Slashdot Mirror


Intel x86s Hide Another CPU That Can Take Over Your Machine -- You Can't Audit it (boingboing.net)

A report on BoingBoing, authored by Damien Zammit, claims that recent Intel x86 processors have a secret and power control mechanism implemented into them that runs on a separate chip that nobody is allowed to audit or examine. From the report: When these are eventually compromised, they'll expose all affected systems to nearly unkillable, undetectable rootkit attacks. Further explaining the matter, the author claims that a system with a mainboard and Intel x86 CPU comes with Intel Management Engine (ME), a subsystem composed of a special 32-bit ARC microprocessor that's physically located inside the chipset. It is an "extra general purpose computer." The problem resides in the way this "extra-computer" works. It runs completely out-of-band with the main x86 CPU "meaning that it can function totally independently even when your main CPU is in a low power state like S3 (suspend)." On some chipsets, the firmware running on the ME implements a system called Intel's Active Management Technology (AMT). This is entirely transparent to the operating system, which means that this extra computer can do its job regardless of which operating system is installed and running on the main CPU. From the report: The purpose of AMT is to provide a way to manage computers remotely (this is similar to an older system called "Intelligent Platform Management Interface" or IPMI, but more powerful). To achieve this task, the ME is capable of accessing any memory region without the main x86 CPU knowing about the existence of these accesses. It also runs a TCP/IP server on your network interface and packets entering and leaving your machine on certain ports bypass any firewall running on your system. Update: 06/15 18:54 GMT by M :A reader points out that this "extra computer" could be there to enable low-power functionalities such as quick boot and quality testing.

Editor's note: The summary is written with inputs from an anonymous reader, who also shared the story. We've been unable to verify the claims made by the author.

368 comments

  1. Just as well by rossdee · · Score: 3, Interesting

    That my PC has an AMD CPU

    1. Re:Just as well by Anonymous Coward · · Score: 5, Funny

      Breaking: A user with AMD-powered computer found happy. More at 11PM.

    2. Re: Just as well by Anonymous Coward · · Score: 1

      Yep all those poweredge gaming machines can't be wrong.

    3. Re:Just as well by Anonymous Coward · · Score: 2, Interesting

      Except AMD chips appear just as problematic.

      https://libreboot.org/faq/#amd

    4. Re:Just as well by myowntrueself · · Score: 0

      AMD provides better processors for actual work, Intel relies on the kiddie gamer market.

      Not servers or anything like that. Almost all servers in data centers are running on AMD chips.

      --
      In the free world the media isn't government run; the government is media run.
    5. Re:Just as well by spire3661 · · Score: 5, Informative

      Intel market cap: $150 Billion

      AMD market cap: $3.54 Billion

      That is a lot of kiddie gamers........

      The plain truth is that Intel spends 4 times as much on R&D as AMD generates in revenue. AMD is a sad joke compared to Intel. They are not peers, hell they arent even really competitors. If they were sodas AMD would be RC Cola, to Intel's Coca-Cola, not Pepsi.

      --
      Good-bye
    6. Re:Just as well by Lumpy · · Score: 1

      Not true, I have a pile of IBM servers running XEON processors. I also have the raft of AMD servers as well, but it's not like one has a significant market over the other.

      And a lot of data centers I know of have Intel XEON servers. typically the high power ones that have 16-32 cores.

      --
      Do not look at laser with remaining good eye.
    7. Re:Just as well by marcansoft · · Score: 5, Informative

      ... and guess what, AMD CPUs have an extra ARM core in them, as well as multiple little cores of various architectures attached to the GPU. All running proprietary firmware.

      Throwing random little CPUs at problems is nothing new. What makes you think the firmware in your PCIe WiFi card also can't access all main memory and be turned into a rootkit? What about the Embedded Controller on laptops, that runs even when it's off?

      Yes, the state of firmware auditability of modern PCs is dismal. It's been like this for at least a decade. Yes, Intel does it one way, AMD does it another way, and just about every other peripheral on your board is also an attack surface. GPU? Dozens of little auxiliary cores (unrelated to the GPU unified shaders); Nvidia or AMD, doesn't matter. That USB 3.0 host controller? Probably runs firmware too. Ethernet? Yup, often has firmware these days. That LSI SAS controller? Full PowerPC core with enough oomph to run Linux itself. Your hard drive? 3 ARM cores, you can make them run Linux too. And all of those things can scribble all over your main memory unless you enable the IOMMU (except the HDD, that one can scribble all over your storage instead).

      Sleep tight.

    8. Re: Just as well by ArmoredDragon · · Score: 4, Informative

      Umm no, they don't. Maybe back in 2000 to around 2008, after Intel went with that netburst shit, but not anymore. Every datacenter I've managed for the last 3 years has almost no AMD gear at all.

    9. Re: Just as well by Anonymous Coward · · Score: 0

      Oh look, it's the sarcasm fairy! Wonder where she's going... *whoosh*

    10. Re:Just as well by Anonymous Coward · · Score: 0

      AMD CPUs have something very similar. An out of band "power management" processor what has full access to the memory via the PCI DMA.
      See 31C3 talk "AMD x86 SMU firmware analysis" https://www.youtube.com/watch?v=yE_PMcwltzo

    11. Re:Just as well by zamboni1138 · · Score: 2

      One of the best turkey sandwich's in town comes from a place that serves Royal Crown products.

      And this business has been successful and expanding for 30 years.

    12. Re:Just as well by Anonymous Coward · · Score: 0

      I don't know my k-6 was one hell of a bad ass processor I used it for over a decade. The fx9590 appears to be awfully nice too.

    13. Re:Just as well by mdouglas · · Score: 5, Informative

      AMD is the one that came up with x86-64 which Intel subsequently copied. Has anyone ever used an Itanium?

    14. Re:Just as well by lister+king+of+smeg · · Score: 5, Informative

      AMD is a cheap knockoff whose entire design philosophy revolves around avoiding patent and copyright lawsuits from Intel. Its in house technology is extremely inferior. The only good thing they can possibly do for the market now is to completely open up all development resources.

      And, let's bring back the alpha chip. It already is superior to Intel. Always has been.

      And GODDAMMIT! Where's our 3D printers that can print homemade computers? We were supposed to have that shit 30 years ago.

      Really...
      Its not like they are the one that made the AMD_64 instruction set that was then in turn licensed to intel...
      While its manufacturing technique is inferior that is because the brain-dead executives sold off their fab and they now have to contract with someone else to do it.
      As for bringing back ALPHA it may have been superior then they stopped developing it in 2001. Intel/AMD have come a long way in 15 years.

      --
      ---Saying gnome 3 is better than windows 8 not so much a compliment as it is damning with light praise.
    15. Re:Just as well by Anonymous Coward · · Score: 0

      If they were sodas AMD would be RC Cola, to Intel's Coca-Cola, not Pepsi.

      I happen to like RC Cola, you insensitive clod!

    16. Re: Just as well by loufoque · · Score: 3, Interesting

      What makes you think x86 is not already Alpha under the hood?

    17. Re:Just as well by sjames · · Score: 3, Interesting

      Don't forget, AMD brought us x86_64. Otherwise, Intel would probably still be pushing 32 bit Xeon to the masses and ultra expensive Itanic for 64 bit.

      AMD CPUs perform well as long as you don't use the Intel compiler. Unfortunately, most benchmarks are compiled with Icc complete with the built in sandbag code.

    18. Re:Just as well by blackomegax · · Score: 0

      AMD still has utter shit single-threading. Which is still useful for real work. And MT, they only barely catch Intel.

    19. Re:Just as well by Anonymous Coward · · Score: 2, Insightful

      Ironically, RC scores better in blind taste tests than Coca-Cola and Pepsi.

    20. Re:Just as well by zdzichu · · Score: 2

      You are fscked up the same way by AMD: https://libreboot.org/faq/#amd

      --
      :wq
    21. Re:Just as well by Anonymous Coward · · Score: 0

      Their in house stuff is extremely inferior? You mean like the amd64 architecture that intel uses in all of it's 64 bit chips?

    22. Re:Just as well by Anonymous Coward · · Score: 2, Insightful

      I use AMD's 8 core CPUs extensively for video editing/encoding and other tasks that benefit from a fast multicore CPU. Intel makes CPUs that offer comparable, or better, performance, but they are significantly more expensive.

      Intel's dominance has been largely the result of illegal tactics. They are the Microsoft of the CPU world. Every OEM has been told by Intel "If you buy from anyone other than us, then, in the future, you may find that we are unable to supply you with the parts you need"

    23. Re:Just as well by wierd_w · · Score: 2

      shit, secondary processors have been inside PCs since the 80s.

      Remember things like "A20 gate" in old pcs? It was a hack on the AT keyboard controller. It was introduced to solve an addressing issue with ram above 1mb in real mode.

      Using secondary chips to do things in memory is an ancient idea. The amiga relied on it quite heavily in fact.

      Own a Wii? There's a secondary ARM core nicknamed "scarlet" in there, running beside the PPC core.

      While having this system compromised by malware is a worrisome prospect, having it opened up for clever sideband processing tasks could be very beneficial to PCs in the future. Right now it is just a system management interface. In the future, that system could enable all sorts of neat stuff. granted, some of the things it can enable are not pleasant. A great many are, however.

      Why the scaremongering? Fear sells eyeballs, and eyeballs make money.

      Nothing to see here. Move along.

    24. Re:Just as well by loonycyborg · · Score: 2

      But you need to always remember that more money isn't automatically more work done. In practice access to more money leads to their inefficient use. Also, 4 times as much R&D isn't that much if you take possible inefficiency of spending into account. And market capitalization is very subjective measure.

    25. Re:Just as well by Anonymous Coward · · Score: 0

      That doesn't help you.

      AMD has the same functionality, though in their case it's built on an ARM module on-die.

    26. Re:Just as well by flink · · Score: 1

      AMD is the one that came up with x86-64 which Intel subsequently copied. Has anyone ever used an Itanium?

      Someone at HP or Intel must have financed a pretty great bender for our operations team in the early 2000s, because we bought in huge to the HP-UX Superdome on Itanium architecture. All we wanted was a platform to host our Tomcat web farm. We ended up supporting our application on that steaming propriety cow pie for about 5 years before we moved to cheap Intel Linux servers.

    27. Re:Just as well by Anonymous Coward · · Score: 0

      Thank you for that. I was feeling under the weather and needed a good joke to bring my spirits up.

    28. Re:Just as well by SumDog · · Score: 1

      AMD still dominates the console market. PS4/XBOX anyone?

      They also invented the entire AMD64/EMT64 extension to x86 (ironic since their early venture into the market were Intel clones).

      Intel uses a lot of anti-competitive practices to keep AMD from dominating, but I think they intentionally stopped short of killing them off. AMD having the console market makes and easy, "Look, we're not anti-competitive. AMD is still in the market, and they're in every gaming console!"

    29. Re:Just as well by SumDog · · Score: 1

      You realize that Intel bought DEC's entire Alpha architecture and killed it right?

      (Parts of that architecture made it into the Pentium Pro and later generations)

    30. Re:Just as well by mschwanke97402 · · Score: 2

      AMD64 was a set of completely obvious extensions to the Intel X86 model. Expand the existing 32 bit registers to 64 bit and add 64 bit versions of the existing 32 bit instructions as necessary. Nothing earth shaking or even novel. Intel made the mistake of not releasing their 64 bit earlier, and they easily could have, so AMD gets the bragging rights. There are quite a few articles about the whole deal.

      Now the lower level bits and pieces that make it all work down deep, AMD has not done a decent core design on their own in years and years, Intel keeps churning out great new core designs every 2-3 years. That's why Intel outsells AMD by far, except perhaps, at the lower performance/price points. You know, in all those budget PCs and the XBox One and PS4.

    31. Re:Just as well by SumDog · · Score: 2

      SD cards have a 32-bit micro-controller on them. They're used to mark bad sectors and keep writes from being on adjacent memory locations (disturbing memory locations a lot on SD cards can corrupt data). There's a talk out there somewhere, where a researcher reprograms the SD cards on-board processor, while keeping it functioning as an SD card. In theory, you could take a 25GB card, have it report it's 15GB and write a small program to make a copy of all writes to a hidden part of the card for retrial later.

    32. Re:Just as well by malditaenvidia · · Score: 1

      Don't the PS4 and Xbone use AMD processors, ya ditz?

    33. Re:Just as well by Anonymous Coward · · Score: 0

      Pentium pro? That CPU was introduced a little later than half way during the 90's. Alpha wasn't in Intel's hands until 2001.

    34. Re:Just as well by MachineShedFred · · Score: 4, Informative

      This is such overblown pap - the only way to provision Intel AMT / vPro is to either have physical access to the keyboard during reboot, or to have a certificate signed by a trusted provider specifically for provisioning AMT / vPro if you would like to do it over the network. And no, you can't add in your own self-signed nonsense because the CAs that can do this are in the AMT firmware. If you don't get a cert from Verisign / Comodo / etc., the firmware tells you to stick it up your ass and refuses to provision.

      Having done manual provisioning, scripted provisioning, and network provisioning in a technology trial for using vPro on a network with ~55,000 PCs spread across the continent, I can say that Intel thought about this "back door" and made it so that you have to go through some extraordinary work in order to use it. And, even then, unless you paid for full-blown vPro on each and every PC, you get access to basically what you could have done with Wake-on-LAN back in the day, with a few extras. With vPro you can do remote control and remote virtual disk mounts, but doing so causes big flashing red and yellow bars on the border of the screen letting a local user know someone's doing it.

      Moreover, Intel has been actively marketing this functionality for over 5 years to big business as a way to cut software costs for costly (and shitty) remote control solutions that don't work when the OS is fucked. To think that this is some super secret clandestine operation is complete horseshit.

      What an overblown piece of trash this 'article' is.

      --
      Slashdot still doesnâ(TM)t support Unicode after it was added to the HTML standard in 1997.
    35. Re:Just as well by wisnoskij · · Score: 1

      Sort of a ridiculous stance to take. AMD does pretty well for itself. The choice in Processor of graphics card is well understood to be so close that the deciding factor is how you plan on using the PC. At the end of the day, even without the marketing and monopolistic clout that Intel has AMD has managed to stay competitive enough to survive.

      --
      Troll is not a replacement for I disagree.
    36. Re:Just as well by MachineShedFred · · Score: 1

      Yeah, because as I look over the Amazon EC2 instance types, I see so many that are backed by AMD CPUs.

      No wait, they're 100% Intel Xeon.

      --
      Slashdot still doesnâ(TM)t support Unicode after it was added to the HTML standard in 1997.
    37. Re:Just as well by hairyfeet · · Score: 4, Interesting

      There is actually quite a lot of us because if you were to do a blind A/B test with an FX-8 versus an i5? You wouldn't be able to tell which is which....but your wallet would know the difference.

      My FX-8320E when paired with an R9 280 and 16GB of RAM plays all my games with so much bling that I have gotten killed on several occasions because I was too busy gawking at the pretty to notice the enemy coming up behind me, runs very very cool (on air the highest I have ever hit is 122F with all 8 cores slammed doing A/V work) and the whole system, with an SSD and 3TB HDD? Less than $550 after MIR.

      When you add to this the fact that AMD has been opening their docs, just as the FOSS community asked them to do, giving massive amounts of code to the community with Vulkan being just one of many, no DRM chips like TPM, oh and you can get their chips for often less than a third an equivalent Intel chip? Its really not a hard choice to make.

      --
      ACs don't waste your time replying, your posts are never seen by me.
    38. Re:Just as well by MachineShedFred · · Score: 1

      Well, for one thing, Intel purchased the remnants of Digital, so any ALPHA come-back would be under Chipzilla.

      --
      Slashdot still doesnâ(TM)t support Unicode after it was added to the HTML standard in 1997.
    39. Re:Just as well by Anonymous Coward · · Score: 0

      AMD CPUs performed well 10 years ago when Intel had it's head up it's ass. Now they haven't been able to keep up. Their best performing CPU is around 60% of Intel's best Core-series CPU, which doesn't even count the Xeon line.

      There's a reason AMD sells so cheap - they can't really talk the performance game anymore, so they have to sell to value.

    40. Re:Just as well by MachineShedFred · · Score: 2

      That's because the design considerations for a console are very different from a desktop PC.

      Price is far more of a factor when you are selling the hardware at a loss, and it's undisputed that AMD products are inexpensive in comparison to Intel.

      --
      Slashdot still doesnâ(TM)t support Unicode after it was added to the HTML standard in 1997.
    41. Re:Just as well by Archtech · · Score: 3, Insightful

      The plain truth is that Intel spends 4 times as much on R&D as AMD generates in revenue.

      The plain truth is that there is no necessary correlation between spending on R&D and useful results. It is an unfortunate modern delusion that spending vast amounts of money is somehow meritorious in itself. You see government officials doing it all the time. "We have spent $50 billion of [your] money on this, so congratulate us on a job well done!"

      --
      I am sure that there are many other solipsists out there.
    42. Re:Just as well by Archtech · · Score: 3, Informative

      I have always suspected that Itanium was merely a piece of FUD intended to discourage users from buying Alpha systems - which actually worked, and performed extremely well. (First time I tried out an Alpha running VMS, I ran a standard benchmark. Every time I ran the benchmark I just saw the command prompt come up immediately. Eventually I realised that the benchmark was running to completion faster than the terminal could move its carriage mechanism).

      --
      I am sure that there are many other solipsists out there.
    43. Re:Just as well by Anonymous Coward · · Score: 0

      Own a Wii? There's a secondary ARM core nicknamed "scarlet" in there, running beside the PPC core.

      "Starlet", continuing the whole movie theme (the chip was nicknamed by reverse-engineers, not Nintendo or IBM).

    44. Re:Just as well by Archtech · · Score: 4, Insightful

      Exactly so. For years I used to wonder which was more important: hardware or software. It was after the Alpha debacle that I came to understand that neither is very important compared to marketing.

      --
      I am sure that there are many other solipsists out there.
    45. Re:Just as well by r1348 · · Score: 1

      TPM is platform-independent, my HP laptop has an AMD Kaveri APU and a TPM chip.

    46. Re:Just as well by dunkelfalke · · Score: 2

      One would hear the difference. I used to be an AMD only guy for more than a decade, but then Core2Duo came out and suddenly I was able to have a fast CPU without a fan. And even now I have a passive cooled i5 - same cooler BTW as the Core2Duo from years ago.

      --
      "It's such a fine line between stupid and clever" -- David St. Hubbins, Spinal Tap
    47. Re:Just as well by sjames · · Score: 3, Informative

      In practice, they do well with heavy parallel computation, especially when measured on a cost per performance basis. It helps that quad socket designs are cheaper for AMD as well.

    48. Re:Just as well by Anonymous Coward · · Score: 0

      Pretty much this.
      Every single thing you plug into the system bus (PCI, PCI-E, hypertransport, whatever) will have complete access to everything.
      I guess the interesting thing here is that apparently this one also bypasses firewall rules and intercepts network traffic.
      This might contain some kind of vulnerability that's easier to exploit than hardware you need physical access to.

    49. Re: Just as well by Anonymous Coward · · Score: 0

      Until recently poweredge had AMD options available.

    50. Re: Just as well by johnsmithperson123 · · Score: 1

      Right up until Dozer (that was 2011, 2012) AMD enjoyed from the early 2000s a moderate to significant advantage in the server market, especially for core count and mixed virtualization. After Dozer... well, the entire company went south.

    51. Re:Just as well by Anonymous Coward · · Score: 1

      Funny that you mention illegal tactics of Intel while ignoring AMDs own illegal activities. Neither company are saints.

    52. Re:Just as well by Anonymous Coward · · Score: 0

      This is just FUD from some FOSS evangelist. "Oohhh, lookout, proprietary, scary monsters under the bed!"

      It's a management engine. It's right in the name people. Crying wolf over disclosed, announced functionality is so much FUD it isn't even funny. Do you know how your car works? "Oohhh, lookout, proprietary engine technology, scary monsters under the bed!"

      That isn't to say that involuntary, unintentional use of the IME isn't possible. The history of our industry is that systems untested by hackers (whether white or black) usually fail miserably. The real world of security regularly spanks those unprepared. And everyone is unprepared.

      However to suggest that the IME is some kind of "mole" in our systems, on par with the old KGB infiltrating the CIA during the Cold War, well that is preposterous. I dismiss you, sir! DISMISSED I SAY!!!

    53. Re:Just as well by Anonymous Coward · · Score: 2, Interesting

      Alpha engineers went to AMD, I think to build the 64 bit processors. Those were great, but Intel kept them out of the market with anti-competitive deals and by rigging benchmarks, it seems.

    54. Re:Just as well by Qzukk · · Score: 1

      These days it seems that scammers just take 4GB cards, reprogram them to report that they're 16GB and just let the thing fail when you fill it up. A lot more money to be made that way than the opposite.

      --
      If I have been able to see further than others, it is because I bought a pair of binoculars.
    55. Re:Just as well by Anonymous Coward · · Score: 0

      The current Intel stuff still seems to share bugs with the Pentium III. Which was a quite good processor. And did you notice that while they become more efficient, the actual performance of the 3000 to 6000 series is not rising by much (except when new extensions come into play).
      Anyway, AMD bet on a power/performance point that was not really worth it, except for consoles. And they do not have the income to quickly correct that.

      And.. did you see Intel selling Atom processors?

    56. Re:Just as well by reboot246 · · Score: 2

      Maybe the NSA has already done that "extraordinary work" you speak of.

    57. Re:Just as well by viperidaenz · · Score: 1

      Unless your hard drive is NVMe, then it can scribble all over your storage and main memory.

    58. Re:Just as well by TeknoHog · · Score: 4, Interesting

      AMD64 was a set of completely obvious extensions to the Intel X86 model. Expand the existing 32 bit registers to 64 bit and add 64 bit versions of the existing 32 bit instructions as necessary. Nothing earth shaking or even novel.

      Ideas are a dime a dozen. It's the actual implementation that makes a difference in the real world. If the idea were so obvious, you'd think that Intel would have been in a much better position to bet on the new idea, with all their resources.

      It's interesting that after about 14 years of AMD64, we are still haunted by x86-32 in many places with closed binary-only software. For instance, Skype on Linux was only released as a 32-bit binary, so you had to maintain all these ugly compatibility libraries. I wonder how much of this is due to the AMD origins of the architecture, and the subsequent slowness of the Intel and Microsoft camp to adopt it.

      --
      Escher was the first MC and Giger invented the HR department.
    59. Re:Just as well by Roman+Mamedov · · Score: 2

      What makes you think the firmware in your PCIe WiFi card also can't access all main memory

      Something which is called an IOMMU.

      https://en.wikipedia.org/wiki/...
      Memory is protected from malicious devices that are attempting DMA attacks and faulty devices that are attempting errant memory transfers because a device cannot read or write to memory that has not been explicitly allocated (mapped) for it. The memory protection is based on the fact that OS running on the CPU (see figure) exclusively controls both the MMU and the IOMMU. The devices are physically unable to circumvent or corrupt configured memory management tables.

    60. Re:Just as well by Anonymous Coward · · Score: 0

      AMD is releasing a new chip this year, hopefully at a good price/performance ratio and without these shenanigans.

    61. Re:Just as well by Anonymous Coward · · Score: 0

      No they don't. The i7-5960x is faster than anything AMD has produced for the desktop market - from the 9590 on down - in everything. Every. Single. Thing. AMD stopped updating the underlying microarchitecture of their 6+ thread chips in 2012. Piledriver is all they've had in that market segment for four years. Steamroller and Excavator have been relegated to 1m and 2m chips.

    62. Re:Just as well by Anonymous Coward · · Score: 0

      Ditto. I had the pincers from my cooler broken for almost 2 years, on a always on rig, meaning that it was only making contact between the cooler and CPU by cheer gravity (ofc, I laid the tower down) and it worked flawlessly even on load and never let me down even once.

      Recently I gone and bought a new cooler because I was tired of being lazy and having the tower taking so much floor space while it was laid down as it was.

    63. Re:Just as well by Anonymous Coward · · Score: 0

      How do you know the three letter agencies haven't added their own private key to the TPM module for intelligence purposes?
      I would if I was in their position. Has anyone de-capped the TPM module and analyzed the ROM data?

    64. Re:Just as well by Anonymous Coward · · Score: 0

      AMD's equivalent is the Platform Security Processor, or PSP.

    65. Re:Just as well by _merlin · · Score: 2, Interesting

      I tried to like Alpha, I really did. But it was impossible to like. The DEC Alpha workstations were horribly unreliable - you often had a third of your workstations out of service at any given time due to power supply or mainboard failures. They used far too much power and ran too hot. And Sun UltraSPARC quickly leapfrogged them in performance. Add to that the annoying ISA and horrible weak memory model that made it really hard to do any concurrency, and no-one wanted to touch it. NetBurst was basically an x86 front-end bolted onto an Alpha back-end, and it became evident very quickly that it was a dead end, just like Alpha itself. Alpha got high clock speeds, but not much else.

    66. Re:Just as well by Anonymous Coward · · Score: 0

      Not really, the STP is about 20-30% slower on a given load unless you're specifically using intel-optimized code, in which case you get 40-50% slower.

      Imagine running Nvidia drivers on your AMD Radeon (with an abstraction layer hack) and getting 50~ % performance out of that? It'd be pretty damn good, right?

      Market share is king, though. If you don't have it, nobody makes stuff for you and you're stuck eating un-optimized dust.

      Still on the low-end, AMD APU's are equal to Intel's offerings or better per dollar/watt..

    67. Re:Just as well by dgatwood · · Score: 1

      It's fascinating, really. The main reason RC is less popular is that it is available in fewer locations and has less shelf space allocated to it in the locations where it is available. Why is it available in fewer locations, you might ask, and why does it have less shelf space? Because it is less popular.

      I don't think the same applies to AMD, though.

      --

      Check out my sci-fi/humor trilogy at PatriotsBooks.

    68. Re:Just as well by Anonymous Coward · · Score: 0

      A classic example of the who-gives-a-shit anecdote.

      Nothing to see here, move on.

    69. Re:Just as well by Fragnet · · Score: 1

      That's a really quite ridiculous assertion.

    70. Re:Just as well by Fragnet · · Score: 2

      Depends what you're encoding. Intel chips with onboard HD graphics have QuickSync for H264 encoding and decoding. I expect it'll go 10 bit soon too. The encoding and decoding performance is quite stunning.

    71. Re:Just as well by Bengie · · Score: 3, Interesting

      AMD didn't come up with x86-64, a specific person that AMD hired came up with it. And immediately after that person left, AMD created the netburst version of their CPUs. I was reading that with the new AMD Zen, AMD pretty much left everything up to the engineers and had them start over with a clean slate. Only time will tell, but from what I'm reading, it will likely pay off in spades.

    72. Re:Just as well by yusing · · Score: 2

      Hell, Commodore 1541 floppy drives contained their own 6502 for an on-board DOS. Programming the drive was a hot topic for years.

      --

      "You must try to forget all you have learned. You must begin to dream." -- Sherwood Anderson

    73. Re:Just as well by hairyfeet · · Score: 1

      FUD the ONLY chips that have the ARM core are the 4 that were based on the consoles, even the AMD page on the subject hasn't been updated since 2013, why? Because they only bought the ARM DRM for the consoles that demanded it and never bothered to do anything else with it.

      So its only there if you buy one of the 4 ULV chips based on Jaguar, and even then there is no known software in the wild that can even access it. Its a leftover from their deal with the consoles and the only chips you can buy with it are ones that didn't pass muster to be included in the consoles.

      Now that said I've built a couple HTPCs using the Jag and they run just fine, one is running Win 8 (the only place Metro makes sense, a 10 foot UI) and the other is running OpenELEC Linux and both run great, if all you are needing is an ULV HTPC for 1080P video or a media server you can stuff in a closet? Works good for that purpose, but the ARM chip isn't an issue.

      --
      ACs don't waste your time replying, your posts are never seen by me.
    74. Re:Just as well by Pseudonym · · Score: 1

      AMD64 was a set of completely obvious extensions to the Intel X86 model.

      I sometimes think that AMD's genius isn't what they added, but what they dropped by design. If it had been up to Intel, x86-64 would have a 64-bit "real mode", an even more complicated TSS, and yet another incompatible segmentation type.

      --
      sub f{($f)=@_;print"$f(q{$f});";}f(q{sub f{($f)=@_;print"$f(q{$f});";}f});
    75. Re:Just as well by Narcocide · · Score: 1

      Except you're wrong because that "60%" you're talking about is those very same aforementioned illegally sabotaged benchmarks. In reality its 5-10% at most for any actually fair empirical or relevant real-world test.

    76. Re:Just as well by Narcocide · · Score: 1

      Spoken like someone who has agonized and studied every 3rd party benchmark ever posted to tomshardware or phoronix but never once tried to recreate one himself using something other than the Intel compiler.

    77. Re:Just as well by Narcocide · · Score: 1

      Yea, not only those but a rather large majority of the previous few generations of consoles primarily feature AMD/ATi hardware. I believe ATi video cards also held a significant marketshare of OEM PC installations before losing some contract with Dell to Intel.

    78. Re:Just as well by Narcocide · · Score: 1

      Ah yes, back in the days when your sound card was a bonus feature of your disk drive...

    79. Re:Just as well by Anonymous Coward · · Score: 0

      Sorry fella, AMD is properly crap. Poor me agreed with you but not any more. I have aspirations now and a wife - move on mate whilst you can.

    80. Re:Just as well by inode_buddha · · Score: 2

      Um, no. Compaq bought DEC, and was in turn bought out by HP. WTF did anyone get the idea that intel bought alpha???

      --
      C|N>K
    81. Re:Just as well by Anonymous Coward · · Score: 0

      AMD's from 2012 and back are free of this, but most post-2013 AMD CPUs have it. Unlike Intel, where this additional CPU is in the motherboard, with newer AMDs it's in the CPU itself.

    82. Re:Just as well by ChrisMaple · · Score: 1

      AMD is losing a half billion dollars a year. It's a miracle their creditors don't shut them down.

      --
      Contribute to civilization: ari.aynrand.org/donate
    83. Re:Just as well by cm5oom · · Score: 1

      Why do people keep bringing up amd64 as if that some how invalidates the hundreds if not thousands of things intel as done over the last 50 years. Other than amd64 what has amd done in the last 10 years, a big fat nothing that's what. Who brought us the core duo, the core 2 duo, the core 2 quad, nehalem, sandy bridge, need I go on? The fact that everybody uses that one thing amd did over a decade ago to defend them should be a big flashing warning sign that the company is not very relevant in todays market. Stop living in the past.

    84. Re:Just as well by Anonymous Coward · · Score: 0

      Radeons and GeForce cards have a similar microprocessor to manage clocks, voltages, power rails, boot the gpu's peripherals, run the security engine and handle microcoded ops. They are both using a mix of custom 32-bit microcontrollers and RISC V.

    85. Re:Just as well by Dorianny · · Score: 1

      AMD is a cheap knockoff whose entire design philosophy revolves around avoiding patent and copyright lawsuits from Intel. Its in house technology is extremely inferior. The only good thing they can possibly do for the market now is to completely open up all development resources.

      And, let's bring back the alpha chip. It already is superior to Intel. Always has been.

      And GODDAMMIT! Where's our 3D printers that can print homemade computers? We were supposed to have that shit 30 years ago.

