One could argue that it’s surprising they haven’t already.
One could argue that it’s surprising they haven’t already.
https://twitter.com/codinghorror/status/907711853530300416
It rips my current computer apart, which is perfectly decent:
https://browser.geekbench.com/v4/cpu/compare/4107961?baselin...
If these things can outperform on passive cooling why are we not seeing people building farms out of them with active cooling.
That's the thing with Intel CPUs. There are a huge number of ways to configure them. Even knowing the part number is not really enough to judge what the overall system performance will be.
That stuff is great but doesn't mean much. Just because they're blocking border agents from trivially imaging phones at the border doesn't mean that they won't cooperate at a higher level with some undocumented baseband features.
Just as Defense in Depth is a concept in security, we've already seen a corollary "Offense in Depth" from the intelligence community. Is the best attack in the random number generator[3] or undocumented silicon[4] or intercepting your boxes on the way to your data center[5] or tapping your fiber[6] or stealing your certs[7] or paying your employees to go rogue[8]? Why choose when you can just do them all.
Apple hardware is vertically integrated and utterly undocumented. The AMT chip has been present on motherboards since 2006[9]. The Snowden Introspection Engine found that the Wifi Chipset remains powered up even when Wifi is turned off.[10] I find it hard to believe that the same government who went to all these lengths to compromise our infrastructure would really let Apple get away with refusing. How did that turn out for Joseph Nacchio?[11]
[1] https://www.washingtonpost.com/world/national-security/us-wa...
[2] https://www.cultofmac.com/498052/ios-11-lets-quickly-disable...
[3] https://en.wikipedia.org/wiki/Random_number_generator_attack...
[4] https://en.wikipedia.org/wiki/Hardware_backdoor#Examples
[5] https://www.extremetech.com/computing/173721-the-nsa-regular...
[6] https://arstechnica.com/tech-policy/2013/10/new-docs-show-ns...
[7] https://nakedsecurity.sophos.com/2013/12/09/serious-security...
[8] http://www.ocweekly.com/news/fbi-used-best-buys-geek-squad-t...
[9] https://libreboot.org/faq.html#intel
[10] https://www.documentcloud.org/documents/2996800-AgainstTheLa...
No, it seems more probable that they did this because their largest customers want centralized management at a low level. They want to be able to track and control assets, and to prevent asset loss. They, being the largest customers, control the features that Intel offers. It then makes no sense, financially, to make two versions of the CPU.
Unfortunately, the market for people who care is vanishingly small. Most people don't much care about privacy or security, other than to pay it lip service - if even that much. Prevalent is the idea that they've nothing to hide and, thus, nothing to fear.
So, without evidence that this was inspired by a three letter agency, I'm going to assume it is a financial decision. That seems much more reasonable and probable.
Do you have any evidence to prove three letter agency coercion? I'd expect it to be quite the news event, if you did.
It has been around long enough.
Anybody work for an MSP or enterprise that actually uses this in the field?
It hasn't anything to do with quality specifics, nor of alternatives. Without factual evidence to support the three letter agency theory, the rest of the argument is invalid.
Don't get me wrong, I think it's a horrible idea. I've just seen no reasons to assert that it was done because of a three letter agency being the directors. As near as I can tell, and I've followed this fairly closely, no such evidence exists. At best, it's speculation. At worst, it's conspiracy theory. Either way, presenting it as fact and then basing an argument on that is illogical.
We can do better than that. There are lots of valid complaints that don't need speculation, disinformation, or hyperbole. IME is a horrible idea, at least it is so long as you can't disable it as the end user. This very thread is a fine example of one of the reasons that it is horrible. It's a security nightmare and should be user controlled.
No three letter agency needed to point this out. Wild, unsubstantiated, accusations may make people take the complaints less seriously. That seems less than helpful.
That's pretty different than asserting it was done at the behest of a three letter agency and then basing a whole argument on that. Extraordinary claims require extaordinary evidence.
https://securingtomorrow.mcafee.com/executive-perspectives/a...
This is a statement by the Intel CTO from 2016 on the ME discussions, and briefly reassured us that Intel is conscious of the security of the ME, and that they have teams dedicated to it and can push firmware updates out to cover vulnerabilities.
https://www.intel.com/content/www/us/en/architecture-and-tec...
Intel made an official announcement in May that they have discovered an escalation of privilege vulnerability and are addressing it accordingly as you would expect. It also notes that consumer hardware and firmware is not affected by the vulnerability, demonstrating that Intel actually does release two different chips, and prioritizes privacy and security more over features on the consumer models.
https://newsroom.intel.com/news/important-security-informati...
