4 ms·
Two bits surprised me. First, Intel is apparently collecting telemetry underneath the OS? "The ITH can trace different internal hardware component (VIA - V
by quasirandom 6y ago
Two bits surprised me.
First, Intel is apparently collecting telemetry underneath the OS?
"The ITH can trace different internal hardware component (VIA - Visualization of Internal Signals, ODLA - On-chip logic analyzer, SoCHAP - SOC performance counters, IPT - Intel Process Trace, AET - Intel Architecture Trace), and external component like CSME, the UEFI firmware, and you can even connect it to ETW. *This telemetry eventually finds its way to Intel in various methods*."
The second is the nested complexity. The sheer quantity of stuff running before the bootloader is staggering. How is it possible to secure these nested trees of computers-in-computers?
- deleted 6y ago[deleted]
- Layke1123 6y agoIt's not. In fact, look up what micro code is. Computers have been intentionally compromised for years in order to "catch the bad guys". Open source hardware that is subjected to intense security reviews is the way out of state sponsored hardware backdoors.
- test1_1234 6y agoI'd be interested to know more about the telemetry part as well. So far I've comforted myself by thinking that the Intel Management Engine is mostly a theoretical vulnerability, rather than something that's practically going to affect me. I'd also like to know if this telemetry only affects the newer Intel machines with the Platform Controller Hub, or the older Memory Controller Hub architectures as well, since I'm still using a Core 2 Duo machine.
- elric 6y ago> this telemetry eventually finds its way to Intel in various methods Wait what? How does that work, and how is that legal?
- vbezhenar 6y agoI guess via Intel ME drivers installed in Windows.
- salawat 6y ago...Why rely on the installed OS? The ME already has networking capability. Further, most intel firmware seems to have it's own update channel. It probably uses the same mechanism.
- vetinari 6y agoFrom what I've seen, ME updates are bundled with UEFI updates.
- vetinari 6y agoIntel ME drivers are only to allow access from the local machine. Normally, localhost access would go through loopback, but ME can communicate only via the ethernet or wifi network adapter. To access ME on other computers, you don't need any drivers.
- eeZah7Ux 6y ago> how is that legal? It's perfectly legal to sell hardware with telemetries, homecalling and vulnerabilities that are known to the vendor but not published AKA accidental backdoors. How? Money.
- chithanh 6y agoGiven how malware has been demonstrated that infiltrates the Intel ME firmware, reads main memory and covertly exfiltrates data (through introducing packet jitter), I think it is safe to assume that Intel has the same abilities. https://fahrplan.events.ccc.de/congress/2013/Fahrplan/events/5380.html https://fahrplan.events.ccc.de/congress/2013/Fahrplan/events...
- eeZah7Ux 6y ago> The sheer quantity of stuff running before the bootloader is staggering. How is it possible to secure these nested trees of computers-in-computers? Complexity and absence of peer review are the main enemies of security. That stuff is incredibly complex and mostly closed.
- fsflover 6y ago> How is it possible to secure these nested trees of computers-in-computers? https://github.com/corna/me_cleaner https://github.com/corna/me_cleaner Or, buy hardware from vendors who neutralize ME according to the link.
- 1vuio0pswjnm7 6y agoOne idea of a "secure boot" would be to not have anything, save for what is necessary for hardware initialisation, outisde the user's control running before the bootloader. IMO, telemetry is a security breach. The whole notion of "secure boot" has nothing to do with "user security" (although it can be marketed that way). It has to do with companies having unfettered control over a hardware product after it has been sold. The companies seek to secure the ultimate control over the computer from anyone else, including the user. Many people seem to agree that software written by hardware companies is, generally, not relatively high quality.