      Really... Its not like they are the one that made the AMD_64 instruction set that was then in turn licensed to intel... While its manufacturing technique is inferior that is because the brain-dead executives sold off their fab and they now have to contract with someone else to do it. As for bringing back ALPHA it may have been superior then they stopped developing it in 2001. Intel/AMD have come a long way in 15 years.

      AMD had some very large maturing-bonds repayments coming up at the time. Effectively frozen out of the debt-market and without Investors willing to inject new capital AMD had to choose between selling assets or declaring bankruptcy. Selling and leasing back non-liquid assets is used often by companies that need money but are shut out of the debt-markets because of over-leverage or other issues with with the business. It is essentially a secure loan backed by collateral

    86. Re:Just as well by Anonymous Coward · · Score: 0

      "In theory, you could take a 25GB card, have it report it's 15GB and write a small program to make a copy of all writes to a hidden part of the card for retrial later."

      Then you write to the card, delete it and fill the card up, delete and write it full a few more times.

    87. Re:Just as well by marcansoft · · Score: 1

      The ARM has nothing to do with game consoles. The PS4 and the Xbox One don't even use the ARM for their secure boot/DRM, they use something else (the PS4 uses the SAMU which is an LM32 derivative core inside the GPU portion, and I think the Xbox One uses more custom stuff). Read this libreboot page; the ARM is required to boot any modern AMD chip. Or this if you want a reference from AMD from last year. The PSP is very much alive and well and required to boot modern AMD chips.

    88. Re:Just as well by Anonymous Coward · · Score: 2, Insightful

      NetBurst was basically an x86 front-end bolted onto an Alpha back-end

      I'm calling bullshit on this assertion. Willamette, the first NetBurst CPU, was released in 2000. The Alpha intellectual property wasn't sold to Intel until 2001. Now, it's true that Alpha became Compaq's property in 1998, but considering the lead time required from initial design to tape out to production, I simply cannot believe that NetBurst had an Alpha back-end.

    89. Re:Just as well by Cederic · · Score: 3, Insightful

      While true, it's also true that without doing any R&D you tend to find yourself short on new products.

      Give me $5bn on R&D and I promise I'll give you a more valuable new product opportunity than if you give me $5m

      I don't promise I'll give you a positive ROI ;)

    90. Re:Just as well by Anonymous Coward · · Score: 0

      yes, yes, yes, but the auxiliary cores of my GPU can't access the memory directly and it can't talk to the network!!!!

    91. Re:Just as well by Anonymous Coward · · Score: 1

      There is (or was, not sure if it has been relaxed) a rule that the DOD requires at least two sources for any component. Kill off your competitor, and suddenly you can't bid on any DOD contracts.

      If I recall correctly, that was how AMD got a license to the x86 patents in the first place. Intel needed a competitor that could be a second source to be allowed to bid on DOD contracts.

    92. Re: Just as well by Anonymous Coward · · Score: 0

      The usual server manufacturers just don't sell AMD.

      When I did a quick survey some years ago, the only one where AMD was even an option was HP.

      A sad state of affairs.

    93. Re:Just as well by Anonymous Coward · · Score: 0

      So, AMD designed the most used 64-bit CPU architecture, reducing Intel to a clone-maker. Meanwhile, Intel produced a lot of trademarks...

    94. Re:Just as well by AmiMoJo · · Score: 1

      If you are going to that level of paranoia though you can't trust anything on your computer. We know that the NSA intercepts hardware being shipped to customers and tampers with it, so you can't trust your BIOS, your GPU firmware, the CPU microcode, the HDD firmware...

      --
      const int one = 65536; (Silvermoon, Texture.cs)
      SJW, n: "Someone I don't like, and by the way I'm a fuckwit" - AC
    95. Re:Just as well by Archtech · · Score: 4, Interesting

      Working at DEC in 1992-3, I never saw anything like that. The Alpha computers I used were exactly like their VAX predecessors except that they ran a whole lot faster. No unreliability, no overheating. Perhaps your experience was running Ultrix, which was always an unhappy compromise - like all proprietary version of Unix.

      My assessment, as a 20-year DEC employee, was that Alpha was perhaps the greatest hardware achievement the company ever brought off.

      --
      I am sure that there are many other solipsists out there.
    96. Re:Just as well by Anonymous Coward · · Score: 0

      Truth. Been using AMD since Barton 3000+. Pentium IV was too expensive for me at the time. Wallet has hurt far less since then. No problems with games for last 13yrs, usually paired with GTXx70 equiv of the day. Fabulous chipset/pin future proofing. Always handled my Nuendo/Tools' projects. Just replace the shitty stock coolers and you're away.

      Sure, with unlimited money I'd go a top end i7 just to have the best performance. But it pwns the pocket too much for diminished real world return in my usage needs, regardless of technical superiority. Also, the heatsink clips are annoying on Intel boards.

      All time fav bang-for-buck is still Celeron 300A Mendocino chips though. Plus some household fans, and a refreshing Jolt Cola to celebrate the moment you hit 450Mhz.

    97. Re:Just as well by _merlin · · Score: 2

      That's quite a bit earlier than my experience with them - I only dealt with Alpha workstations (not servers), running Ultrix (not VMS), and towards the end of their run. It's possible they'd gone downhill by then.

    98. Re:Just as well by TheRaven64 · · Score: 1

      That's not an entirely fair comparison, as Intel is in a lot more markets than AMD. If the world decided to stop buying x86 processors tomorrow, then AMD would be completely sunk (or, close to, depending on how well their ARMv8 chips sell), whereas Intel would just shut down a few divisions. The majority of Intel's R&D spend is on process technology. This is why they're usually a generation ahead of their competition on fabs. AMD, in contrast, outsources the production and so this R&D money shows up as an expense on their balance sheet and is shared with other companies that fab chips in the same foundries as AMD.

      --
      I am TheRaven on Soylent News
    99. Re:Just as well by nhat11 · · Score: 1

      As mentioned in other ./ posters here, AMT is an advertised feature and AMD have some extra chips too. This is some tin foiled hat article

    100. Re:Just as well by dwye · · Score: 1

      It has less shelf space because they don't pay the stores enough to get more shelf space.

      As to them beating Pepsi or Coke in taste tests, whose tests? Pepsi;s tests showed them beating Coke at the same time that Coke's tests showed Coke was preferred by people drinking more than a small cup at a time. This rather implies that test design is as important as the wording on political polls in determining the outcomes, that it, _very_ important.

    101. Re:Just as well by allo · · Score: 1

      what have the romans ever done for us?

    102. Re: Just as well by Anonymous Coward · · Score: 0

      Not architecture, instruction set and mode definitions. Basically AMD produced a set of specs, then Intel implemented it better than AMD did.

    103. Re:Just as well by cm5oom · · Score: 1

      That was kind of my point. I mean what has intel done for the pc platform? I'm just here shilling for a company that's never done anything to make x86 better mean while amd did that one thing a decade ago that everybody won't shut up about.

    104. Re: Just as well by Anonymous Coward · · Score: 0

      Your benchmark sucks

    105. Re:Just as well by Junta · · Score: 1

      They were pretty much that way back in the day, but around the time of Netburst they came into their own. Intel course corrected to a good architecture as of Nehalem and AMD went down a very wrong path in Bulldozer, relegating them to the current state of affairs.

      --
      XML is like violence. If it doesn't solve the problem, use more.
    106. Re:Just as well by thegarbz · · Score: 1

      I think it may have a lot more to do with the "if it ain't broken don't fix it" crowd. I mean there's a lot of software that really doesn't gain any benefit from being re-compiled as 64bit, and then what came first the ugly compatibility library or the software using it? That answer is obvious and when the compatibility libraries are there, why bother?

    107. Re:Just as well by TeknoHog · · Score: 2

      I sometimes think that AMD's genius isn't what they added, but what they dropped by design. If it had been up to Intel, x86-64 would have a 64-bit "real mode", an even more complicated TSS, and yet another incompatible segmentation type.

      This. AMD64 feels cleaner in some sense, though I'm not qualified to comment on the details of memory management. For example, consider the x32 initiative that was floated around the Linux community in the past few years: using the AMD64 ISA with only 32-bit pointers. The idea was that it would speed up a lot of software, and the 4 GB limit per process would not hurt most users. To me this seemed like a step backwards: just as we finally got a nice flat memory space, these guys want to go back to something like segmentation or PAE for a small performance increase.

      --
      Escher was the first MC and Giger invented the HR department.
    108. Re:Just as well by TeknoHog · · Score: 1

      One would hear the difference. I used to be an AMD only guy for more than a decade, but then Core2Duo came out and suddenly I was able to have a fast CPU without a fan. And even now I have a passive cooled i5 - same cooler BTW as the Core2Duo from years ago.

      I also had a passive cooled C2D, T7200 to be precise. For a lot of workloads, it was much faster than the Ci5 in my newer laptop. Unfortunately, I needed a better motherboard and more than 3 GB of memory, none of which were available with the suitable chipset and socket.

      Intel clearly has the lead in power efficiency, so I generally prefer it for mobile/fanless uses. AMD for everything else -- besides the pricing, they have much less artificial market segmentation.

      --
      Escher was the first MC and Giger invented the HR department.
    109. Re:Just as well by Anonymous Coward · · Score: 0

      AMD64 was a set of completely obvious extensions to the Intel X86 model. Expand the existing 32 bit registers to 64 bit and add 64 bit versions of the existing 32 bit instructions as necessary. Nothing earth shaking or even novel. Intel made the mistake of not releasing their 64 bit earlier, and they easily could have, so AMD gets the bragging rights. There are quite a few articles about the whole deal.

      Just to be clear: When AMD releases something first then it an "obvious extension" but when Intel releases it first then AMD is a "cheap knockoff"?

      Go ahead and keep buying Intel chips. That should keep the prices of AMD chips lower so I can save money.

    110. Re:Just as well by MachineShedFred · · Score: 1

      Ok good - they can provision AMT and vPro on your PC. They still can't remote observe without you knowing about it, because of big flashing yellow and red bars on the sides of the screen. Or, if you're using a non-Intel GPU, it just doesn't work.

      The only possible way to get this to remotely execute code is to mount a bootable ISO as an optical disk, force a reboot to it, and have your ISO do things. But that's an incredibly convoluted (and obvious) way to "exploiting" a system when there's 100 easier ways through known software flaws. And, completely useless if you've done something very mundane, like encrypt the disk.

      In order to use vPro as an attack vector, you'd have to stack up a ridiculous amount of flaws and attacks, that it's just not worth the time and effort.