Intel releases a software tool for checking if your system is one of the vulnerable units or not, they have a fix already for the firmware and confirm it is not due to physical design flaws, and are working with manufacturers to push the updates ASAP.
Overall, I don’t feel like Intel is at all intentionally sabatoging it’s customers, and genuinely considers the ME a valued feature by consumers, even though it bothers me that one is included on every product, they do differ and consumer models have fewer privileges than business models, which seems to be more of a firmware design than a hardware design, so I tend to believe that they simply don’t design extra chips without the ME and instead lock it down more on a software level. Vulnerabilities also appear to be firmware based, and the extremely vague announcement by black hat doesn’t suggest otherwise either. Intel very obviously takes the security of their devices very seriously and makes themselves available to users who need help identifying whether or not they’re vulnerable and what to do about it.
Nor could they likely pay them enough to make it worth the trouble if there wasn't a market for the ME - Intel is $170 billion company, with a $12 billion R&D budget last year alone [0].
[0]https://www.electronicsweekly.com/blogs/mannerisms/markets/i...
On another site, having a similar conversation about this very topic, multiple people jumped in to assert that this was done at the behest of the NSA and that the legal mechanism for doing so was a National Security Letter. No amount of linking was able to convince them that that's not even what an NSL does. Nor would they believe that an NSL contains no such mechanism to force a company to do such.
Worse, it was multiple people who believed this. It wasn't just one isolated individual. Even showing them what an NSL really is made no difference to them. I pointed out what it did have the power to do, and they countered by saying that's what they claimed but that it could secretly do more. I asked for a citation and was told it wasn't out there because it was top secret. They linked to some of the most outlandish stuff, as if Cold War spies were actually proof that the NSL could compel Intel to include the ME and to include exploits in the code just for NSA use.
It went on like that, for a good day and a half of back and forth. I finally gave up trying to help them be sane.
I don't get it. I truly don't understand. These are otherwise bright people, or so they seem. I'm well and truly flabbergasted by this behavior.
You are wrong. They offer countless different versions of CPU's, famously denying "enterprise" features like ECC to private customers. One can only wonder why they are so generous and give everybody "enterprise" manageability for free.
I can probably agree that none of apple’s actions have significantly affected the percentage of computing functionality used in society that is comprisable at low cost — however I do think that Apple can choose to act to (1) increase the average cost to compromise (2) expand the (incredibly small) set of functionality which is not trivial to compromse.
I don’t think that any truly expert 3-letter agencies can reasonably oppose those goals in a way that completely prevents them from advancing. I think it would be self-defeating for the NSA to implement something like a “security blocking sophon”[1] that permanently cripples the capacity of technology to become more trustworthy given how dependent are the societies in which these entities operate on trustworthiness being possible in some contexts ...
[1] (sophons are a concept from this novel — which I won’t spoil, great series!) https://en.m.wikipedia.org/wiki/The_Three-Body_Problem
I agree with your premise but still want to recognize you backing it up with data.
EDIT: Actually, I might be mis-remembering. After a short while of searching I couldn't find any references to what I just said (though searching for "Google" appears to make the results less relevant than normal).
Now imagine that with a laptop’s power budget. Put a Transmetta like x86 decoder in front for legacy apps, combine with Apple’a full stack control, custom blocks on the chips, llvm bitcode and a few more years of development and you end up with a laptop that covers 80% of Apple’s market.
They can still use Intel for higher end machines, but the bulk of laptops will be all Apple. Along with unbeatable battery life.
Apple laptops already have a good battery life. I don't think people would be willing to give up performance relative to competitors products to have better battery life.
Basically in sum you are expecting apple to support 2 different hardware arch on the desktop/laptop, have inferior performance compared to windows, give up bootcamp etc in order for people to have 14 hours of battery instead of 9 when they will just do what they currently do and plug their devices in when they go to bed.
Its certainly an interesting idea but I think the downsides outweigh the positives.
As for not being able to install Windows, I’m sure you could if the x86 front end was in silicon (again, think Transmetta), but it is probably not for that target market anyway.
As for Apple supporting two systems, I don’t see the problem. They did it for the 68k to PPC and PPC to x86 transition, and when you own the entire stack, including system language and build chain, it probably isn’t as big a deal as cross platform with different APIs and paradigms.
I mean, if use a tapped Intel chip can keep FBI and NSA away from their door step, they probably more than happy do to that.
Because at the end of the day, most people will only blame Intel, not them.