Game Over We Have Obtained Fully Functional JTAG for Intel CSME via USB DCI
twitter.com
twitter.com
It's really puzzling that Intel would risk the entire company to include features like this. Even if the NSA said "we demand it", surely this is possibly the end of Intel being a trustable computing platform?
The deeper question being, how can any cloud based program know that it is running on a computer safe from such snooping? Is there any possible way or do we just need to give up on that idea forever and assume that what runs on someone elses computer might be monitored and nothing can be done about it.
I have an off-topic question about that statement. I fail to grammatically parse the construct "A and B insist C no be there". Doesn't it need to be "A and B insist C is not there"?
Any sources for IME being completely disabled / not present on macs?
[0]https://www.theregister.co.uk/2017/08/29/intel_management_en...
Intel's large scale customers wanted this feature. To Intel, it has been a net asset instead of a liability, and maybe this will still hold up.
In other words, I'm not sure how you can use this to modify running devices without being able to stop the clock first. Is this something that JTAG supports now?
Even though it's run over the same wires, it's a separate protocol from the hardware JTAG probe you describe.
First thing Intel would do is to implement/create new ME-like thing, maybe on other arch like ARK before and hide it little more.
Then finally someone would find it anyway in a few years and let others know about it ...
"History does not repeat itself, but it rhymes."
https://www.digitaltrends.com/computing/intel-kaby-lake-skyl...
Edit: I read some more. It looks like this is going beyond what I thought and affects way more machines.
That PDF also says your BIOS must support this kind of debugging, and, for the ‘OOB’ protocol, your hardware must support it. So, your BIOS may be configurable to make this attack impossible, and your hardware may already be protected against it.
[1] https://security-center.intel.com/advisory.aspx?intelid=INTE...
https://security-center.intel.com/advisory.aspx?intelid=INTE...
You could spy on user activity, sniff encryption keys etc
If I had to guess, I wouldn’t be surprised if a different exploit is found that bypasses the bios setting to compliment this one.
http://www.tomshardware.com/news/mantistek-gk2-collects-type...
but invisible and undetectable
If I correctly understand how AMT works then it implements it's own mechanism with similar purpose inside ME firmware, which with AMT enabled remains active even in S5.
The article doesn't have many details though.
I can see use-cases for it, but good luck convincing the W3C.
Intel has put CSME and DCI in all (?) their chips since 2015. Skylake was announced in 2014, launched in 2015.