      --
      Slashdot still doesnâ(TM)t support Unicode after it was added to the HTML standard in 1997.
    111. Re:Just as well by Anonymous Coward · · Score: 0

      Athlon was more like 15 years ago...

    112. Re:Just as well by Anonymous Coward · · Score: 0

      AMD didn't come up with x86-64, a specific person that AMD hired came up with it.

      And Intel didn't come up with the x86 instruction set. Specific people that Intel hired came up with it. See the flaw in your logic yet?

    113. Re:Just as well by Anonymous Coward · · Score: 0

      This is such overblown pap - the only way to provision Intel AMT / vPro is to either have physical access to the keyboard during reboot, or to have a certificate signed by a trusted provider specifically for provisioning AMT / vPro if you would like to do it over the network.

      You don't know that at all, and that's the point of the article.

    114. Re:Just as well by StuffMaster · · Score: 1

      Intel's dominance was due to illegal tactics when netburst was their thing. Since Core 2, and especially since Nehalem, they've been tops in per-core performance. Then AMD pulled a Netburst and created Bulldozer and haven't been even close to competitive.

      I know they don't have the resources to compete equally, but I'd really like AMD to be a contender again.

    115. Re:Just as well by Anonymous Coward · · Score: 0

      Hey, Some of us actually love RC Cola and Diet Rite!!!

    116. Re:Just as well by Coren22 · · Score: 1

      If you feel this is true, link to a single benchmark that doesn't use the intel compiler, and shows an AMD chip outperforming the i7-5960x. Otherwise, you are just blowing smoke.

      https://www.spec.org/cgi-bin/o...

      Feel free to point out any AMD processors that beat out the i7-5960X at 394.

      --
      APK likes to ask for responses to the same things over and over. Maybe he just likes the responses?
    117. Re:Just as well by Coren22 · · Score: 1

      Yeah, TPM is a hardware encryption chip, it could be used for DRM, but mostly it is used to store the hard disk encryption keys so you can boot Windows without having to type in a decryption password.

      --
      APK likes to ask for responses to the same things over and over. Maybe he just likes the responses?
    118. Re:Just as well by Anonymous Coward · · Score: 0

      You mean like has a root key to give themselves any key they want? No way, that would be like too easy...

    119. Re:Just as well by MobyTurbo · · Score: 1

      Like most Intel features AMD has the same thing in their chips, PSP they call it. "platform security processor", it peforms exactly the same function as IME, and happens to also use a seperate CPU just like Intel does for it.

    120. Re:Just as well by cm5oom · · Score: 1

      Thank you for being a prime example of what I'm talking about.

    121. Re: Just as well by Anonymous Coward · · Score: 0

      Also, terminals don't have a "carriage mechanism". What, are you from the 1950's typing pool??

    122. Re:Just as well by NotAPK · · Score: 2

      You're absolutely right, we can't.

      But do not be surprised that some people want to talk about it. And certainly do not be surprised when foreign nations decide not to buy US hardware and software. I'm not saying Chinese hardware is any more innocent, that's not the point I'm making, the decision that the NSA made (was anyone consulted?) to subvert the security of every PC on the planet will have repercussions. And this will have significant impact on the IT economy of the US.

      As an individual wanting to use a trusted computing platform, for my own computing needs and those of my small business, I now have to look far and wide for hardware I can trust. Personally I'm keeping a close eye on the Russian effort to shrug off x86 dependence.

    123. Re:Just as well by Anonymous Coward · · Score: 0

      NetBurst was basically an x86 front-end bolted onto an Alpha back-end, and it became evident very quickly that it was a dead end, just like Alpha itself.

      Alphas I remember were wide machines, not narrow like NetBrust. Alpha got into problems due to lack of design process automation, as I recall. Basically it got killed by the complexity.

    124. Re:Just as well by Anonymous Coward · · Score: 0

      If I am not mistaken, correct me if I am, AMT and vPro are only parts running on the ME. We know what AMT and vPro can do and how to interact with them, but we don't know everything the ME can do.

    125. Re:Just as well by andrew71 · · Score: 1

      Almost a century has passed - at least that's what it feels like - and still we don't seem to have learned that the drive was called 154I (with a final capital "i") :-)

      --
      13-4=54/6
    126. Re: Just as well by KenHansen · · Score: 1

      They are the Microsoft of the CPU world.

      Most companies would love to become 'the Microsoft' of their industry.

      Every OEM has been told by Intel "If you buy from anyone other than us, then, in the future, you may find that we are unable to supply you with the parts you need"

      Those bastards! Publicly admitting to treating loyal customers that exclusively use only their parts better service! BTW, "every OEM" I am aware of has offerings that use both AMD and Intel CPUs.

    127. Re: Just as well by KenHansen · · Score: 1

      Ironically, RC scores better in blind taste tests than Coca-Cola and Pepsi.

      But honestly, how big is the blind soda drinker market?

    128. Re:Just as well by mschwanke97402 · · Score: 1

      Intel actually did have x64 in-house. They decided there was no need for it and sat on it. They were right in that regard too. There was little, to no, actual 64 bit software to run on the AMD64 processors. Server stuff, OK, but nothing on the desktop. The old chicken/egg conundrum. Recall that the original Windows XP 64 bit was really Server 2003 64 bit in consumer clothing. A real hot mess that was.

      Anyway, even though it was more of a marketing ploy at the time, AMD deserves credit for moving the market along a bit, my point was that they didn't really invent anything earth-shattering. Everyone in the business knew what x64 would look like it was just the waiting to see it realized that was hard.

    129. Re:Just as well by mschwanke97402 · · Score: 1

      Obvious as in we'd all been there, done that several times when we moved from 8 bit to 16 bit to 32 bit. In order to maintain the Intel ISA compatibility going forward you are constrained to doing things a certain way. It is fairly obvious. Remember that when you parse it all down to basics, AMD is a licensee of Intel, as in, they have paid for the right to copy Intel's processor architecture.

      As I said earlier, when it comes to implementing that architecture, down at the microcode and pipeline level things are different. That's where it isn't at all obvious and innovation and hard work can really matter. Ten years ago AMD was eating Intel's lunch because their micro-architecture was so much better.. I do give them credit where it is due.

      Nowadays, AMD's cores aren't nearly as good as Intel's. Intel outspends AMD by far, year in and year out, on their R&D. AMD does cost less and that is a good reason to choose them for some purposes. I will continue to choose Intel when performance, heat and power consumption concern me.

    130. Re:Just as well by Anonymous Coward · · Score: 0

      My AMD Zambezi black edition 8 core FX-8350 that I bought retail 3 years ago with an AMD water cooling setup for $189, lays waste to most i7's on the market on the market even today. You are right though they are not even really competitors. If they were operating systems intel would be microsoft and AMD would be linux. Intel overcharges, under delivers, could care less about their customers, the only reason they have majority market share is because of inompetent people that don't know any better which makes up about 50% of intels customer base, the other 50% coming from pre-installed systems that come prepackaged with overpriced intel chips because they made deals with the manufacturers.

      You judge quality by how much money you get robbed for, you must be an apple fan boy also.

    131. Re:Just as well by Anonymous Coward · · Score: 0

      Damn I miss my Alphaservers. :-(

    132. Re:Just as well by Anonymous Coward · · Score: 0

      unless you enable the IOMMU

      For this you need at least Enterprise version of Windows and some configuration. Do Linux and friends utilize IOMMU for memory protection even without running a hypervisor?

    133. Re:Just as well by djl4570 · · Score: 1

      Compac sold the Alpha IP to Intel in June 2001. HP announced the acquisition of Compaq in September of 2001.
      http://www.zdnet.com/article/a...

    134. Re:Just as well by Anonymous Coward · · Score: 0

      The reality is that AMD was always shit, it's just that at various points in the past, Intel has been even more shit.

      Neither was worth bothering with when PowerPC was still viable.

    135. Re:Just as well by Anonymous Coward · · Score: 0

      Well then Intel couldn't sell to the DoD, fucknut.

      Think you're smart eh?

    136. Re: Just as well by Anonymous Coward · · Score: 0

      Ours is almost solely AMD gear.

      In our niche our CapEx is by far the smallest, along with OpEx. Hell, even our systems are done QA first tendency which has resulted that we offer the most stable performance in our niche. Not the highest peak performance, but every user gets what they paid for.

      Intel systems even use more power than the AMD counterparts we use oO; Which was kind of unexpected.

  2. Nefarious Headline for Practical Feature by Anonymous Coward · · Score: 3, Funny

    This is key to enabling low-power functionality in Intel CPUs - think quick boot and quality testing. It doesn't have any surveillance or other purposes.

    1. Re:Nefarious Headline for Practical Feature by BlackPignouf · · Score: 2, Insightful

      Sure, and there's no way it could be used by three letter agencies, ever.

    2. Re:Nefarious Headline for Practical Feature by NotInHere · · Score: 1

      I think the critical part is that intel doesn't let anyone write code for that chip, basically making it a black box.

      BUT I think its better to have it in the hands of Intel than, say, Microsoft.

    3. Re:Nefarious Headline for Practical Feature by Anonymous Coward · · Score: 0

      And you know this because of the thorough audit you did on it right...

    4. Re:Nefarious Headline for Practical Feature by LynnwoodRooster · · Score: 1

      Why do that when you can just get the OS vendors to give you backdoors and control? That way you can access everyone, not just the few that have this extra hardware feature...

      --
      Browsing at +1 - no ACs, I ignore their posts. So refreshing!
    5. Re:Nefarious Headline for Practical Feature by Yvan256 · · Score: 1

      You really think AMD will mess around with Intel's CPU?

    6. Re:Nefarious Headline for Practical Feature by Anonymous Coward · · Score: 0

      If it could it would likely be for Israel's unit 8200, not the NSA.

    7. Re:Nefarious Headline for Practical Feature by fph+il+quozientatore · · Score: 1

      You probably made a typo -- the keys for "just the few" and "all of them" are close-by on the keyboard, after all.

      --
      My first program:

      Hell Segmentation fault

    8. Re:Nefarious Headline for Practical Feature by BronsCon · · Score: 1

      On one hand, I think this whole thing is overblown. On the other hand, playing devil's advocate, the TLAs can't access a machine that is powered down; this potentially allows them to turn it on remotely.

      --
      APK quotes people (including myself) without context and should not be trusted. Just thought you should know.
    9. Re:Nefarious Headline for Practical Feature by almechist · · Score: 1

      This is key to enabling low-power functionality in Intel CPUs - think quick boot and quality testing. It doesn't have any surveillance or other purposes.

