> In this article, we describe how we discovered this undocumented mode and how it is connected with the U.S. government's High Assurance Platform (HAP) program.
> Googling did not take long. The second search result said that the name belongs to a trusted platform program linked to the U.S. National Security Agency (NSA).
>We believe that this mechanism is designed to meet a typical requirement of government agencies, which want to reduce the possibility of side-channel leaks. But the main question remains: how does HAP affect Boot Guard? Due to the closed nature of this technology, it is not possible to answer this question yet, but we hope to do so soon.
Interesting that Intel will provide this to the US government for enough money, but wouldn't offer it as an additional $50 or $100 option for end-customers to disable the ME.
I think there are probably enough privacy conscious people who would be willing to buy a Skylake or newer platform from Intel if they could easily disable the non-BUP components of the ME for a reasonable fee.
1. It is useful in business settings
2. It enables the US spy agencies complete surveillance of all PCs
It's the second point that explains why they can't make it optional. And that makes business sense. That way they ensure backing from the NSA, instead of having to fight against them.
It is already common knowledge that the ME is used to implement DRM.
The DRM functionality of the ME has been discussed in several books. [0] The ME contains DRM functions to securely decode content (e.g. streaming video) in a way such that decoded content cannot be snooped by the host processor before it is displayed to the user (ostensibly via a secure channel like HDCP).
The PAVP module is part of the ME firmware. Which means the management engine is, among other things, a DRM implementation.
https://en.wikipedia.org/wiki/Intel_GMA#Protected_Audio_Vide...
https://recon.cx/2014/slides/Recon%202014%20Skochinsky.pdf (page 17)
Of the four criteria in the exemption, I wouldn't put it past the government trying to make the case that exposing a NSA spy program somehow falls afoul of good faith investigation - but the general view that "any DRM research is a crime" is no longer accurate.
This is rather an argument against DMCA or an argument why researchers working in this area should consider leaving the USA.
(Though it is somewhat more limited than the DMCA.)
You can see how well this embargo works in every electronics mall
Where did you get that information?
https://en.wikipedia.org/wiki/SW26010 doesn't claim any of that.
These turned out to be not such a great idea.
I've read that x86 has multiple registers (eg, https://news.ycombinator.com/item?id=9264195, http://blog.erratasec.com/2015/03/x86-is-high-level-language...). "You want to do something with rax, so the processor grabs one of its 168 internal registers to play the role of rax for a moment" sounds like a type of register-window implementation to me. Or I'm completely misinterpreting the term.
Note that my sentiment/tone in asking this is "huh, if that's the case then POWER and other architectures could really compete with x86!". (Assuming POWER doesn't use that approach.)
Of course, IBM knew about this way back.
https://en.wikipedia.org/wiki/Tomasulo%27s_algorithm
Those who do not study history are doomed to repeat it.
Also, it's not really an x86 thing (for instance most Atoms don't have these extra registers), it's an in-order vs out-of-order thing. Most Power cores do have the larger bank and renaming.
PS: read my profile description.
> You can see how well this embargo works in every electronics mall
IIRC, the embargo was only against very specific processors used in a specific supercomputer design.
[1]: I'm not suggesting most, if not all, people don't need the ability to disable Intel ME, only that, they more often than not don't value it enough to pay for it..