikov 9y agoAnd the main question - did they found anything NSA-ish in there?
- microcolonel 9y agoYou mean finally cracked again.
- cryogenic_soul 9y agoI mean, it is a first time that researchers get full access to the Intel ME firmware, so now it is became possible to reverse engineer it.
- whage 9y agoWhere should I start if I want to dip my toe in this topic? Have a few years of web development experience and a Bsc in software engineering in progress.
- exikyut 9y agoGo google "intel ME" and wade through the results. Optionally use date filtering to progressively skip back through the years. Next, download Minix and get a good handle on it. The next step is getting access to the Minix kernel on the ME, and after that, it'll be a case of who has the best apps for the CPU in their CPU.
- nolok 9y agoAt first it looks nice "oh now we can get rid of it" but it also opens up a very scary near future security-wise. We've now entered a realm where an attacker could simply plug a device on an usb port of your computer for a few seconds to have it access your cpu's ME through USB JTAG and take over it, allowing him to have full access and control over what you do/read/open/type over the network, without you ever knowing it since you can't see it. And the only way to get rid of it for sure would be to pretty much throw that cpu away and buy a new one. Or am I being overly paranoid and there is something I haven't considered that makes this scenario impossible ? EDIT: given the answers I think my main concern wasn't well expressed above. I'm not saying this as in "ME is making it easier to be compromised". That may or may not be true, but that's not my point. My point is, we all know that once compromised, you can't clean it and need to burn it all and start from scratch: recover from backup (not files on the compromised machine), format everything, reinstall. Due to the nature of the ME, this is not a solution here. The cleanup needs to be done at the hardware level. Unless I misunderstood something, once it happens, your cpu is done for, period. And 'using a hack to cleanup the hack' is still in the realm of cleaning up rather than start from scratch, it's not a solution for the same reason than cleaning up your comprised linux box is not one and you need to start from scratch.
- maccard 9y agoI think you're being overly paranoid. If the attacker has physical access to the machine, chances are you're compromised anyway, even before this vulnerability.
- jerianasmith 9y agoThank you so much for your help i really appreciate it.
- TheNewLab 9y agoI think many don't realise that DCI is not supposed to be activated on production CPUs.
- kbeckmann 9y agoSure, but this makes it possible to dump the firmware for further analysis. I think that's the big news here. Think we might read about a few new bugs over the coming months. Also it might be possible to flash new firmware (to lock it down).
- turblety 9y agoIt's a nice thought, but I don't think it'll allow us to flash new firmware. We can already flash firmware on Intel chips, but the firmware has to be signed using Intels keys. The signing verification still happens on the mask rom which is impossible to overwrite. Maybe this discovery will help us understand more how the verification step works. But I think the best we can hope for is a way of overwriting Intel ME very quickly after it's booted every time.
- WhitneyLand 9y agoOne way to think of ME is, we all woke up one day and discovered we have had high resolution night vision spy cams installed in our bedrooms. The next realization is there is no way to turn them off or remove them. It’s posisble even moving won’t help. And yet we really don’t seem to care much. Lesser issues generate national outrage and high volumes of press coverage. Why? HN may be uniquely positioned to show us the answer. Take a community of people with generally above average interest and/or knowledge in this stuff, and the comments are filled with questions asking what the hell ME even is. Apparently, ME is the perfect combination of opaque, obtuse, and obscure. It’s not rocket science, but complicated enough it’s hard to explain well quickly. It’s easy to be a highly technical person yet never have the need to cross paths with the subject. There has been some press, some activity, but all of that is simultaneously dampened for the same reasons.
- inetknght 9y ago> I think HN is uniquely positioned to show us the answer. Take a community of people with generally above average interest and/or knowledge in this stuff, and the comments are filled with I think it's even more sinister: I would argue that a higher percentage of users on HN might be sworn to secrecy about any knowledge they might have anyway. So you end up with very smart people who're either sworn to secrecy or who aren't; those who aren't are asking questions (and very few have answers, and those answers are partial or incorrect). Those who are can't answer them honestly or fully.
- _jal 9y agoIn the past discussions of the ME here and elsewhere, there have always been people making self-assured poo-pooing noises about what a trivial nonissue it is, make deceptive claims about exposure, and then dumb claims about how you can't trust any hardware. They never reply to particular questions that might point out how deceptive the arguments are.
- inetknght 9y agoCall them out on it.
- amelius 9y agoBut ... Perhaps Intel has a second ME installed on the processor. The first one was just a decoy.
- AceJohnny2 9y agoThat would be a hilarious waste of silicon
- amelius 9y agoA ME can be as simple as just another thread context, that is shared with the rest of the CPU. Basically, just a bunch of registers, and some simple logic to activate it.