      None that you know of. The point of the article is that there has been no way to be sure about what's really in there and what isn't. The code appears to have been deliberately obfuscated by Intel at a hardware level. It's true that this subsystem is not new and has been known about for years, but I gather the point of the article is not to announce its existence, rather he wants to say that he has figured out some (but not all) of the subsystem's functionality that was previously hidden, and he wants to eventually replace the whole thing with open source equivalents so that people will know for certain that there are indeed no Three Letter Agency backdoors. I think. I really only skimmed the article.

    10. Re:Nefarious Headline for Practical Feature by skids · · Score: 4, Insightful

      I'm sure it can be used, just like the rest of the hardware "can be used."

      But these things in one form or another have been around for over two decades and everyone who has ever set up real server hardware from scratch knows they're there and their existence has never been a secret. (The closed-source code they run, on the other hand...) It's not even "news" that chipset manufacturers have started to integrate these systems directly into CPUs.

      The earliest one of these I remember was called iLOM on a Sun Systems but I'm sure they predate that. Just LOM and ILO are other names I've seen.

      Once desktops started to need active runtime heat management, many of them got a "systems management" co-processor that helped with thermal/power control.

      Personally I'd be just as worried about whatever firmware is running on the ethernet card these days... which is to say, not very, because there's not much to be done about it, unless you have the reason and time to invest in completely open hardware from top to bottom and the willingness to live within the limitations that might entail. So while I would normally suggest the mildly paranoid just not use the onboard ethernet ports, I can't say I really trust ethernet cards, either.

      Also since there are so many gaping holes just staring me in the face in commercial OSes when it comes to (software) VPN and WPA drivers, I figure it'll be a long, long time before I can get around to finessing things down to the metal, if ever.

    11. Re:Nefarious Headline for Practical Feature by guruevi · · Score: 1

      There are already many platforms (even some workstation/desktop class) that have IPMI or similar remote support. There are similar constructs in the "standard" ACPI (after all, Microsoft made it). If you could hack those chips, yes, you could run whatever you wanted on them and it's a real threat. This is not a feature that Intel is 'hiding', it's actually advertising the feature.

      --
      Custom electronics and digital signage for your business: www.evcircuits.com
    12. Re:Nefarious Headline for Practical Feature by bws111 · · Score: 1

      They have been around a lot longer than that. Mainframes have had 'service elements' and 'support processors' for at least 40 years. And those things can do a heck of a lot more than the Intel AMT stuff. Like alter/display ANY register or ANY storage.

    13. Re:Nefarious Headline for Practical Feature by ausekilis · · Score: 1

      Just wait for Facebook or Google to take advantage of it.

    14. Re:Nefarious Headline for Practical Feature by LynnwoodRooster · · Score: 1

      So all PCs use Intel processors? And all Intel processors made in the last 15 years have this feature?

      --
      Browsing at +1 - no ACs, I ignore their posts. So refreshing!
    15. Re:Nefarious Headline for Practical Feature by slew · · Score: 2, Funny

      On one hand, I think this whole thing is overblown. On the other hand, playing devil's advocate, the TLAs can't access a machine that is powered down; this potentially allows them to turn it on remotely.

      There are many levels of "powered-down". Many enterprise PC have had wake-on-lan and pxe-boot for a while. Often these are simply controlled via bios settings (which we know are completely secure against TLAs)...

      Quick shut the barn doors, the horses have escaped!

    16. Re:Nefarious Headline for Practical Feature by lgw · · Score: 1

      Everything has secondary processors, has forever. What's interesting is that this secondary processor has a TCP stack for remote management - an actual feature lots of people use. I don't know if AMDs are the same, but it wouldn't surprise me.

      --
      Socialism: a lie told by totalitarians and believed by fools.
    17. Re:Nefarious Headline for Practical Feature by BronsCon · · Score: 1

      This guy gets it.

      This whole story is about as non-story as it gets.

      --
      APK quotes people (including myself) without context and should not be trusted. Just thought you should know.
    18. Re:Nefarious Headline for Practical Feature by SeattleLawGuy · · Score: 1

      Why do that when you can just get the OS vendors to give you backdoors and control? That way you can access everyone, not just the few that have this extra hardware feature...

      Some three-letter agencies (US and foreign) have better access to (or can make less detectable modification of) hardware manufacture than to O/S code. Think how complicated the logistical operation would be to make sure you had a really secure computer.

      --
      Real lawyers write in C++
    19. Re:Nefarious Headline for Practical Feature by AmiMoJo · · Score: 1

      Just to put in perspective how much of a non story this is, since the late 90s Intel CPUs have allowed their microcode to be updated by the BIOS or the OS. The CPU itself can be reprogrammed in an undetectable way to betray you.

      So can a dozen or more other parts of the computer. Your hard drive/SSD is a prime target. We have seen proof of concept malware running on a GPU.

      --
      const int one = 65536; (Silvermoon, Texture.cs)
      SJW, n: "Someone I don't like, and by the way I'm a fuckwit" - AC
    20. Re:Nefarious Headline for Practical Feature by Anonymous Coward · · Score: 0

      Just try and power on my desktop remotely.
      The power cable is disconnected =D
      If they manage that, Nikola Tesla would be proud.

    21. Re:Nefarious Headline for Practical Feature by Anonymous Coward · · Score: 0

      No worries, comrade! That's what we have four letter agencies for.

    22. Re:Nefarious Headline for Practical Feature by swalve · · Score: 1

      No. http://www.tomshardware.com/re... Also, we've known about this for like a decade.

    23. Re:Nefarious Headline for Practical Feature by Anonymous Coward · · Score: 0

      This is key to enabling low-power functionality in Intel CPUs - think quick boot and quality testing. It doesn't have any surveillance or other purposes.

      Sure, and Intel virtually guarantees it isn't possible to exfiltrate any information from the system via the web management interface it runs on tcp/16992 because "trust us." That interface must be completely secure and unbreakable - even though it's not even HTTPS secured with even basic (insecure) SSL.

    24. Re:Nefarious Headline for Practical Feature by Anonymous Coward · · Score: 0

      "for a while"...

      Might be understating it a bit to describe 30 years as 'a while'!

    25. Re:Nefarious Headline for Practical Feature by Anonymous Coward · · Score: 0

      Why, then is there a 3G interface for sais hidden ARM proc. in the last -at least 5 years Intel chips? Fun?

    26. Re:Nefarious Headline for Practical Feature by fph+il+quozientatore · · Score: 1

      All Intel processors made in the last 10 years have it: https://libreboot.org/faq/#int... All AMD processors made in the last 3 years have it: https://libreboot.org/faq/#amd I am not sure about ARMs, but they also have something called "security engine", and I can find very little info about them on the internet.

      --
      My first program:

      Hell Segmentation fault

    27. Re:Nefarious Headline for Practical Feature by Anonymous Coward · · Score: 0

      Why do that when you can just get the OS vendors to give you backdoors and control?

      And where exactly are these backdoors? These baseless claims date back two decades and in those two decades all these people claiming these backdoors exist still can't seem to be able to find them, we even had 2 Windows source code leaks and the backdoor crew still failed to find any proof.

      Then we see all this uproar about Windows 10 telemetry and that this is some spying mechanism, well why the fuck would they need that if they had the backdoors you have been telling us existed that you couldnt ever find any proof of?! The new evil is "telemetry", of course based on the track record of the people here that will turn out to be just telemetry and nothing more.

    28. Re:Nefarious Headline for Practical Feature by Anonymous Coward · · Score: 0

      "It's ok if I shoot you in the head, because I've allready cut off your arms"

      Arguments that Might work with cunts and cunt like men.

  3. This isn't New by Anonymous Coward · · Score: 1

    PCs have been shipping with IME for several years now. Has this person been living under a rock?

    1. Re:This isn't New by rickb928 · · Score: 1

      Agreed, I had been using IME for long time. This is not new. In fact, it's so old I expect that if it were compromised, those exploits are in their 3rd generation by now. The one where sovereign hackers usurp the previously installed tools and the fight is for the C&C net.

      And I suspect it has been tried, repeatedly. By everyone of note.

      --
      deleting the extra space after periods so i can stay relevant, yeah.
    2. Re:This isn't New by GameboyRMH · · Score: 1, Interesting

      I'd be surprised if the spooks don't have an exploit for it for targeted use, but as you point out, nothing has been found in the wild for all these years, so the cost/benefit is obviously not good enough for your average blackhat. Software-only APTs are good enough and don't rely on proprietary hardware features.

      There was a conspiracy theory going around when it was new that the IME included a GSM modem (and presumably a hidden SIM card tied to a subscription paid for by the Illuminati) and could be used for out-of-band remote control of your computer.

      --
      "When information is power, privacy is freedom" - Jah-Wren Ryel
    3. Re:This isn't New by Rockoon · · Score: 1

      PCs have been shipping with IME for several years now. Has this person been living under a rock?

      ..and its still not audited. Have you been living under a rock?

      --
      "His name was James Damore."
    4. Re:This isn't New by Anonymous Coward · · Score: 0

      Every week I read of malwares that have been in use several years and were revealed lately. Every week I read of OS flaws allowing root access, and were revealed lately. How do you know Intel, Google, NSA or aliens (Barry) have not been using IME or similiar without detection?
      Can you even point to a way to detect legitimate remote IME operation in your computer?

    5. Re:This isn't New by Anonymous Coward · · Score: 0

      If this would have been compromised it would most likely be the most sought after exploit in the world, and if it where to be come known to the world the possible price for it would drop like a stone...

      I could see most governments pay upwards of $100M for it as long as it's kept secret, and for that money i could see that many people would keep very quiet about it..

      So unless there was an ethical cracker that figured out a exploit i would suspect that any information about it would be kept really quiet and only known to a very small group and used by a few limited, highly trusted, persons.

  4. Don't Blame Me by T.E.D. · · Score: 1

    ...I voted AMD.

    1. Re:Don't Blame Me by CajunArson · · Score: 1

      Don't worry, they have their own cloned version of the same thing.

      Incidentally, most ARM smartphone chips also include similar functionality, but apparently it's only a big deal when a desktop PC has "OMG NSA" parts and not the audio/video recording device with wireless tracking capabilities that the same paranoid idiots carry around with them everywhere they go.

      --
      AntiFA: An abbreviation for Anti First Amendment.
    2. Re:Don't Blame Me by Anonymous Coward · · Score: 0

      well i bought intel so i guess its my fault, sorry everyone
      sorry

      so sorry,

    3. Re:Don't Blame Me by Yvan256 · · Score: 1

      I voted VIA.

