10 ms·
How Purism avoids Intel’s Active Management Technology
- shmerl 6y agoLooking forward to AMD laptops with Coreboot support as well.
- fsflover 6y agoProbaly won`t happen since AMD have their own secret code which no one could neutralize yet.
- shmerl 6y agoSupposedly it's already in the works: https://twitter.com/jeremy_soller/status/1286457590289858560 https://twitter.com/jeremy_soller/status/1286457590289858560
- nullc 6y agoWelp. Their response to Raptor in that thread just forever cost System76 my business. System76 takes the position that compatibility with x86 binaries is worth having to take closed, remote-access-enabled, binary firmware. That's a position someone can take. Responding "So what?" and "I was expecting this" is just nasty and unprofessional.
- shmerl 6y agoYeah, that was strange. Sounds like there is some argument history behind it.
- kbenson 6y agoIt does read like that, but even so, the initial question from Raptor Computing Sys was very well worded and not disrespectful at all. The inability to at a minimum leave it as "We've covered this before, and disagree on some items. We'll have to agree to disagree and leave it at that." or even "I'm doing what I can, we'll see where it ends up in the end" or "See the official account for official statements" is the troubling part. Then a gain, that doesn't appear to be uncommon on Twitter, where everyone seems to have trouble disambiguating their professional and personal lives, and those of the people they are responding to (which is related).
- wizzwizz4 6y agoTo be fair, I can see why > Even if you do port coreboot was read as abrasive; that tweet can be read as a snarky attack that belittles the efforts of the porter, to which the "so what?" response is apt – in fact, a de-escalation. And yet, in reality, it wasn't one. (This is why you assume good faith, people!)
- kbenson 6y ago>> Even if you do port coreboot > was read as abrasive; that tweet can be read as a snarky attack that belittles the efforts of the porter I guess, because it allows for the chance that someone may not finish what they set out to do? > to which the "so what?" response is apt – in fact, a de-escalation "so what" is not a useful path to de-escalation. It's a way of saying "you've said your point and I don't think any of it applies, but I'm not going to explain why, nor even go to the length of explaining this to you, and instead respond with two words." It is, at it's core, dismissive, and that's not a useful way to de-escalate (even though I admit some people seem to think it is). What people don't seem to understand that that colloquial speech used with a friend is often dismissive in exactly this way, on purpose, because when you can actually assume good faith because of lots of prior interactions, it speeds up communication. > And yet, in reality, it wasn't one. Yeah, as I noted above, it very rarely is. The only times I think it can be used safely are when the people in question know each other well enough to know the other person is not being condescending and dismissive, and even then it's easy to be interpreted as that when the discussion is heated. In those cases, it sometimes takes people cooling off to assess the conversation more rationally and see what's actually the more likely intent in the phrase. > (This is why you assume good faith, people!) Good faith is useful, and necessary, but it really works best when only a little faith is needed in the first place. Since you can only assume good faith for yourself, it's also in your own self interest to make sure you limit the ways in which you speech can be misinterpreted. Often that means being a bit more formal so misunderstandings based on tone and familiarity are more rare. That's a shame, because sometimes we want to show friendship through our words, but that's much harder to do in pure text. Smiley's and emoticons can actually go a long way towards correctly communicating intent in these cases. Sorry for the rant, I used this as a way to solidify some of my thinking on the subject. :)
- Godel_unicode 6y agoThat's not System76 account. It's a personal account of one person who has a history of being harassed by Raptor. Raptors tweets were from their official account, and your reaction was the exact goal of their antagonism.
- boring_twenties 6y agoRecent (1-2 years?) AMD BIOS supports disabling the Platform Security Processor (their ME equivalent). I haven't been able to figure out what exactly this means, but it does seem to be disabled after system initialization. Kind of like Intel's HAP bit, except user-settable.
- floatboth 6y agoEither like the HAP bit, or less — only disabling its visibility to the OS on the PCIe bus.
- boring_twenties 6y agoYeah, I'm a little confused as to why they'd bother implementing and deploying this feature without even a cursory explanation of what it does...
- numpad0 6y agoMaybe it’s literally classified
- LargoLasskhyfv 6y agoI found [1] https://www.igorslab.de/en/inside-amd-bios-what-is-really-hidden-behind-agesa-the-psp-platform-security-processor-and-the-numbers-of-combo-pi/ https://www.igorslab.de/en/inside-amd-bios-what-is-really-hi... to be a good explanation. Essentially it's the crank which brings up the rest of the SOC. The other functions are optional, but no booting possible without it.
