4 ms·
They wouldn't. As I said, this is to the best of my knowledge. However, I believe I would know because it's not like one day the CEO came to us with a folder f
by throwaway230958 9y ago
They wouldn't. As I said, this is to the best of my knowledge.
However, I believe I would know because it's not like one day the CEO came to us with a folder filled with requirements to be implemented. This is something that started very small ("find a way to force reboot a PC remotely if it's non-responsive") and evolved from there over months/years. I endured way too many meetings were design decisions were made. Unless there were secret CIA agents disguised as my colleagues, I really believe it was designed by Intel engineers all the way through.
I have no issues with people criticizing the product for its failures. I agree with them. But every time I see someone claiming this was a CIA thing, it actually hits me personally.
Then again, I'll never be able to convince anyone of anything. I just felt like saying something this time.
I guess I'm having a bad morning :)
- criddell 9y ago> Unless there were secret CIA agents disguised as my colleagues That's a thing actually. > I'll never be able to convince anyone of anything. I believe you. Conspiracy theories are fun but ultimately I know that secrets are hard to keep secret.
- fragmede 9y agoI believe you. But looking at the International Obfuscated C Code Contest (http://www.ioccc.org/ http://www.ioccc.org/) entries, and knowing how much I have to force my eyes not to glaze over whenever a college sends me a 700 line pull-request, if one of your colleagues waited until the deadline to send a massive pull-request for their part of the project, can you say that the deadline is pushed back until every single line is meticulously analyzed by hand, to assert that nothing nefarious could possibly happen with their code? Just one of your coworkers would need to believe in a greater purpose, for king and country, and grown up in a large family with a brother or cousin who's a part of the intelligence community. It sounds far-fetched, but so does the Bay of Pigs.
- deleted 9y ago[deleted]
- ddalex 9y agoHaving worked for Intel (in the open source org) I trust you. I've seen first hand how a cool, small, simple feature is blossoming into something dr. Frankenstein would be proud of. Also, I think people here severely underestimate the red tape and huge efforts needed to implement something mildly complex, Intel scale. Developing ME under wraps with full CIA-like functionality is staggeringly difficult - I've seen the effort needed getting the BIOS to work on the prototype boards without crashing or destroying the HW; pulling ME to work reliably on all boards would be one order of magnitude harder; making it spy CIA-style - add two more orders of magnitude. I think people don't really understand how difficult is to get something that close to the metal work reliably; able to poke inside the memory of a running OS - forget about it. Also, I think the readers of HN severely overestimate the effort CIA needs to spy on the internet users - why even try to bug the firmware when people actively share their privacy via apps that they themselves install???
- cyphar 9y ago> I've seen first hand how a cool, small, simple feature is blossoming into something dr. Frankenstein would be proud of. Complete aside, but the whole story of Frankenstein is about how Dr. Frankenstein is repulsed by his actions the moment that he brings the monster to life. So he most certainly wasn't "proud" of his actions, he was horrified by them. But I agree that this is likely how some of the engineers who worked on Intel ME would feel too. > why even try to bug the firmware when people actively share their privacy via apps that they themselves install??? We know (thanks to Snowden and WikiLeaks) that the NSA and CIA have programs like this, so it's actually more incredible that you don't believe that the CIA or NSA would invest resources in adding backdoors to things like Intel ME. I don't buy that they designed it, but given that we know they intentionally sabotage internet standards it's very likely they sabotaged it in some manner. Or at the very least they have security vulnerabilities they are not disclosing, so they can exploit them.
- ddalex 9y ago> So he most certainly wasn't "proud" of his actions, he was horrified by them. In the end, yes. But the novel starts with him being so proud of the golem that he takes it home with disastrous results. Hmmm, maybe the comparison to ME isn't that far-fetched. > I don't buy that they designed it Yep, this is what I'm saying - it's unlikely that they ever told Intel "put this in there". > it's very likely they sabotaged it in some manner. Or at the very least they have security vulnerabilities they are not disclosing Absolutely, yes. They would be vastly incompetent not to have them, in fact. What I don't agree about with HN crowd is the threat profile of such an exploit. I have trouble believing that they use them on a mass-scale. There are so many people looking at the ME, that using any exploit on a massive scale would disclose it almost immediately, and allow the 'enemy' to develop protections. Given the extraordinary capabilities of such an exploit giving it a very valuable status, they probably need to protect it, and will use it only when absolutely necessary; such as the vast, vast majority of the HN users would not ever be subjected to such an exploit. On the other hand, if your person is interesting enough to NSA to deploy such an exploit against your devices, probably you have vastly more significant problems, like trying to stay outside the visual range of a Predator drone. If any Three Letter Agency will deploy such an exploit against your PC, you can be absolutely sure that they have already bugged your phones, and not with a Stinger device, but tapping directly into the data feed at the phone exchange. Probably you have to incinerate your trash because the garbage men are spooks - this is the kind of threat that I assume you're facing if a TLA is trying to bug your ME.
- pdkl95 9y ago> a folder filled with requirements That's not how the intelligence agencies operate. > evolved from there over months/years THIS is how they influence standards and design choices. We know that in 2013 the NSA budgeted at least $250M to programs such as "BULLRUN" that which intended to "Insert vulnerabilities into commercial encryption networks, IT systems, and endpoint communication devices..."[1]. For an example of how this works, see John Gilmore's description[2] of how the NSA influenced IPSEC. They don't use a folder of requirements; instead they gain influence over enough people to complain about "efficiency" or other distractions and occasionally add a confusing or complicated requirement that just happens to weaken security. PHK gave an outstanding talk[3] that everyone should see about the broader subject of how the common model most people have about how the NSA works is obsolete. [1] http://www.nytimes.com/interactive/2013/09/05/us/documents-reveal-nsa-campaign-against-encryption.html http://www.nytimes.com/interactive/2013/09/05/us/documents-r... [2] https://www.mail-archive.com/cryptography@metzdowd.com/msg12325.html https://www.mail-archive.com/cryptography@metzdowd.com/msg12... [3] https://archive.fosdem.org/2014/schedule/event/nsa_operation_orchestra/ https://archive.fosdem.org/2014/schedule/event/nsa_operation...
- julian_1 9y agoDo you know technical details - like how many processes are even running under the Minix OS? Also which internal or external groups lead the code development of those processes? Is the code accessible to any employee/engineer with a technical relationship to IME?