5 ms·
I worked on what became ME at Intel from the mid 2000s through around 2012 ou 2013. I completely agree that in retrospect, it wasn't the best idea. However, I
by throwaway230958 9y ago
I worked on what became ME at Intel from the mid 2000s through around 2012 ou 2013.
I completely agree that in retrospect, it wasn't the best idea. However, I really want to say that it was never a project for the CIA as some keep saying.
This was a widely-marketed product at the time of its inception. It was the whole point of the Intel vPro line. I've been to a ton of roadshows between 2008 and 2009 where the marketing people demoed the heck out of ME to everybody. It was a feature thought to be THE differentiator from AMD. Of course, later AMD came up with their own equivalent and ME became "a commodity"
So again, we can all argue whether it was a bad idea, but the notion that it was designed by/with the CIA is simply not true to the best of my knowledge, but I really think I'd know, as I've been to way too many design meetings and saw the decisions being made by Intel engineers.
- cyphar 9y agoI've never bought into the "NSA/CIA made Intel create this" line of reasoning because, as you say, there was a legitimate use for this technology (misguided as its implementation was). Of course, I have no doubt that the NSA/CIA may have added further backdoors, or are withholding vulnerabilities in ME. However, one thing that I've always felt conflicted about is why this feature is present in _all_ CPUs. Usually if someone wants to use Intel's AMT then they have a giant support contract with specialty hardware, so it seems odd that the core CPU feature necessary is present on all CPUs despite no user actually using outside of enterprise. Is it because the bring-up, other low-level stuff, and things like PASP (DRM) were implemented on top of ME, and so it was not considered viable to re-do that on chips that didn't have ME (though I was under the impression that very early ME was not used for anything else)? Or was it just a matter of "it's easier to just use what we have for every chip"?
- pault 9y agoI really don't understand why I have to pay out the nose for ECC memory support but I get this surveillance device "for free".
- slobotron 9y agoOfficially, you still need to pay extra to enable the remote management capabilities of ME...
- 0xfeba 9y agoThe NSA added a option bit to the firmware to allow them to turn it off on their computers. https://www.bleepingcomputer.com/news/hardware/researchers-find-a-way-to-disable-much-hated-intel-me-component-courtesy-of-the-nsa/ https://www.bleepingcomputer.com/news/hardware/researchers-f...
- yborg 9y agoIt makes perfect sense in the enterprise space to facilitate the illusion of management control (there is a good reason the IT dept trope is so widespread). LOM has been a thing on servers since forever. And absent some enormous financial incentive, it's absurd to think that Intel would go through this much trouble to architect something like this with a primary goal of providing American three letter agencies a backdoor. On the other hand, the magic killswitch you guys put in equally obviously was requested by them, this thing basically makes anything with an Intel desktop CPU unusuable in a high-security context. But given the already well-known threat model at the time this thing was conceived of self-propagating malware, creating a technology that is embedded in every single device with a desktop CPU that can't be turned off, makes the device unusable without it, and has remote compromise bugs that can succeed while the target is "off" was certainly a bad idea.
- kaffeemitsahne 9y ago>but the notion that it was designed by/with the CIA is simply not true to the best of my knowledge Seems irrelevant. The internet and smartphones were also not created by the CIA/NSA for mass surveillance, yet the 3 letter guys still uses those technologies for mass surveillance very successfully.
- kodablah 9y agoThree questions if you don't mind (and feel free to speculate yourself or anyone else): 1. Many features have options to be disabled (e.g. bios settings). Why doesn't this, even to this day? 2. You may have been involved in implementation, but do you know why it still exists on every board regardless of backlash? 3. I am a bit ignorant, does the chip fabbing process justify putting this on every board instead of just on enterprise ones (especially since you can consider it a feature worth upcharging for)? Pardon my skepticism, but its continued use without the ability to disable speaks to ulterior motives regardless of original implementation design.
- periya 9y agoI can answer 2 and 3. 2. IMHO I don’t think there is enough backlash yet. The average consumer is not informed about this yet. I guess this will change over the next couple of months since I’ve been reading a lot more about ME. 3. The chipset is fabbed irrespective of the SKU. Creating a separate floor plan for non enterprise parts is not cost effective , it’s easier to fab every SKU alike and then fuse out features based on the SKU.
- FLUX-YOU 9y ago>However, I really want to say that it was never a project for the CIA as some keep saying. Probably not a rubber stamp with "CIA" on top of the project documentation, but someone on the team could have been talking to the intelligence community and relaying specs or meeting details. It's an obvious target just because of Intel's ubiquity and they are based in the US. You're kind of a bad intelligence agency if you don't try for backdoors to this level on processors running millions of devices world-wide. And the intelligence community has actively tried to stop good encryption from spreading while promoting bad encryption/RNG (forgive me for not knowing the details), and so it's pretty clear they are willing to compromise worldwide standards in favor of gaining an edge.