Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

> - ME can't actually be disabled completely according to Qubes OS founder Joanna.

In case you're referring to her article titled "Intel x86 considered harmful"[1] it's worth noting that she only speculated the following:

> A large part of the ME firmware is stored on an SPI flash chip, which admittedly could be reprogrammed using a standard EEPROM programming device to wipe all the ME partition from the flash. But this approach does not have a good chance of succeeding. This is because the processor itself contains an internal boot ROM [37] which is tasked with loading and verifying the rest of the ME code. In case the bootloader is not able to find or verify the signature on the ME firmware, the platform will shutdown.

However, if I understand correctly, that's exactly what Youness Alaoui[1] at Purism did.

[1] https://blog.invisiblethings.org/papers/2015/x86_harmful.pdf [2] https://puri.sm/posts/deep-dive-into-intel-me-disablement/



By my reading of this, it's hilarious: they turned on a feature that was provided for the NSA, the "HAP" bit. This put the ME into a special high assurance mode. But because it can't find the rest of the HAP software, it goes into "disabled" mode - without disabling the rest of the platform.


A perfect example of getting lucky. How long until subsequent Intel releases lack this.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: