Intel ME: Myths and Reality [pdf]
events.ccc.de
events.ccc.de
The unmarketed HAP bit is actually evidence they either can do some hack leveraging it, or at least are worried other services can or will become able to.
The theory that the complete subsystem would have been kept secret if it was of interest for secret services is also highly laughable. Especially when it is well known how they regularly leverage other marketed management/sideband services, for example in telecom equipment, to do their espionage operations.
It's like saying "I have a car and can drive 20 miles, but being able to drive 2000 miles is impossible." Saying everything in impossible when you own the system memory is just a failure of imagination.
Yeah, they've known it was a vulnerability for some time. Such a thing wasn't even allowed in secure systems with so-called "High Assurance Platform" being an attempt to mitigate risks in insecure boxes they know market will buy anyway. Stuff like SELinux Trusted Solaris, and so on go here. Recently, for SIGINT and/or politics, NSA is doing 90-day evaluations of COTS products to replace secure, Type-1 gear. The Assurance part that I saw had same requirements as EAL1: so low nobody certified to it to avoid being laughed at. I can only assume bringing in lowest grade stuff across whole DOD when medium assurance is already marketed is a BULLRUN-style subversion to boost surveillance. We don't need smart enemies with these kind of "Defense" policies.
In reality, Intel was able to market it legitimately for its features. May well have needed to, in the face of competition.
But what may have been discussed in back rooms, with other interests -- ones that can't be ignored, and that also represent a big chunk of business? (Both purchases, and influence on trade, surveillance, and any number of other factors that affect one's business.)
Anyway, I think a whole processing subsystem would be too big and obvious to hide. Hiding functionality within it? Quite plausible.
And we have precedents, in this regard. (Fiber trunk and other splitting/tapping, e.g. the "ATT room"; the Clipper Chip agenda; weakening of NIST encryption standards; the scope of "inadvertant" domestic data collection;...)
Page 45: "WHERE'S THE INTEL ME FIRMWARE?" The Intel ME firmware is in the same flash chip of the BIOS/UEFI, in its own region.
Page 46: "Reading and writing it with an external programmer is quite simple." ..showing 2 pictures of raspberry pi connected to disassembled laptops with wiring all over the place.
How simple is simple I wonder :D
[1] https://www.aliexpress.com/item/SOIC8-SOP8-Flash-Chip-IC-Tes...
I'm dumb as heck and I managed to get the wiring right and set an rPi up for SPI flashing.
They get to exploit all the bugs to do their nefarious things and can neuter the ME of their own machines to not provide the same attack surface. I find it highly unlikely that the NSA did not know about how insecure the current ME generation is and I also find it very hard to believe that Intel would not have put any effort into pentesting it.
Or maybe it was just pure corporate greed on Intel's part after all. I fear we'll never know, unless another NSA leak happens that contains information about this.
IMO the first half is almost useless, but the second one is actually worth listening to.
myth 1: and they come to the conclusion "pretty unlikely". So no you didn't mythbust - just you don't think it is true. Also, if it is made for solving real IT problems then why can't I disable it? (without using me_cleaner)
myth 2 conclusion: "yes, but it depends". So you are saying it is true.
myth 3 conclusion: "was possible, not anymore". You are saying it is true again.
myth 4 conclusion: "its complicated" - nobody said it was easy but its possible so that makes it true.
and so on ...
The relevance of this post is very limited.
Of course. How much time do you spend reading opinions on a highly technical field from hobbyists who readily admit they are no experts, and whose work is based on a hand-picked list of comments posted by anonymous people on social media?
I would gladly read the whole presentation from start to finish if it was written by experts talking about their research in their domain of expertise. This is not that.