- mrschwabe 9y agoCompanies like Intel, who are complicit in helping CIA or any intel agency (government, rogue or otherwise) infiltrate and exploit our systems - need to be held accountable by the market. Intel ME and the (assumed [0]) partnership with CIA to design and build this system - should be an absolute travesty blow to the integrity of their business long-term. Will you, as lead engineer or sys admin for your mission critical business now continue to choose Intel products to help build your infrastructure? Unfortunately it seems that our modern market has not yet evolved enough to punish companies involved in such reckless behavior. I suspect the reason is primarily the ease of which governments can mass tax and create fiat currency. Perhaps there is some alternate decentarlized currency system that would limit government's ability to tax, print and award juicy big-brother contracts to these companies. Anyway, for now at best - and perhaps somewhat encouraging - is the subsequent brain drain of engineers and hackers alike who want nothing to do with faceless corporations like Intel, Google, Facebook, IBM, et all who routinely deceive/exploit and work against the best interest of their own customers. [0] https://twitter.com/9th_prestige/status/928740294090285057 https://twitter.com/9th_prestige/status/928740294090285057
- majewsky 9y ago> Companies like Intel, who are complicit in helping CIA or any intel agency (government, rogue or otherwise) infiltrate and exploit our systems - need to be held accountable by the market. At the same time as "buy American"? You're aware that any American chipmaker will be gag-ordered to help the CIA?
- mrschwabe 9y agoFair point, but let's not paint such a bleek picture. Gag-orders are an unfair (unconstitutional?) weapon of tyrannical regimes and should be condemned as so. Aside from taking political action to remove that tool from big brother's arsenal we as hacker/entreprenuers can build systems and strategize on how to mitigate and avoid gag-order scenarios altogether. Perhaps this is pie in the sky but a future where open hardware is as ubiquitous/accessible/easy to use as open source software would make it easier to change chips or gut your laptop and re-build it with hardware that you can trust.
- wslh 9y agoAsk HN: How would you organize an Intel boycott?
- 24gttghh 9y agoFind a manufacturer in Shenzhen who can mass-produce older Intel pre-ME motherboards/CPU die clones and start your own fabrication...
- jarym 9y ago'Intel inside' was clearly not just a marketing slogan but a reference to spy agencies.
- sidcool 9y agoCan someone ELI5 this for me?
- ksk 9y agoIntel created a product (Similar to Dell's iDRAC) which has a co-processor for system admin type stuff. This product and/or associated modules have security flaws. Those flaws can be potentially used to takeover the machine and allow malware to exist outside of the CPU/RAM/HDD architecture and stay undetected.
- reacharavindh 9y agoAh, I’m so glad and proud of the hacker community now. The nasty and opaque backdoor is now out in the open So the researchers can now find a way to close the hole. I have a feeling the current gen intel processors are going to be in demand amongst the security community and privacy conscious users because the newer ones will definitely have an even shittier backdoor in place of the now bust ME.
- throwaway230958 9y agoI worked on what became ME at Intel from the mid 2000s through around 2012 ou 2013. I completely agree that in retrospect, it wasn't the best idea. However, I really want to say that it was never a project for the CIA as some keep saying. This was a widely-marketed product at the time of its inception. It was the whole point of the Intel vPro line. I've been to a ton of roadshows between 2008 and 2009 where the marketing people demoed the heck out of ME to everybody. It was a feature thought to be THE differentiator from AMD. Of course, later AMD came up with their own equivalent and ME became "a commodity" So again, we can all argue whether it was a bad idea, but the notion that it was designed by/with the CIA is simply not true to the best of my knowledge, but I really think I'd know, as I've been to way too many design meetings and saw the decisions being made by Intel engineers.
- cyphar 9y agoI've never bought into the "NSA/CIA made Intel create this" line of reasoning because, as you say, there was a legitimate use for this technology (misguided as its implementation was). Of course, I have no doubt that the NSA/CIA may have added further backdoors, or are withholding vulnerabilities in ME. However, one thing that I've always felt conflicted about is why this feature is present in _all_ CPUs. Usually if someone wants to use Intel's AMT then they have a giant support contract with specialty hardware, so it seems odd that the core CPU feature necessary is present on all CPUs despite no user actually using outside of enterprise. Is it because the bring-up, other low-level stuff, and things like PASP (DRM) were implemented on top of ME, and so it was not considered viable to re-do that on chips that didn't have ME (though I was under the impression that very early ME was not used for anything else)? Or was it just a matter of "it's easier to just use what we have for every chip"?
- jlebrech 9y agowould it be possible to use minix os inside the cpus directly as desktop os or rewrite the firmware or is it read only?