- boring_twenties 6y agoThanks for that! This is quite relevant to me right now as I'm thinking about my next upgrade. Obviously, I'd prefer to buy AMD, especially if this disable switch is legit. But grotesquely, I'm still considering going with Intel, because at least I know I can use me_cleaner there, and more or less understand exactly what it does. Hopefully this document will clear some of that up.
- clmgs 6y agoAMD has a similar backdoor: https://en.wikipedia.org/wiki/AMD_Platform_Security_Processor https://en.wikipedia.org/wiki/AMD_Platform_Security_Processo...
- _kbh_ 6y agoI would argue that the out of band management provided by DMTF DASH is closer to what people consider then Intel backdoor then the AMD PSP. The PSP cannot be accessed remotely and is only available locally which removes most of the attack surface. https://www.amd.com/system/files/documents/out-of-band-client-management-overview.pdf https://www.amd.com/system/files/documents/out-of-band-clien...
- R0b0t1 6y agoDisabling is not removing. People have found motherboards that should ostensibly not support vPro (e.g. Asus gaming motherboards) that do report vPro ME functionality. There is no reason to believe the software switch is working, especially when even a system integrator can accidentally enable the features. If someone wants them on they turn on. Purism sells snakeoil. Presenting their offerings as FOSS-compatible would be honest. Claiming additional security is not.
- fsflover 6y agoEven though it`s true that ME is not 100% removed, most of it is. https://puri.sm/learn/software-freedom-in-perspective/ https://puri.sm/learn/software-freedom-in-perspective/
- R0b0t1 6y agoME hasn't been removed at all. The hardware is still on the machine.
- teddyh 6y agoThat’s a useless definition of “removed”; using that definition, ME can never be “removed” at all! But that’s not what we’re talking about here. A more useful definition would be to use “removed” as in “not a security problem anymore”.
- R0b0t1 6y ago> using that definition, ME can never be “removed” at all! This is my point. It can't be removed. It will always remain a security problem.
- dongvsascript 6y agothat's like saying having a flimsy house door lock lying in your kitchen drawer is a security problem. you have hardware on the cpu no longer accessible by software. you have a mellanox network card the me can't talk to. it's there, in the kitchen drawer. it's no longer in the door -so not a security problem. the 'issue' requires physical access to the machine, and for you to be logged in with an admin account. if someone is physically sitting next to your server and logged in as root, you have no security anymore. they don't need to break into anything, the can just run what they want already. someone is in your car with keys in the ignition. you're saying they can steal your car by hacking the entertainment system because it's insecure.
- kelnos 6y ago> We choose Intel CPUs that do not have vPro The Wikipedia article they link about vPro says: > Intel vPro technology ... [includes] VT-x, VT-d... Does this mean that Purism hardware won't support virtualization extensions? Seems like that would be a big downside, and would make it a non-starter for a lot of people (including myself).
- rzzzt 6y agoThe second sentence on Wikipedia says: When the vPro brand was launched (circa 2007), it was identified primarily with AMT, thus some journalists still consider AMT to be the essence of vPro. (They have also added a small asterisk to the Purism article to clarify - I'm also just reading it now so don't know if it was there before)
- sukilot 6y agoYou have dig past the marketing labels and into the actual specs. Some CPUs have VT-x but not vPro https://ark.intel.com/content/www/us/en/ark/products/149091/intel-core-i7-8565u-processor-8m-cache-up-to-4-60-ghz.html https://ark.intel.com/content/www/us/en/ark/products/149091/...
- floatboth 6y agowhere "some" means pretty much all consumer CPUs.
- Godel_unicode 6y agoThat's absolutely not true, there are a ton of modern consumer CPUs with vpro. Here's a comparison of the 10500 through the 10900{,k}, all of which have vpro. https://ark.intel.com/content/www/us/en/ark/compare.html?productIds=199316,199335,199311,199332,199273,199328,199277 https://ark.intel.com/content/www/us/en/ark/compare.html?pro... Here's the more complete list of Core processors which have vpro platform eligibility. It's quite long. https://ark.intel.com/content/www/us/en/ark/search/featurefilter.html?productType=873&0_VProTechnology=True&1_Filter-Family=122139 https://ark.intel.com/content/www/us/en/ark/search/featurefi...
- mietek 6y ago(2017)
- seemslegit 6y agoWhat are the odds that the chips that don't feature AMT/ME don't have it physically as opposed to it just being crippled in firmware ? In which case if one is worried about government backdoors this should alleviate exactly zero concerns.
