I didn't know this - so it's possible to turn off Intel ME? The idea of a full copy of Minix with TCPIP running on my machine is scary. Can someone else turn it back on?
I didn't know this - so it's possible to turn off Intel ME? The idea of a full copy of Minix with TCPIP running on my machine is scary. Can someone else turn it back on?
* By patching the ME firmware itself - see the me_cleaner project, and methods documented here: https://puri.sm/posts/deep-dive-into-intel-me-disablement/ . This is Pretty Reliable; the runtime code has been deleted from flash.
* By setting a bit in the flash configuration, assumed to be added for the US High Assurance program: https://github.com/corna/me_cleaner/wiki/HAP-AltMeDisable-bi... , https://www.ptsecurity.com/ww-en/analytics/disabling-intel-m... . This is Mostly Reliable; the mechanism has been fairly aggressively reverse engineered and was added for a program with strict requirements.
* By sending an HECI command that says "hey ME, turn off your runtime" https://review.coreboot.org/c/coreboot/+/52800 . This is Somewhat Reliable; the method is well understood and seems to work but I'm not sure someone has done a deep dive audit into whether it could be re-enabled somehow.
I haven't found anyone who has actually reversed the functionality to audit what it's doing, though.
There is no proof that they are
>hardly anybody bats an eye.
Because only a certain niche of paranoid people are willing to believe that companies are trying to make their systems intentionally insecure so that you can be personally hacked.
This is not unique to NSA. Security agencies within other governments play the same games with supply chains.
If you feel different that's fine but with security the old adage 'better safe than sorry' applies very much and given the data collected so far the evidence of 'some old leak' times n is rather more solid than your belief in the opposite. FWIW Intels claims that they would not cooperate with the NSA are worth absolutely nothing because the USG has the power to tell Intel to stay quiet about such a deal.
If CISCO could be influenced by the NSA then so can Intel, either through supply chain interdiction or through more direct means. But to categorically claim that this is an impossibility is nonsense, the relevant questions are (1) has it been done? and (2) how would we ever find out given the locked up status of the ME? and (3) who past Snowden would be brave enough to leak the evidence if it exists?
Well...
- I don't think the ME knows how to talk to non Intel NICs (install a Realtek or Broadcom based NIC).
Some searching I just did regarding "AMT" (remote management feature that uses the ME) says it needs an Intel NIC.
And, some searching I just did regarding vPro (not 100% sure what this is exactly) says vPro uses the onboard network adapter.
- So I don't think the ME will look for a NIC on the PCIe bus at all, but not 100% sure.
- I'm fairly sure AMT/vPro/the ME doesn't know how to talk to anything other than stuff on the PCIe bus (use a USB NIC)
- The NIC the ME would use has a MAC like any other NIC. Should be information available from the firmware. Just block it at the router.
Not really doubting you as that kind of stands to reason to me, but is there any proof of this? The whole thing seems opaque.
If the OS is running, wireless AMT forwards packets through the OS driver; it's cooperative (unlike the wired AMT, which always exists at a higher level than the OS, because it has features like resetting a crashed OS).
If the OS isn't running, you provision the AMT with WiFi credentials for the AMT host, using a tool. If you want, you can use the Local Manageability Service (LMS) tool to automatically forward credentials from the OS to the AMT, otherwise, you can install specific profiles.
When I'd built my first home server/NAS I wanted remote control but I didn't want to pay for hardware with real IPMI/iLO/..., so I choose desktop motherboard from Intel with Q35 chipset (it was time when Z45/Q45 was cutting edge and 35th series was previous generation). NIC was Intel's one too, I think it was legendary PRO/100, not 1G yet.
I was VERY disappointed to discover, that I didn't get remote console and/or remote serial port with ME/AMT at all, that it i not true AMT in desktop motherboards, even with Q chipset.