6 ms·
> Intel ME and the (assumed [0]) partnership with CIA to design and build this system I worked at Intel on ME and the things that came before it until around 2
by throwaway230958 9y ago
> Intel ME and the (assumed [0]) partnership with CIA to design and build this system
I worked at Intel on ME and the things that came before it until around 2013. I can tell you two things --
1. No, Intel ME wasn't born out of a desire to spy on people nor was it -- to the best of my knowledge but I honestly believe I would know -- created at the request of the US government (or others). It was an honest attempt at providing a functionality that we believed was useful for sysadmins. If it was something done for the CIA, I believe it would probably have been kept secret instead of marketed.
2. It was initially going to be much "worse". Early pilots with actual customers -- such as a large british bank -- were going to run a lot more stuff -- think a full JVM -- and have a lot more direct access to the user land.) Security concerns scrapped those ideas pretty early on though.
In retrospect, I personally believe the whole thing was a bad idea and everybody is free to crap on Intel for it. But the thing was never intended as a backdoor or anything like that.
- chinathrow 9y agoregarding 1): hiding in plain sight is sometimes a valid strategy. So is heavy compartmentalization.
- orliesaurus 9y agowow, thought the exact same thing haha
- mrschwabe 9y agoKudos for speaking up about it, understandably with a throwaway account - which unfortunately doesn't help prove what you say is in any way truthful. But you probably still work for them and enjoy a nice salary. So can't blame you at all there. But I do just wish more people would be willing to put their careers on the line to say the right thing. This is one of the underlying problems: when smart people go along with bad things, very bad things can and will happen - if on the contrary smart people speak out about bad things then those bad things will be less likely to unfold on a large scale as we see them happening so often in SV. To your points though, I mean it is a great perspective and helps to illustrate a sliver of possibility of innocence here on Intel's part but it's a little weak given that the operation would have been compartmentalized and political objectives/partnerships therof obviously not part of the system's technical development.
- zAy0LfpBZLC8mAC 9y ago> But you probably still work for them and enjoy a nice salary. So can't blame you at all there. Why not? Is a salary a good ethical justification for mistreating other people?
- mrschwabe 9y agoWell, you're right salary is not justification for mistreating other people but I can at least sympathize with OP who has maybe rationalized going along with something shady because he himself was mistreated/deceived and perhaps wants to believe ME is not a tool for exploitation; for many 'ignorance is bliss' is a way of life that works for them so it is what it is.
- azernik 9y agoOP's explanation is that this was a shitty decision, made for decent reasons. So... no? But that's not a relevant question?
- revmoo 9y ago> No, Intel ME wasn't born out of a desire to spy on people This is utterly impossible to believe
- orliesaurus 9y agoOk, however: sometimes to hide a thing, all you've gotta do is...you just hide it in plain sight and give it a slightly different "color scheme"
- stevenh 9y agoWhy would they do something as ridiculous as telling you its true purpose?
- throwaway230958 9y agoThey wouldn't. As I said, this is to the best of my knowledge. However, I believe I would know because it's not like one day the CEO came to us with a folder filled with requirements to be implemented. This is something that started very small ("find a way to force reboot a PC remotely if it's non-responsive") and evolved from there over months/years. I endured way too many meetings were design decisions were made. Unless there were secret CIA agents disguised as my colleagues, I really believe it was designed by Intel engineers all the way through. I have no issues with people criticizing the product for its failures. I agree with them. But every time I see someone claiming this was a CIA thing, it actually hits me personally. Then again, I'll never be able to convince anyone of anything. I just felt like saying something this time. I guess I'm having a bad morning :)
- criddell 9y ago> Unless there were secret CIA agents disguised as my colleagues That's a thing actually. > I'll never be able to convince anyone of anything. I believe you. Conspiracy theories are fun but ultimately I know that secrets are hard to keep secret.
- fragmede 9y agoI believe you. But looking at the International Obfuscated C Code Contest (http://www.ioccc.org/ http://www.ioccc.org/) entries, and knowing how much I have to force my eyes not to glaze over whenever a college sends me a 700 line pull-request, if one of your colleagues waited until the deadline to send a massive pull-request for their part of the project, can you say that the deadline is pushed back until every single line is meticulously analyzed by hand, to assert that nothing nefarious could possibly happen with their code? Just one of your coworkers would need to believe in a greater purpose, for king and country, and grown up in a large family with a brother or cousin who's a part of the intelligence community. It sounds far-fetched, but so does the Bay of Pigs.
- ska 9y agoto the best of my knowledge but I honestly believe I would know Honestly, if a three letter agency was working with a tech company to produce a back door, the last people I would expect to know would be most of the engineers involved in the implementation.
- kyberias 9y ago> Honestly, if a three letter agency was working with a tech company to produce a back door, the last people I would expect to know would be most of the engineers involved in the implementation. Who would the first people be then?
- deleted 9y ago[deleted]
- Skunkleton 9y agoIf I were a 3 letter agency with a large budget, I would insert someone as a project manager at the target company. If I couldn't do that, I would work with their C level folks.
- AnonymousPlanet 9y agoPreferably no one in the implementing company. Work using customer pressure, say an important bank. And later you swoop in and get exclusive access during a nice and cozy dinner with one of the Cs. It's more like judo than brute force arm twisting.
- daxorid 9y agoRight. ME does make sense as a feature for sysadmins. Except . . . . Well, can you shed light on the following: 1. Why did your team deem it necessary to deny the end-user the capability to disable this feature? 2. Why did your team decide to enable ME on ALL consumer grade chips? You could have only enabled it on, say, Xeon, as a value-add - exactly like you do for ECC support. You could have made more money this way. But . . . you didn't. Without legitimate, sensical answers to the above questions, there is no reason for anyone to believe your team did anything other than design a backdoor for the Feds. Sorry.
- jschwartzi 9y agoI'm not OP, but to respond to question 1, allowing users to disable the feature would also allow attackers to disable the feature. If you're relying on ME to provide remote access so that you can clean and repair infected machines, then it's game over for you if the attacker can disable ME. It would have made much more sense to require you to enable it before first use, and ship it as disabled from the factory. Enablement should work like blowing an eFuse where it's never off once it's turned on, but if you never turn it on it doesn't exist. Then I don't have to worry about the feature unless I know exactly what it is and how to use it.
- nickpsecurity 9y ago"I'm not OP, but to respond to question 1, allowing users to disable the feature would also allow attackers to disable the feature." Older products had jumpers, physical switches, or software mechanisms for securely updating firmware. The first two are immune to most types of remote attacks if done in hardware. Intel already uses signed updates for microcode which people aren't compromising remotely left and right. Intel supporting a mechanism like those that already existed in the market for disabling the backdoor would not give widespread, remote access to systems. If anything, it would block it by having less privileged, 0-day-ridden software running. I'll also note that the non-Intel market, from OpenPOWER to embedded, has options ranging from open firmware (incl Open Firmware itself) to physical mechanisms to 3rd-party-software. Intel is ignoring those on purpose for reasons they aren't disclosing to the users that also probably don't benefit them.
- kazagistar 9y agoWhy doesn't Intel offer their chips without an ME, as an option? The mandatory nature makes it malicious.
- MBCook 9y agoWhat percentage of people would really want that? The vast majority of consumers don’t know/care. Or it’s sold as a feature. Most businesses probaby WANT the feature. See other comments in this discussion about lights-out management. I’m guessing t wouldn’t be economically worth it.
- confounded 9y agoIf you’re not using it, then it’s a big unpatched vulnerability. I’ve never worked anywhere that uses it, although I’m sure a few places do.
- openasocket 9y agoSaves money to have only one assembly line of chips. Hell, the i5 chips they make now are just i7s with some of the features disabled. So if they make an i7 and there's an error in some part of the chip that's specific to the i7 features, they can disable the i7 parts and sell it as a working i5. At least this is what I recall from an article a year ago on here about that.
- thisacctforreal 9y agoThis is known as the “Silicon Lottery”
- criddell 9y agoThere are parts of ME that you need (like the BUP module for configuring on boot).
- valarauca1 9y ago> > Intel ME and the (assumed [0]) partnership with CIA to design and build this system Then why do you need security clearance to work on Intel ME?
- dmitrygr 9y agoDo you have a citation for that? That sounds interesting
- jlgaddis 9y agoThe "citation" is a Twitter post [0] that included a screenshot of an anonymous post to 4chan by a supposed Intel employee who claims to have worked on the Management Engine team for the last three years. It was linked upthread. [0]: https://twitter.com/9th_prestige/status/928740294090285057 https://twitter.com/9th_prestige/status/928740294090285057
- dmitrygr 9y agoThank you. That is worrisome.
- ZenoArrow 9y agoThink about it logically for a second. Regardless of the decisions that led up to the inclusion of Intel ME in Intel CPUs (i.e. regardless of whether the CIA was involved or not), compromising Intel ME is still a security risk for Intel customers, so of course they're going to limit access to a select few that they trust, and that the government can trust. I'm fairly certain similar restrictions will also apply to those who are granted access to knowledge about CPU microcode, which is an equally large security risk that nobody with even a basic understanding of how CPUs work is blaming on the CIA.
- valarauca1 9y agoSecurity though obscurity doesn't work.
- Dolores12 9y agoWhy not make a physical turn off switch on motherboard to disable it?
- julian_1 9y ago> were going to run a lot more stuff -- think a full JVM Is a JVM really a lot more stuff than Minix OS?
- sametmax 9y agoMan, anybody with a remote idea of how IT works would have said it was a very bad idea. I can't believe in genuineness here. Nobody smart enough to design that system is dumb enough no not understand the consequences. So it's been knowingly decided to create this monster and ship it to the entire world.
- jlgaddis 9y agoUnfortunately, in the real world, many times those of us who do have a remote idea suggest that things are "very bad ideas" but nonetheless get ignored by those who actually make the decisions.
- pksadiq 9y ago> Nobody smart enough to design that system is dumb enough no not understand the consequences. Do you remember the plain text password leaks from Yahoo? In the real world nothing has to be true/good/secure. All it has to be is that users should be felt so, doesn't matter what the reality is. As long as the focus is on earning more money/power/control, this is always going to happen.
- dawnbreez 9y agoIt should've only been sold on a special "business class" series of CPUs. Intel already loves having dozens of variants, as evidenced by recent market offerings; and it's not like they don't already have dedicated business-class CPUs for workstations. Simply only sell ME as an "addon" tier, and that limits the potential damage. Incidentally, did you hear about Silent Bob is Silent? What are your thoughts on that vuln?
- pksadiq 9y ago> If it was something done for the CIA, I believe it would probably have been kept secret instead of marketed. If that is the case, we would have doubted about this too much early than it would otherwise (because there is a dedicated hardware). So some people friendly feature have to be dubbed along with the anti-features. This may not be the real case though, but one of the possibilities.