    4. Re:Don't Blame Me by Anonymous Coward · · Score: 0

      you mean I should not be jerking off when my phone is around?
      that is a serious change in a lifestyle...

    5. Re:Don't Blame Me by Anonymous Coward · · Score: 0

      6502 here. And yes, they work fine for surfing the internet. Turn off pictures.

    6. Re:Don't Blame Me by Yvan256 · · Score: 1

      Also turn off Javascript.

      And CSS.

    7. Re:Don't Blame Me by Narcocide · · Score: 1

      You're forgiven, but just this once.

  5. No need to verify story by ranton · · Score: 4, Informative

    Editor's note: The summary is written with inputs from an anonymous reader, who also shared the story. We've been unable to verify the claims made by the author.

    Everyone is used to getting their news from social media anyway, so why bother verifying the claims before posting it as news?

    --
    -- All that is necessary for the triumph of evil is that good men do nothing. -- Edmund Burke
    1. Re:No need to verify story by ceoyoyo · · Score: 1

      This is a discussion site not the New York Times. It's perfectly acceptable to post a rumor or unverified claim. It's good that they identified it as such... usually the Slashdot editor just clicks publish on whatever swill caught his eye in the submissions.

    2. Re:No need to verify story by thegarbz · · Score: 4, Informative

      Editor's note: The summary is written with inputs from an anonymous reader, who also shared the story. We've been unable to verify the claims made by the author.

      Everyone is used to getting their news from social media anyway, so why bother verifying the claims before posting it as news?

      I'd like to go the other way, why are we adding an "unverified" disclaimer to something that has been known about for many years? Intel aren't hiding anything. The existence of this miraculous CPU is documented on their website and it's function is accessible using their provided tools. Heck AMD do it too they just happen to call it PSP instead of IME. The only thing they are hiding is what's in their firmware which everyone has done for a long long time.

    3. Re:No need to verify story by Anonymous Coward · · Score: 0

      I agree mate, this is an incredibly low-quality non-news story about a well-known remote monitoring platform which has been around for a decade or so.

      Go back to Gawker, son, you're embarrassing yourself.

  6. Comment removed by account_deleted · · Score: 1

    Comment removed based on user account deletion

  7. Old news by psergiu · · Score: 5, Informative

    https://libreboot.org/faq/#int...

    https://libreboot.org/faq/#amd

    Both Intel and AMD had this for years - read above links ...

    --
    1% APY, No fees, Online Bank https://captl1.co/2uIErYq Don't let your $$$ sit in a no-interest acct.
    1. Re:Old news by Anonymous Coward · · Score: 0

      From your Intel link:

      The ME [Intel Management Engine] also has network access with its own MAC address through an Intel Gigabit Ethernet Controller.

      How would I not notice this in my router or edge device logs?

    2. Re: Old news by Anonymous Coward · · Score: 0

      Because it only listens for "magic packets" that wake up and shut down a remote system. With laptops that have a 3G/4G mobile network option, Intel allows the use of a kill/reactivate command that comes along as a SMS message. They would want to keep this secret.

    3. Re:Old news by dissy · · Score: 4, Informative

      The ME [Intel Management Engine] also has network access with its own MAC address through an Intel Gigabit Ethernet Controller.

      How would I not notice this in my router or edge device logs?

      Mainly only by not looking.

      That may sound stupid at first glance, but the fact Intel AMT articles keep popping up a decade later written as some form of surprise that the feature exists seems to prove most people don't bother looking.

      ME/AMT utilizes HTTPS by default on port 16993, can support HTTP by default on port 16992, and VNC protocol on I believe it's default port (I've never had to specify an alternate port in the VNC client to connect)

      Also of note is that older ME versions don't let you upload your own SSL certificate for HTTPS, and although I may be wrong but I'm fairly sure VNC by default is not encrypted either.

      This means someone in your posistion of control over the core and edge network would both see this traffic if looking, and potentially be able to setup a MITM to obtain the ME/AMT login credentials fairly easily depending on your desktop admins setup.

      Normally LAN to LAN traffic over a proper switched network is relatively safe, seeing that an ARP storm to a switch for redirecting LAN traffic would ALSO be noticed by you the network admin, and ideally has been proactively prevented as well.

      For desktop admins and/or network admins without this knowledge or skill however, if the LAN doesn't prevent or log/notify about such things, ideally the ME/AMT hasn't been enabled either.

      Only those with a tiny amount of knowledge (just enough to be dangerous) are likely to shoot themselves in the foot with a horribly insecure setup.

    4. Re:Old news by meadow · · Score: 1

      reading the first link it says:

      ... it has a network interface that is demonstrably insecure ...

      Obviously no one is going to expose an AMT port through a firewall without taking precautions. That article sounds a little disingenuous to me as though they deliberately want to slam AMT technology.

      I've always looked at AMT as a sort of built in Cyclades serial console server and the main feature I actually like about it is in fact the Serial Over LAN (SOL) feature. Every technology has risks but I think that this article might be deliberately alarmist.

    5. Re:Old news by mrchaotica · · Score: 1

      Somebody needs to hack Intel and AMD and release their private keys and source code.

      --

      "[Regarding the 'cloud,'] ownership was what made America different than Russia." -- Woz

    6. Re:Old news by Anonymous Coward · · Score: 0

      you have to give it an ip first, afaik it won't use dhcp

    7. Re:Old news by meadow · · Score: 1

      The other thing is that you actually want and need to set a static address for the AMT interface for obvious reasons: If you use either Manageability Commander Tool or the web interface, you need to know where to connect to. It won't even let you activate the interface without setting a secure password (strong password policy is enforced and cannot be bypassed).

      On my home systems I don't expose the AMT interface to the outside via my router, but if I were at a company I would have a special, secure log-in machine to access from outside to which the AMT systems would be exposed internally.

    8. Re:Old news by Anonymous Coward · · Score: 0

      Heh, they don't have access to their private keys either. Nobody has. What they do have is access to the HSM that has the private keys. One would have to either steal that thing, or manage to get enough unauthorized access to it to sign trojaned microcode/ME firmware... but it would be an one-time thing. Use it, and it gets discovered and revoked.

      Although it is *possible* that the TPM functions required by the microcode itself to revoke SGX and TXT credentials is implemented by the ME, and in that case, well, Intel screwed up big time. This is not anywhere close to likely, it is the kind of primary mistake they do NOT make (these guys had constant-time, constant power-draw AES+RSA implemented in microcode for the microcode update loader since at least the Core 2...).

    9. Re:Old news by skids · · Score: 1

      Normally LAN to LAN traffic over a proper switched network is relatively safe, seeing that an ARP storm to a switch for redirecting LAN traffic would ALSO be noticed by you the network admin, and ideally has been proactively prevented as well.

      Storms maybe, but just try to secure a server core where the systems guys want to just keep moving VMs from hypervisor to hypervisor from even just plain old arp spoofing, and I'll see you a year or so later crawling out of the dot1Qaw rabbit hole looking for a career change to something that involves staring calmly at growing plant life.

    10. Re:Old news by Anonymous Coward · · Score: 0

      dot1Qaw?

    11. Re:Old news by Anonymous Coward · · Score: 0

      > systems guys want to just keep moving VMs from hypervisor to hypervisor

      This is literally how a properly designed cluster for virtual servers will function. The "systems guys" don't want to keep moving vms around, thats quite literally one of the main functions, features, and benefits of virtualization.

    12. Re:Old news by skids · · Score: 1

      Sure, but it totally does not make life easy for network security, let me tell you.

    13. Re:Old news by skids · · Score: 1

      Sorry, cut-pasto, dot1Qbg. Though my understanding is a lot of places these days throw that in the trash and just fire up a bunch of GRE tunnels.

    14. Re:Old news by Anonymous Coward · · Score: 0

      Easy workaround: Install your own NIC in these systems and don't use the onboard one.

  8. Yawn by Simon+Rowe · · Score: 1

    Looks to be a regurgitation of Joanna's paper http://blog.invisiblethings.or...

  9. Problem for coreboot by Anonymous Coward · · Score: 0

    That's a major problem for projects like libreboot/coreboot

    https://libreboot.org/faq/#int...
    https://libreboot.org/faq/#amd

  10. What the fuck? by 110010001000 · · Score: 3, Insightful

    This has been known for years and is present on Intel and AMD. What year is this?

    1. Re:What the fuck? by Yvan256 · · Score: 1

      And we're safe anyway. It's really easy to know what's dangerous or not on the Internet since the creation of the evil bit.

  11. "Trusted" by Fwipp · · Score: 5, Insightful

    From the article:

    We have no physical separation between the components that we can trust and the untrusted ME components, so we can't even cut them off the mainboard anymore.

    Why do you trust the main CPU, if you don't trust the ME chip?

    1. Re:"Trusted" by Anonymous Coward · · Score: 0

      I guess it's because "nobody is allowed to audit or examine" the separate chip.

    2. Re:"Trusted" by Anonymous Coward · · Score: 0

      Except the NSA. Secret keys are secret.

    3. Re:"Trusted" by Anonymous Coward · · Score: 0

      Because he's an idiot.

      Furthermore, you SIMPLY CANNOT TRUST *BILLIONS* of transistors in a chip manufactured by one of the MOST SECRET companies on the planet, designed no less by well known USA NSA SPY COMPATRIOT *HAIFA ISRAEL*.

      Publish the full chip design from block design all the way down to the masks,
      AND let us inspect and monitor all aspects of the chip fabrication plant during the production run,
      THEN and ONLY THEN, will we begin to consider using the word TRUST in association with a product.

    4. Re:"Trusted" by ras · · Score: 1

      Why do you trust the main CPU, if you don't trust the ME chip?

      Because hardware designers making the odd mistake is just normal. I've spent a fair portion of my life papering over their mistakes, always successfully. But to fuck things up beyond redemption; that requires a computer programmer - just ask the patients treated by Therac 25.

    5. Re:"Trusted" by The+Finn · · Score: 1

      Just like RMS has with his Loongson laptop, right?

      --
      NetBSD: the cathedral vs the bizzare.
    6. Re:"Trusted" by Anonymous Coward · · Score: 0

      For the same reason why we don't trust RDRAND, even though we trust the rest of the CPU it came with: that one particular component has an evil bit set, so it's evil.

  12. This was mentioned a long time ago by dayton967 · · Score: 1

    This was mentioned along time ago with the VPro Chips having a cellular modem built in.
    https://www.popularresistance....

    1. Re: This was mentioned a long time ago by Anonymous Coward · · Score: 0

      Never found any supporting evidence of a 3g modem in the chip.

      Per Intel it requires a separate 3g modem.

