Exploiting Intel’s Management Engine
kakaroto.homelinux.net
kakaroto.homelinux.net
In other words, the ME is to Intel boards as Apple’s T2 chip is to their recent notebooks: an SoC that takes on the real role of being the “system processor”, turning the [rest of the] socketed CPU into effectively an “application processor.”
In fact, given that it’s so self-sufficient, it’s interesting that Intel choose to ship the ME as an “IP core” of the CPU itself, rather than making it part of the off-die Intel PCH chipset that they supply to mobo vendors. Is it just to provide the ME with low-latency access to CPU components like ALUs (for TPM encryption circuits) and d-cache (for packet sniffing)? Because it seems like it isn’t really built this way, and an “external ME” would be just fine running without a CPU socketed in at all. (Which would be neat, honestly; if you could exploit an external ME, you could run software on your Intel-chipset motherboard without a “real” CPU!)
Given that industry players seem to be all trending toward this design in one way or another (even game consoles did the “system SoC” / “application CPU” split with the last two generations), I wonder if this design pattern will ever be standardized, in the way that interrupt controllers or MMUs were standardized. Will we ever see an open-hardware board with its own open-hardware system-management SoC running FOSS firmware?
It's worrying that these vulnerabilities are not disclosed in a way that lets people take control of their devices.
That the ME is so tightly integrated seems mainly to be for cost savings. There is also an argument for increased security, as now your attacker must be able to work with a decapped highly integrated CPU.
Intel did at one point do what you were suggesting -- if you look at the sandsifter project the author found a family of devices that had a parallel execution unit that was dispatched instructions with a "secret" prefix that had full access to memory. This could still exist in newer processors but be better hidden, it would certainly make a lot of one might want to do with the ME a lot easier.
Ideally there would be a standard way to verify and measure all the various firmware images (and potentially option ROMs which would be theoretically measured with SRTM via UEFI) for these system processors during boot during a DRTM event (with Intel's STM/AMD SMM supervisor enabled as well) but there is a long way to go for that.
[1] https://i.blackhat.com/USA-19/Wednesday/us-19-Hasarfaty-Behi...
[2] https://www.youtube.com/watch?v=iYvhHey_dTk
[3] https://chromium.googlesource.com/chromiumos/platform/ec/+/m...
> an “external ME” would be just fine running without a CPU socketed in at all
and made Ryzen a nearly-SoC, EPYC an actual SoC (no chipset at all required AFAIK). (To be fair Intel did integrate many things onto the die as well..)
https://fuse.wikichip.org/news/1177/amds-zen-cpu-complex-cac... seems to confirm that SMUs are on-die at least on EPYC.
> Interestingly the Chromebook EC firmware is open source
And even the Google Security Chip is included under that. You can't run a customized GSC firmware on a production device unless you have Google's keys, but you can look — and hopefully maybe reproduce the build?
I suspect this popped up in meetings and is at least partly the reason for the design now.
[1]https://en.wikipedia.org/wiki/Intelligent_Platform_Managemen...
iLO is kind of a piece of crap, but I do love my Xen and resource pools
Keeping that "Just buy a shitload of cheap-o eBay 2U/4U hand-me-downs" workflow viable for years to come :D
I've got an old laptop lying around, could I hook at up to my router and access it without remote desktop software from another PC on my network?
Or does this require some expensive intel software with a subscription?
It works if the computer is fully vPro compliant. There are castrated versions of vPro for small businesses that lack the KVM feature. It’s all free and you just need to do the initial provisioning in the MEBx (post UEFI).
Again, having the ME in the CPU is not enough. The chipset, NIC, and BIOS/UEFI support matter.
True but it has been shown a lot of motherboards that should not support these things do, or at least that they are software enabled features.
Basically it's a business feature and usually not available on consumer laptops.
If IME could be reprogrammed then maybe there would be a way to add these features.
The device is weird because it strikes me as the perfect HTPC, and yet it isn't really marketed as such.
They're a lot more convenient for this than actual 19" servers, since they take up a tiny fraction of the space and power of even a single server. However they would be so much more useful if I could remote IPMI into them rather than having to find a monitor, keyboard, HDMI cable and mouse every time I want to fix them.
They would also be reasonable for home theatre since they are silent and low power, while at the same time having decent CPUs, but they use Intel graphics so I guess they probably can't drive 4K + 60Hz displays, although I've never actually tried.
On the other side because of security, I'm not sure whether I should be glad to use NUC models that don't have it at all.
So assuming I take the risk, what networking link does AMT require? Do I guess correctly that it works only over Ethernet? Thinking of mobile devices that have only a cellular modem link.
I'll give it a look, thanks.
Example: https://images-na.ssl-images-amazon.com/images/I/51FGMbh0rkL...
Rule of thumb (as far as I know, not exhaustive): No i3 model has vPro support, i5 models may or may not have vPro depending on the particular CPU used, and more or less all i7 models have vPro.
On newer machines you can set the IME to connect to a IPsec tunnel when some conditions are met and keep the IME enabled when the machine is on battery power and a wireless network. This allows you to administer the device when it is "outside of the office."
> VNC
> IPsec tunnel
This being the state of enterprise, no wonder every Fortune listed company is getting their doors blown off.
https://www.cyberciti.biz/faq/remotely-access-intel-amt-kvm-...
I personally run Coreboot on my Thinkpad with the ME "disabled" (essentially just broken and stuck in a constant bring-up state), and System76[2], Purism[3], and Dell sell machines with the option of disabling the ME entirely, if one is super-paranoid.
[1] https://github.com/corna/me_cleaner
https://twitter.com/rootkovska/status/939064351008395264
Purism routinely overstates their capabilities in this regard, claiming to "neutralize" the ME.
Also note that the ME is a hardware feature. Most efforts to remove/disable it focus on the ME firmware, which is loaded only some time after boot. Some ME function remains even if you completely zero out the firmware.
See Peter Stuge's 30C3 Talk "Hardening hardware and choosing a #goodBIOS", noting IPv6 packet sent over the network interface even then (around 17:18 mark).
archive.is is nice, but the Wayback Machine makes URLs which are a lot more transparent.