10 ms·
Intel PIII: Is Big Brother Inside? (1999)
- dehrmann 6y ago> But didn't you say it'd help to prevent counterfeiting of chips? The stolen part I get, but did it used to be easier to counterfeit chips? There's a lot that goes into making something that looks like a PIII, and even then, I assume Intel had state-of-the-art fabs, so I'm surprised this was a concern. The hardware scams I've heard of stamping better specs on something, for hard drives, a firmware hack that makes it appear to be higher capacity, and unauthorized hardware made in off-hours on the same production line.
- deleted 6y ago[deleted]
- bombcar 6y agoThose are the direct scams - but there are also lesser scams where a supplier replaces a part with a working part made by another manufacturer and pockets the difference. The parts may work correctly (in some cases it was only discovered because the parts worked FASTER than expected) - but it is fraud.
- moonbug 6y agoa common problem back then was chips getting remarked as higher clock bin parts.
- whoopdedo 6y agoI felt at the time that when Intel said "counterfeit" they really meant "clones".
- M277 6y agoYes, this was what immediately came to my mind as well. For an interesting, albeit slightly unrelated read, see: https://en.m.wikipedia.org/wiki/Chip_art https://en.m.wikipedia.org/wiki/Chip_art >"Prior to 1984, these doodles also served a practical purpose. If a competitor produced a similar chip, and examination showed it contained the same doodles, then this was strong evidence that the design was copied (a copyright violation) and not independently derived."
- rasz 6y agoWhat Intel meant at the time was "someone is selling our chips relabeled to a higher SKU and pocketing our cut". This happened in 1996 with criminal gang remarking 120 to 150, 133 to 166, etc, pocketing extra ~$30-50 per CPU. https://www.youtube.com/watch?v=wsKjX6UGYUQ https://www.youtube.com/watch?v=wsKjX6UGYUQ Intel was so pissed someone else was making money on binning they locked multiplier on later 133/166/200, all Pentium MMX and later models ending easy overclocking. https://forums.anandtech.com/threads/pentium-200mhz-multiplier-unlocked.800270/ https://forums.anandtech.com/threads/pentium-200mhz-multipli...
- paranoidrobot 6y ago> later models ending easy overclocking. Except the classic case of the Celeron 300a which let you go from 300Mhz to 450Mhz with a simple change of a motherboard FSB clock setting. I was nervous when I ordered the parts - but stunned that it was so easy for me to do, and left me with a machine that was effectively faster than anything Intel was officially selling at the time.
- rasz 6y agoFSB (and later BCLK) overclocking is what we got left with for a while until Intel killed that too with Sandy Bridge just after introducing special upscale K series CPUs generation earlier with Nehalem. All in an effort to sell gimped parts while charging extra for the whole deal.
- monocasa 6y ago> Q: I've never heard of software "expiring." How is that possible? What a beautiful world that was
- gambiting 6y agoI mean, in 1999 one of the dominant software distribution models was shareware where frequently applications would stop working after some amount of time and demand payment.
- stingraycharles 6y agoThe article is referring to automatic expiry of license keys though. Still seems like a rather naive question, I agree.
- sn_master 6y agoWith subscription, even continuing to pay increasing amounts isn't a guarantee than the product will remain available once the vendor decides to cancel it. And, piracy isn't an option for developing countries where the software price is over a year's average wage.
- ttt0 6y agoIt's never guaranteed, no matter what payment model. There is plenty of discontinued closed-source software from way before a subscription model became a thing that everyone does, and some of it managed to stay alive only thanks to piracy. With subscriptions it's way worse, because it has to rely on a central server, sometimes for no good reason at all, and you can't even do that. It's just bound to happen that the company will pull the plug once it's no longer profitable.
- tehjoker 6y agoBack in the day, the license keys weren't checked at a central server, there was some kind of check sum or database inside the software instead. This was wonderful for both pirates and legitimate users for when the company disappeared. I still remember a working Starcraft CD key (though it later turned out that something on the order of 01234566789 worked).
- illys 6y ago"Big Brother Inside" for just a unique id? What should we say now about Intel Management Engine?
- sneak 6y agoEvery single iPhone and iPad transmits its hardware serial number to Apple when you launch the App Store app, or on first boot after restore for "activation".
- trollied 6y agoI don’t know why you’ve gone on a tangent and randomly mentioned Apple? Anyway, speaking of unique identifiers in mobile devices, mobile phones have had IMEIs for ages - pre-dates Apple by a long time.
- sneak 6y agoFrom TFA: > Intel has revealed that each Pentium III chip will carry a unique serial number that can be read by the computer's software. Intel claims that the serial number will facilitate e-commerce, promote "digital content protection," prevent counterfeiting of Intel processors, and help to track stolen ones. We know users have questions about this controversial feature, so we assembled this FAQ. Q: Why are privacy experts concerned? A: Privacy experts are concerned because the CPU's electronic serial number could be used for purposes that may not be in users' best interests.
- PurpleFoxy 6y agoWe already know the management engine is a backdoor/botnet. No intel powered computer is secure or private.
- b0tzzzzzzman 6y agoThis has been said alot on HN, but I get the feeling it's quickly shrugged off. The real key is out of band communications and out of scope of the OS.
- deleted 6y ago[deleted]
- JohannMac 6y agoCommon to have unique SN in a processor. Let the SW vendors do copy protection too. E.g. at Sonos we used them to associate with the software signed certificate such that you couldn't run a given Players software on another Player without the same SN. When making products via contract manufactures, especially in China, it was a wise procedure.
- qazxcvbnmlp 6y agoThat is glorious and horrifying. Sounds like it protects your business from counterfeits and hobby hackers at the same time :) Also, I have a Sonos system and it works great!
- userbinator 6y agoHorrifying should indeed be the reaction: https://news.ycombinator.com/item?id=21895086 https://news.ycombinator.com/item?id=21895086
- Daho0n 6y agoFor now (see other comment with link). I'll never touch Sonos again. They burnt their bridges.
- vangelis 6y agoWell, until your choices are buy a new Sonos device or get bricked.
- snailmailman 6y agoWhen I built my pc the cpu came with some free game or game coupon or something. It wasn’t in the box, I instead had to download and run some AMD software that verified that I was in fact using the CPU. I’m under the impression that it detected my specific CPU not just make/model but some sort of unique ID. Presumably this stops people from claiming the code and reselling the cpu,(or at least without reselling it as “new”) or from spinning up a VM and trying to redeem random promos without owning the real CPU. Thought it was interesting that they did that but didn’t think much more of it. I don’t even remember what the promo was. Might have just been extended warranty or something?
- beervirus 6y agoOh man, I remember this. What a simpler time.
- o-__-o 6y agoI remember the flood of articles that told you to disable CPUID because it could be detected from javascript. The internet was faster then too..
- CodeWriter23 6y agoThe wedge used to drive home even more draconian privacy infringement like the Intel Management Engine.
- musicale 6y agoYes, and he seems to be there to stay. :(
- marcan_42 6y agoI'd forgotten tech reporting was just as bad in 1999 as it is today. Here's the important part missing from the article: that serial number is available from userspace, and cannot be intercepted by the kernel in any way. They provided a way to disable it, but not to report, control, or intercept how it is accessed. It is returned by the unprivileged, untrappable* CPUID instruction. Every single UEFI computer sold today has a unique serial number (GUID). There are MAC addresses. There are HDD serial numbers. There are zillions of unique identifiers accessible to the operating system. Various copy protection schemes use one or more of these. But what they all have in common is that they are under the control of the OS. A privacy-conscious OS can forbid access to these identifiers for userspace applications, or can fake them to something else. This is how e.g. sandbox environments like the App Store can force apps to use some kind of "advertising ID" for this stuff, and ensure that apps aren't sneakily fetching some true unique system ID. But with the PIII serial number, userspace apps can fetch it without the OS knowing about it. And the disable bit is a one-time operation, so it is not possible to grant serial number access to some apps and not others. This leads to a situation where any arbitrary unprivileged userspace app can uniquely identify your machine, and where vendors relying on this feature might compel you to leave it enabled (e.g. DRM). Now random apps running under an untrusted user can fingerprint your machine, just because you want to watch Netflix. And that is why this design was utterly broken and a privacy nightmare. Not because it's a unique ID. We have tons of those. * VMs can trap CPUID, but of course VM support came later anyway.
- garaetjjte 6y ago>* VMs can trap CPUID On Intel trapping CPUID is also possible without VMs since Ivy Bridge. (Linux exposes it by arch_prctl(ARCH_SET_CPUID))
- lights0123 6y agoAnd is why https://rr-project.org/ https://rr-project.org/ works very well on Intel but barely on AMD.
- garaetjjte 6y ago