Also, a normal user of a computer cannot do whatever they like with Intel ME, so its the least useful circumvention measure I've ever heard of. GDB is infinitely better.
Not to mention that most DRM depends on the encryption being done outside of the computer's CPU. HDMI's DRM relies on the local computer not being aware of the contents of the stream and the monitor itself does the decryption with burned-in keys.
What would be the justification for Intel going through all that trouble to do that (besides a conspiratorial "the NSA needs it to spy on everyone")?
The impression I've gotten, to this point, is that Intel just doesn't care enough about people in the general public who are bothered by the IME to publicly support ways to disable it. Governments had enough buying-power to get Intel to implement an unsupported workaround, but I'm not convinced Intel has a motivation to make accessing that workaround hard.
Besides the real reason? I dunno.
Why would Intel go through all the trouble of creating ME or the broke AMD PSP at around the same time? This is hardwired in silicon, is not cheap to do and definitely needs huge business justification to initiate, implement and maintain. What's the business case?
Are they charging a premium for these features and disabling it for everyone else as they would if it was actually a 'premium' feature? Are they giving an option to those who don't want it to disable it without ado?
No, they are pushing it on everyone. That itself compromises ME. How do we know there is no NSL in effect forcing both Intel and AMD to implement this. Nobody does. But it is an intrusive piece of tech that has complete authority over your PC.
Yes, the NSA exists. Yes, it's their job to spy on people. And yes, it's perfectly valid to include mass surveillance in your threat model. But these constant, uncorroborated claims that the NSA boogeyman is hiding behind every rock and tree are starting to become quite tiresome.
Yeah indeed, they have backdoor-ed every ISP, nation, router, HDD, what-have-you in existence and these people keep telling boogeyman tales.
Tsk tsk tsk. How tiresome.
This is exactly the kind of hyperbolic nonsense I'm talking about. You can't claim that every HDD in existence has an NSA-installed backdoor installed in it without providing any evidence.
If the NSA's capabilities were nearly as extensive as you're claiming, the US wouldn't need to bother maintaining a military. They could just remotely command all of North Korea's computers to shut themselves off, then sit back and wait around for their surrender.
I'm not saying mass surveillance isn't a problem, or even that the NSA doesn't have a backdoor installed in IME (I certainly don't have evidence to the contrary); just that people need to stop exaggerating the threat, or making claims about the NSA having compromised any specific system without providing any evidence to back those claims up.
Remember when the US shut down NK's internet ? https://gizmodo.com/so-who-shut-down-north-koreas-internet-1...
Remember when the NSA was revealed to have a malware that could infect hard drives, being potentially undetectable ? https://motherboard.vice.com/en_us/article/ypwkwk/the-nsas-u...
Remember PRISM ? How about stuxnet, and the other couple of viruses that are almost surely the NSA's.
Sure, those are not backdoors installed by the OEM, rather they are malware that the NSA can use to infect (lots of) systems. But let's not kid ourselves, the NSA does have a ridiculous amount of power, and we have lots of evidence of it.
At this point I'd be rather surprised if the NSA haven't hacked my fridge yet somehow.
_Could_ the NSA have the ability to utilize IME somehow as a means to infect computers? Certainly. Do they _actually_ have that capability? We have no idea. Same goes for your motherboard's firmware, your hard drive's hardware, and any number of other possible vectors. They _could_ be compromised somehow, yes, but let's not claim that any specific motherboard firmware, HDD model, or CPU processor brand definitely _is_ compromised without evidence.
There is an equivalent article from Ars technica, if "theregister" isn't to your liking.
As for the evidence on routers and Internet infrastructure, you should pay more attention to leaks of state-sponsored tools, like the equation group leaks and the CIA one.
Do you want to live in a free society or not? Because this is not acceptable to a free society.
The fact of secrecy around this issue is the only thing to be doubted. Its no secret to non-Americans/concerned citizens; if you choose to continue to be ignorant, I choose to set you the challenge: go and find out for yourself just how bad it really is with the NSA. (It is atrocious.)
If I were an American and believed in what the NSA was doing, I'd want to know what they were doing with their budget if they didn't at least try to get a hardware back door into Intel CPUs. Why waste budget on finding exploits in patchable software when they can go straight to the silicon?
The Intel IME is far different than 'rock and tree' to an organization of 40k employees and $10B budget tasked with bypassing stuff like the IME.
Well, some companies and users use the IME to enable theft-prevention technology. If you can circumvent the IME, you can easily steal a laptop and disable this theft-prevention technology.
If that’s worth building an ever more closed walled garden is another question.
Isn't the ability to spy on everyone the official mandate of the NSA?
If you were worried about NSA spyware that tunnels through your OS... well, then you may as well just be worried about NSA spyware in your NIC.
Because in the end, even if the ME was directly connected to the NIC, it still needs to know how to talk to the NIC (thus why NICs have drivers...). When you use an Intel NIC, the ME knows how to talk to it, and everything is hunky dorey. In practice, Intel could probably build a database of common non-Intel NICs and load all of their drivers into the ME. But really, if we assume that the ME exists for business reasons, then its obvious why Intel will just keep it all as Intel. They are nominally selling something that is advantageous to large organizations, and would like said large organizations to buy as much Intel gear as possible. Said large organizations believe that ME provides sufficient value to go with Intel NICs instead of other NICs.
If it's for what Intel claims, then they would trivially offer an option for the customer to disable it. Hell, they could even make it a selling point for higher-margin chips like Xeon.
Does ME have business purposes? Sure. But their staunch refusal to allow disabling by nongovernmental customers does not pass the sniff test. There is clearly some other, non-business reason for it.
> then you may as well just be worried about NSA spyware in your NIC
If you own my NIC but not my CPU, I can encrypt my traffic and blind you.
If you own my CPU (especially my AES-NI ISA), my options are more limited. Much higher-value target.
>especially my AES-NI ISA
why aes cpus specifically? you're free to not use aes instructions. besides, if you own the cpu, you load whatever shellcode you want, no need to backdoor the aes instruction.
good luck getting a system compiled that does not use them at all. Might be possible with gentoo and the right configuration as it compiles everything, but with a dominantly binary distro like Ubuntu or Debian you're SOL.
I was just saying my options are more limited, and the options for someone unwilling to recompile their own software is very severely limited.
But even if I'm running, say, software-only Salsa20 with all compiler optimizations off, if my CPU is still owned, my keys are still at risk of silent compromise.
The only real defense is to ascertain the processing limitations of IME and then choose your crypto primitives/implementation for both processing and memory hardness that exceeds the ability of the IME's lower transistor count and/or clock speed to keep up with.
It's fairly light on details, but my interpretation is that for a NIC to support PXE boot it has to have firmware that exposes a standardized API so that the boot loader can functions as a DHCP client and a TFTP client. As far as I can tell, the NIC doesn't have to provide some standardized method for general access, just those two things. The NIC could even have a completely different, completely separate API that it expects the OS to use, and just has some firmware that acts as a shim to expose to the boot loader the PXE client API.
Assuming this is true, Intel ME could access the NIC using the PXE boot API, but this only gives it the ability to act as a DHCP client and TFTP client, not arbitrary networking operations.
I could be completely wrong about that, though. This is, at best, an educated guess.
Dear Intel, please PLEASE only use a solid state dongle with no moving parts! :-)
If ARM continues to supplant x86, and an open ISA like RISCV starts to nip at ARM's heels...
You're going to be hard pressed to find a moderately complex SoC without something like that. At a bare minimum, reset and power state sequencing is complex enough to offload to a microcontroller style core these days. The iMX6 is the biggest, most reent SoC I an think of without that.