- wmf 6y agoThis topic is well understood so there's no need for "odds". All the chips have ME. AMT is a firmware feature that can be removed or not bought.
- cantrevealname 6y agoI've been hearing about Intel’s Active Management Technology for years, but I'd like to see a demonstration of how an attack would work. I have an unused laptop with: 1. an Intel CPU that supports the vPro feature set 2. an Intel networking card 3. the corporate version of the Intel Management Engine (Intel ME) binary (well, definitely, a corporate laptop that used to get updates, but how do I check for ME?) Is there a website I can visit that can initiate a remote takeover (I'm consenting to it)? Why isn't this possible? What other step is required on my side to make it possible? Is it possible only through the physical ethernet connection? Why aren't we seeing wide scale exploits based on AMT?
- fsflover 6y agohttps://news.ycombinator.com/item?id=16238765 https://news.ycombinator.com/item?id=16238765
- threatripper 6y agoAbsence of evidence is not the evidence for absence. If the backdoor exists you will need to know a secret to open it. Currently, the public obviously doesn't know this secret or the doors would be wide open for virtually anybody. Because we don't know the secret key, we cannot open them to prove that they exist. So we don't know for sure if the backdoors exist. But the way the IME is designed and handled makes it possible and plausible that backdoors could exist. It's up to Intel to prove that they don't exist.
- selectodude 6y ago>It's up to Intel to prove that they don't exist. That seems a bit over the top to ask them to prove a negative.
- alasdair_ 6y agoReleasing the code would allow people to verify it.
- 6y ago
- closeparen 6y agoI hear a lot about disabling the management engines... what about activating them for yourself?
- rzzzt 6y agoYour computer could run Linux or Doom even while it's off!
- stallmanite 6y agoThe idea of gaining control of the management hardware like this is really exciting. Can anyone here comment on whether it could plausibly happen? I’m guessing it would require leaks from Intel because otherwise whoever develops the capability would presumably keep it close to the vest or sell it for major $ right?
- closeparen 6y agoI just mean, rather than leaving your computer with a powerful remote administration system un-configured & ready to go with a default password, provision it yourself, set the passwords, maybe even use it.
- wmf 6y agoThe ME is running Minix/x86 and presumably a vulnerability could be used to inject new code that isn't signed by Intel. But what would you do with it? Why not just use the OS?
- stallmanite 6y agoI can’t put it into words well but it’s like if I discovered a vestigial limb attached to my body. I’d want to try firing it up.
- m463 6y agoBut will it bitcoin mine for someone else when it's off?
- neilv 6y agoPurism just needs TrackPoint and thicker keyboards, and I can upgrade my stockpile of ThinkPads. :) https://www.neilvandyke.org/coreboot/ https://www.neilvandyke.org/coreboot/
- sscarduzio 6y agoThe trackpoint is the single reason I never bought a Thinkpad.
- phreack 6y agoIt's an acquired taste, but luckily also very easy to ignore in my experience.
- NikolaNovak 6y agoIt's certainly one of those "acquired tastes", though like with 3.5mm elimination, I don't understand the sheer vitriol against it by those who happen not to use it. Why do you care? If everything else in Thinkpad appealed to you, why would an eminently ignorable feature be such a HUGE ("single reason") deal breaker? In my mind, either a) There are other reasons and this is a convenient conscious or subconscious scapegoat; or b) it's an extremely emotional decision, and as such certainly relevant to holder ("Whatever floats your boat!":) but not necessarily applicable or translatable to anybody else. I'd be curious (genuinely!) to hear more - were you actually tempted by any Thinkpads in the past but rejected them due to trackpoint, and if so can you elaborate why - what use case did they prevent or what inconvenience did they cause? Thx muchly! :)
- Godel_unicode 6y agoThe trackpoint is ugly. It's a giant throwback pimple in the middle of the keyboard, which there's no way to get around looking at all the time. Thinkpads being ugly is kind of their thing, so it doesn't surprise me that lots of Thinkpad people don't mind it or even see it as a plus, but to me seeing a trackpoint is like seeing a floppy drive. I used one for years, and I'm really happy that trackpads have gotten good enough that I'll never need to use one again. Edit: display notches are actually probably a better comparison. They're ugly and even though I don't use it I can't get rid of it except by using hardware designed not to have it.
- deleted 6y ago[deleted]
- xbar 6y agoStill no 16x10 screens. Welcome to the failbin.
- pastrami_panda 6y agoA bit harsh, but sure, once you go 16:10 it's very hard to go back to 16:9 laptops.
- Eldandan 6y agoI've been able to make the adjustment by buying something with a slightly larger display. A 13" 16:10 display is comparable to 14" 16:9. At 1080p/1200p you lose some vertical pixels and a very tiny amount of physical vertical length, but you gain horizontal pixels and length, along with potentially more ports. This was my recent experience choosing between a new XPS 13 or a T14s amd. Side by side the screens weren't that different. Port selection, keyboard quality, and trackpoint availability were the tiebreakers in favor of the Thinkpad. (Didn't care much about the performance difference due to my light use case.)
- pastrami_panda 6y agoI can't really stay productive on anything less than 15". Right now I'm currently enjoying this years lineup of 17" laptops whose body is basically what a 15" was some years ago. I do graphics and sound production aside from programming so I'm really enjoying the extreme screen-to-body ratios. Vapor chamber cooling is also a nice addition. But the thing that really gets me is the 16:10 resolution, I could personally never go back after using it, it just feels correct (to me).
- Eldandan 6y ago>I can't really stay productive on anything less than 15". Agreed. Without a dock/external monitor 13" and 14" are really not the sizes one should focus on for productivity, except in short bursts. 16:10 really makes an impact on displays smaller than 17". It took serious justification for me to give up the XPS 13" 16:10 display in favor of a 16:9 14" laptop. I absolutely would not have chosen a 13" 16:9 display because of how big of a net loss it is.
- deleted 6y ago[deleted]
- swader999 6y agoAnother vector for attack is shipping. Do you trust that this won't be intercepted and "customized" on its way to your address from the factory?
- Answerawake 6y agoThey offer "anti-interdiction service" https://puri.sm/posts/anti-interdiction-services/ https://puri.sm/posts/anti-interdiction-services/ From the site: -Customized tamper-evident tape on the sealed plastic bag surrounding the laptop itself -Customized tamper-evident tape on the internal, branded box -Glitter nail polish covering the center (or all) screws on the bottom of the laptop -Pictures of all of the above plus pictures of the inside of the laptop before sealing the bottom case -All pictures sent to the customer out-of-band, signed by Purism and encrypted against the customer’s GPG key -All coordination occurring over GPG-protected email
- johnklos 6y agoHow I avoid Intel's Active Management Technology: I don't buy Intel. Even neutered Intel seems unnecessarily risky.
- kmeisthax 6y agoUnfortunately the same business types who demanded such a ridiculous self-own as an integrated CPU-level backdoor also pressured AMD into shipping the same thing. And we know less about the AMD PSP than we do about Intel ME. ARM is no better, either, at least in practice. Their relatively friendly licensing terms would allow a vendor willing to make their own silicon in volume to ship a no-TrustZone, no-Secure-Boot SOC. However, nobody does this. In fact, moving to ARM has traditionally been used as an excuse to lock out third-party operating systems and unlicensed software. (Remember Windows RT tablets?)
- fencepost 6y agoAMD has its own version, but documentation and available tools for it were very limited last time I looked.
- EE84M3i 6y ago"with the intention of reverse-engineering the remaining parts" this line strikes me as odd. Don't OEMs normally have a contract with Intel (or someone that does) for licensing the motherboard design that would prevent them from doing this?
- deleted 6y ago[deleted]
- wmf 6y agoI have no idea what the contracts say, but Purism seems to be comfortable operating "outside the system" so maybe they just won't have any contract with Intel.
- Cieplak 6y agoClearly there’s demand for an Intel product with these features absent from the platform controller hub. I acknowledge that hardware products take years to develop, and they already have a lot on their plate. Perhaps Intel doesn’t care about consumer whims, but clearly there’s demand from companies like Google. I’m just generally surprised at the lack of public-facing responses from Intel’s leadership around this and other security issues facing their platform. It all reads like lawyers trying to minimize their liability. They’re one of the most important technology platforms today. Everything besides cellphones runs on Intel. Despite actually being a monopoly or duopoly, they don’t have to be so stodgy. I want to love them for their profound impact these past few decades, but it’s hard when it feels like they don’t listen to their customers.
- deleted 6y ago[deleted]
- yvdriess 6y agoThe remote access features are probably removed or disabled via microcode changes. As Purism referred to sourcing recent CPUs without vPro, they are either directly or indirectly getting those kind of vPro-disabled variants.
- ur-whale 6y agoTheir claim demonstrate good itent, but the unfortunate truth is they have no way of proving or even knowing that it holds.