Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Even this is too conspiratorial for me. Not because I believe the NSA wouldn't like access, but because it's not the best approach. Convincing Intel or AMD to have a hidden back door, and to somehow keep that it hidden, is a nearly impossible task. Compare that with just hunting for 0-days like the rest of the world, which the NSA has shown to be quite good at.

Not saying there couldn't be a targeted supply chain attack (that's essentially what was revealed in some of the Snowden leaks, e.g. targeting networking cables leased by big tech companies), but I don't believe there is some widely dispersed secret backdoor, even if just for the reason that it's too hard to keep secret.



At a minimum, it's a thing that certain security conscious consumers (cough DoD) were able to get Intel to include a hidden (not typically user accessible) bios flag for disabling most features of the management engine. So they're at least concerned about it as a security risk. That doesn't necessarily mean they also have backdoors into it, but it's not crazy to think they might. It's hard to be too conspiratorially minded with respect to intelligence stuff, if you aren't making the mistake of treating suppositions as facts.


I have a workstation bought from eBay that has a “ME DISABLED” sticker on the chassis.

Any analysis I could or should do?


Run Intel MEInfo utility, check if it reports "Alt Disable Mode" or anything like that. Article for some context: https://web.archive.org/web/20170828150536/http://blog.ptsec...


>Convincing Intel or AMD to have a hidden back door, and to somehow keep that it hidden, is a nearly impossible task

Interesting, how would an X86 instruction with hardcoded 256-bit key would be detected? IIRC it's really hard to audit the instruction space for CISC architecture.


Well sure, they would not use it for everyday standard cases to limit exposure. Intel does have something to loose, if this would became public knowledge.

But I cannot believe they resisted the temptation to use that opportunity to get such an easy access to so many devices.


Parent's point is that its very existence (not just use, as this is hardware/firmware we're talking about) in widely deployed form would be too risky.

Consequently, if there is an ME-subversion, it's only deployed / part-replaced for extraordinary targets. Not "every system."


Huh? As far as I know every Intel ME has access to the internet, can receive push firmware updates and write access to everything else on the system. It does not need a modified version, they can just use the official way, the normal Intel ME on target devices, if they can cloack their access of the official server, which I think could be achieved of using just the key of the official server and then use another server posing as the official server.

But it has been a while that I read about it and I never took it apart myself, so maybe what I wrote is not possible for technical reasons.


I don't think that's the case. Don't you need to have a selected NIC, integrated properly to get the Intel ME network features? Typically branded as "Intel vPro"

Otherwise, you need something in your OS to ship data back and forth between the ME and whatever NIC you have.


vPro, also known as AMT, is proprietary and it's for professional desktop and laptop systems. ME instead is based on IPMI and is for server-class systems.


Are they reusing the name to be more confusing? Intel ME calls to mind the management engine that's been embedded in most Intel based computers for the last 15 or so years.

https://en.m.wikipedia.org/wiki/Intel_Management_Engine


That's... definitely not how sensitive networks work. To say nothing of airgapped ones.

This seems like as good a short-form intro as any: https://blogs.cisco.com/learning/security-in-network-design-...


I would believe, really sensitive networks, have ME deactivated anyway and need other, specialised infiltration methods.

But when targeting a random individual in a hurry, I think it would be handy to just use the build in backdoor.


The trouble is, as far as I know, that the ME cannot be deactivated. Even if you are a really sensitive network. Your option is to find some of the few Intel chips without it, or find another chip vendor. This often means you can't use common off the shelf systems, so now you can be a victim of a targetted supply chain attack.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: