"In a statement, Intel officials wrote: ... we do not rely on obfuscation of information behind red unlock as a security measure."
(BTW, I work on Linux at Intel, I'm not posting this in any official capacity)
Oh, great! Isn't there a way where intel could provide keys so we could get rid of IME even if it means we won't be able to play DRM'ed content?
It's one thing to have that and be up front and open on it. Get secretive, and you're creating a massive source of unknown unknowns for everyone involved.
And like it or not, if you won't/can't be transparent about it, either
A) It'd take too long to document, which suggests there may be room for simplification
B) you're doing something that if it saw the light of day, would cause outrage, likely because you shouldn't be doing it
C) You're holding back the state-of-the-art for the sake of securing a revenue stream.
None of these inspires a excess of confidence/trust.Edit: Oh, you mention the encryption. Big companies love obfuscating everything they create, because they're afraid something commercially sensitive will exist there and someone will copy it and outcompete them. I agree that this is ridiculous, but I don't think it's evidence of any sort of nefarious activity.
Or do you mean.
- the TXE vulnerability and / or undocumented debugging mode (so microcode wouldn’t have been extracted)
- microcode encryption so the microcode would always have been completely readable
- x86
- Intel itself
?
I can see why they would sign/encrypt it so that things got safer, but then they should have done a much better job of it. If it was encrypted to hide something that could not stand the light of day then that's an entirely different matter altogether.
Time will tell.
Then AMD PSP did the same starting in 2013.