- SEJeff 9y agoAbsolutely fantastic video from a google engineer (and the original author of LinuxBios / Coreboot) on how they replaced the UEFI firmware with Linux to get Dell servers to boot in 20 seconds: https://www.youtube.com/watch?v=iffTJ1vPCSo https://www.youtube.com/watch?v=iffTJ1vPCSo
- f2f 9y agoHere's the presentation slides of the guys who figured it out: https://www.troopers.de/downloads/troopers17/TR17_ME11_Static.pdf https://www.troopers.de/downloads/troopers17/TR17_ME11_Stati...
- kyberias 9y agoLove the Minix slide. It's a wonder this news didn't reach Tanenbaum until recently.
- binaryapparatus 9y agoThis is fantastic news. I expect to see some reliable and easy to apply (usb?) solution to wipe and tame ME. Greatest news is that it works for latest Intel processors so even if they change protection (they certainly will) we at least have very good processors that can work without spyware. All the previous tests I read about only tackled first few generations of Intel ME, for processors/boards over 8 or 10 years old.
- Kliment 9y agoThe core problem with this is that if you have debug access to the core running ME, you can put it back even if it was wiped - or replace it with anything you like.
- waynecochran 9y agoHas anyone used the Intel Management Engine Verification Utility? https://www.intel.com/content/www/us/en/support/articles/000005974/software/chipset-software.html https://www.intel.com/content/www/us/en/support/articles/000...
- kyberias 9y agoI tried it. Didn't find ME on my i5-4690K.
- 0xfeba 9y agoYou can disable all the phone home stuff by not plugging in the ethernet port it uses, eg. using wireless or an add-on card. Or in some motherboards, the secondary ethernet.
- 0xfeba 9y agoWould the downvoter care to state any reasons for disagreeing? The IME only has drivers for a specific ethernet port. They also don't use the secondary ports if equipped, though I imagine that's just a configuration setting.
- campuscodi 9y agoHere's the research team's talk from last year's 33C3 https://www.youtube.com/watch?v=2JCUrG7ERIE https://www.youtube.com/watch?v=2JCUrG7ERIE
- craftyguy 9y agoWait, the screenshot shows that they are using ITP/DAL.. I didn't think that was publicly available. Is this true? If so, then what they have done is only something an OEM, with appropriate permission from intel, could do.
- Kliment 9y agoSome motherboard vendors host downloads of it, whether they're allowed to or not is irrelevant at this stage, it's out in the wild.
- kyberias 9y agoIf someone told me that most Intel processors are internally running MINIX I would have laughed but there you go: http://www.cs.vu.nl/~ast/intel/ http://www.cs.vu.nl/~ast/intel/ Anyway, how do I know whether my CPU has it and is vulnerable via USB?
- SideburnsOfDoom 9y agoIf you are finding the jargon in that tweet too dense (JTAG? ME?), these articles cover the same with more explanation https://thenextweb.com/security/2017/11/09/researchers-find-almost-every-computer-intel-skylake-cpu-can-owned-via-usb/ https://thenextweb.com/security/2017/11/09/researchers-find-... https://www.theregister.co.uk/2017/11/09/chipzilla_come_closer_closer_listen_dump_ime/ https://www.theregister.co.uk/2017/11/09/chipzilla_come_clos...
- userbinator 9y agoNow that we know for sure people who have worked on or are working on Intel ME actually read and post here, I'd like to take the opportunity to refer those of you to a previous post of mine about it: https://news.ycombinator.com/item?id=15120207 https://news.ycombinator.com/item?id=15120207 If you choose to defect and leak all the information you can, you will almost certainly be greatly praised for it by many. Of course there will be negative consequences, but no one ever said that standing firm and adhering to your morals was easy. Maybe if enough employees stood up for what they think is right instead of continuing to silently comply like slaves and let --- or even assist --- companies and governments slowly take away their freedom and privacy, there would be some actual change happening.
- madez 9y agoWhile a leak would make the situation much better, the problem with Intel would still be there. They would change the keys for the next generation of chips, harden their backdoor and keep on rolling. Intel itself is a problem here.
- yuhong 9y agoAndy Glew had a post: http://blog.andy.glew.ca/2017/05/intel-iamt-bug-strncmptrusteduntrusteds.html http://blog.andy.glew.ca/2017/05/intel-iamt-bug-strncmptrust...
- deleted 9y ago[deleted]
- _nedR 9y agoApparently Intel ME can be killed by setting an undocumented flag discovered by the same group? https://www.csoonline.com/article/3220476/security/researchers-say-now-you-too-can-disable-intel-me-backdoor-thanks-to-the-nsa.html https://www.csoonline.com/article/3220476/security/researche... Anybody can shed light on this tool and whether it can mitigate the attack mentioned in the tweet?