      âNotification via an encrypted SMS text message
      over a 3G network. For this option, the laptop does
      not need to be connected to the Internet, but it
      must be within range of a 3G network. This feature
      works even if the OS is not running or has been re-
      installed, thanks to a hardware-to-hardware link
      between the 3G card and the Intel AT system.

  13. Really slasdot? by Anonymous Coward · · Score: 0

    Editor's note: The summary is written with inputs from an anonymous reader, who also shared the story. We've been unable to verify the claims made by the author.

    editors, please give in your geek card.

    This is not news. Intel has had this system since 2006. AMD since 2013.

    Talking about it is important. But "we need to verify it?" even *AFTER* posting links to wikipedia?
    Even the libreboot page has been linked here multiple times:

    https://libreboot.org/faq/#intel

  14. Out of band management by kimvette · · Score: 1

    This is for out of band management so devices can be monitored and restarted remotely (think: enterprise environments). Nothing to get wrinkles in your tin hat over. :)

    --
    The Christian Right is Neither (Christian nor right). See: Matthew 23, Matthew 25, Ezekiel 16:48-50
    1. Re:Out of band management by Carewolf · · Score: 1

      This is for out of band management so devices can be monitored and restarted remotely (think: enterprise environments). Nothing to get wrinkles in your tin hat over. :)

      Yes, it is only for monitoring and controlling your computer remotely. Nothing to see here, nothing to worry about, move along please..

  15. NO! by Anonymous Coward · · Score: 0

    Now that is just one step too far - a remote management CPU just for WinTel to exploit at first, then the FBI/CIA/NSA...
    then the hackers and crackers and wackers....
    NO MORE! My machine, my rules!

  16. Dude, really? by Anonymous Coward · · Score: 0

    John McAfee was making the Alex Jones circuit rounds with this story over a YEAR ago.

    FFS. It supports 3G access too, provided the computer has a 3G modem for that purpose. Surprised they didn't throw that in as "Secret 3G chip exposes all intel CPU's to rootkit hack!"

    Please don't run anonymously contributed unverified stories. This isn't reddit.

  17. Where did I put that rant again? by Anonymous Coward · · Score: 0

    Oh right, here it is.

    We even had an article about just this thing earlier this year, too.

  18. Illegal? by DoofusOfDeath · · Score: 1

    If it's really there and Intel has hidden it, I wonder if they could be successfully prosecuted for conspiracy to commit unauthorized computer access.

    1. Re:Illegal? by Richard_at_work · · Score: 1

      Only if you can prove they are using it without your authorisation. It simply existing is not enough.

    2. Re: Illegal? by Anonymous Coward · · Score: 0

      You can read Intel's own literature for vPro . It's for laptops that have a built in 3G/4G modem option .

    3. Re:Illegal? by DoofusOfDeath · · Score: 1

      Only if you can prove they are using it without your authorisation. It simply existing is not enough.

      IANAL, but I wonder if "Conspiracy with intent to ..." would be a crime in this case.

    4. Re:Illegal? by Anonymous Coward · · Score: 0

      It isn't hidden, dumbass.

    5. Re:Illegal? by Richard_at_work · · Score: 1

      Prove the conspiracy, and prove the intent - Intel has a huge amount of resources setup around this for enterprise systems management, so you have a massive uphill (almost a vertical cliff one might say) battle to climb in order to prove any malicious intent here.

      Just because you dont like it, doesnt mean anything illegal is being done.

    6. Re:Illegal? by DoofusOfDeath · · Score: 1

      Just because you dont like it, doesnt mean anything illegal is being done.

      I agree entirely. My questions were premised on the assumption that Intel was being sneaky about the existence of this mechanism. I'm new to this topic, so I really don't know if that premise holds.

    7. Re:Illegal? by Anonymous Coward · · Score: 0

      I don't think the authors incompetence at reading publically posted information about the feature would qualify as Intel "hiding" it.

    8. Re:Illegal? by Anonymous Coward · · Score: 0

      Nope, mens rea isn't required to prove conspiracy, so you clearly don't know what you're talking about.

    9. Re:Illegal? by Richard_at_work · · Score: 1

      But you still have to prove conspiracy - who did they conspire with and where is the evidence that they conspired together on this? Mens Rea wasn't even in my mind.

      Now who clearly doesn't know what they are talking about?

    10. Re:Illegal? by Anonymous Coward · · Score: 0

      Have you not realized that you don't own your devices anymore but only license them?

      They most likely have a clause in the EULA that would permit them to do whatever they want...

    11. Re:Illegal? by Anonymous Coward · · Score: 0

      >who did they conspire with
      The good women of the government.
      And the men who support them.

      >and where is the evidence that they conspired together on this? Mens Rea wasn't even in my mind.
      All around you.

  19. Here's the thing by H3lldr0p · · Score: 3, Insightful

    I don't like the idea of a computer inside my computer I don't have any control over.

    I find the article a little on the high side of paranoia, however. Yes, it is possible to have unnamed people from unnamed places get in and get data from your system. The article does go out of it's way to point out that this isn't very likely. The firmware running the second CPU is heavily encrypted and hash-checked at runtime. Making it unlikely to be broken until the heat-death of the universe or we finally figure out the P=NP thing.

    Conversely, I'd like to know what's going on under the cover Intel. If this is in the stuff I bought, I figure I have a legal right to be able to access it and run an audit on it. Without having to go through you. Conflict of interest and right of first sale and a few more things spring to mind as to why that's not a something I'd want to do.

    1. Re:Here's the thing by Obfuscant · · Score: 3, Interesting

      I don't like the idea of a computer inside my computer I don't have any control over.

      Then you are destined for a life of unhappiness. Most of the I/O processing in your "computer" is done by dedicated computers that you have no control over. The video card, the network card, the IEEE1394 or USB.b The disk drives. Even the audio. Things that have DMA so they an access memory without the CPU knowing about it...

      You may look at the device and see a part number that you can look up, but dollars to donuts that the part is programmable in some way that makes it be what it is. FPGA, perhaps. Or just a microprocessor with firmware in EEPROM.

      I figure I have a legal right to be able to access it and run an audit on it.

      If they make it so you can "audit" it (whatever that means) then they've made it accessible to bad guys, too.

      Conflict of interest and right of first sale and a few more things spring to mind as to why that's not a something I'd want to do.

      How do you imagine that this "unauditable" CPU is hindering you from reselling the computer? I'm really fascinated to hear the reasoning behind that.

    2. Re:Here's the thing by Anonymous Coward · · Score: 0

      I don't like the idea of a computer inside my computer I don't have any control over.

      Then you are destined for a life of unhappiness. Most of the I/O processing in your "computer" is done by dedicated computers that you have no control over. The video card, the network card, the IEEE1394 or USB.b The disk drives. Even the audio. Things that have DMA so they an access memory without the CPU knowing about it...

      You may look at the device and see a part number that you can look up, but dollars to donuts that the part is programmable in some way that makes it be what it is. FPGA, perhaps. Or just a microprocessor with firmware in EEPROM.

      I figure I have a legal right to be able to access it and run an audit on it.

      If they make it so you can "audit" it (whatever that means) then they've made it accessible to bad guys, too.

      Conflict of interest and right of first sale and a few more things spring to mind as to why that's not a something I'd want to do.

      How do you imagine that this "unauditable" CPU is hindering you from reselling the computer? I'm really fascinated to hear the reasoning behind that.

      FPGA's are curious in this topic also, quite a few of re-implementations of popular computer systems also use lightweight processing cores for IO.

      I think it also leads to people in the free community complaining about 'firmware blobs', which I think is somewhat stupid. For modern systems if these blobs aren't required to be uploaded for operation they're stored in flash, or theoretically in mask rom ... does anyone still use mask rom?

      Primarily I worry about code that operates directly in the primary cpu domain as it has the most extensive and simplest access to the whole system - and the most problematic blob - the bios.

    3. Re:Here's the thing by Anonymous Coward · · Score: 0

      YO DAWG

      I heard you liked to compute

    4. Re:Here's the thing by Nemyst · · Score: 1

      Why are you assuming you have control over your current computer? Your CPU/GPU/whatever isn't any more open than that "CPU in a CPU". Your motherboard isn't open either. There's absolutely no reason why you'd trust one but not the other, considering they come from the same designer and the same fabs.

    5. Re:Here's the thing by Anonymous Coward · · Score: 0

      Why would people try and attack the hash algorithm? They'd attack the code running on the device. Very encrypted systems get rooted on the regular; it's hard, but not "heat death" hard.

      Mind you it might be that this is the rare embedded chip that has no flaws whatsoever, but what are the odds?

    6. Re:Here's the thing by Anonymous Coward · · Score: 0

      i've heard things as far-off as there's a 3g type data radio in every mainstream intel processor the last 10 or so years.

      the IME however, is real, the extra out of band processor core does exist, and only intel (and the feds) know exactly what ALL it is capable of.

      the fact is.. there IS something there... it DOES run independent of your own software, you have NO control over it.. well, part of it anyway, when you disable computrace in bios you deactivate **part** of its function.. but the rest will live on forever.

    7. Re:Here's the thing by Anonymous Coward · · Score: 0

      In actuality these things are problems depending on what you are doing. In the DoD we have found numerous problems with firmware and closed source microcode (and FPGA's in general--particularly the one without fusible links or where the links haven't been burned in) in electronics both from a bugs and a security perspective. Some have come from foreign sourced parts being introduced after a given amount of time in production--other come from COTS parts used to keep cost down since day 1. Some of these electronic bits have purposely compromised firmware or hidden circuits (state actors)--part of why personal USB items have been massively locked down in the last 3 years. Looking at the software alone reveals nothing.

      In this sense both the P and GP have a point. The P should be worried, but as the GP hints at the specific items in the article are not (for the layman) the things you should be worried about at this time. There are many more things that have DMA and can do just as much damage. That being said, GP should be a little more weary when going with a company based in a security questionable country (like Lenovo or Check Point) over Dell / HP / someone who doesn't make the larger items . Yes, the smaller parts from reputable companies could still be compromised as they still come from places like China, but buying the large items gives many more ways for a compromise to be stealthily integrated into the system.

    8. Re:Here's the thing by The+Finn · · Score: 1

      Of course mask ROM (or its modern equivalent) is still used. All the embedded microcontrollers in CPUs, chipsets, and IO controllers at least have bootloaders if not default firmware.

      --
      NetBSD: the cathedral vs the bizzare.
  20. Love and use AMT by meadow · · Score: 4, Interesting

    I love AMT. AMT is definitely one feature of the Dell Optiplex small form-factor systems that I like to use for my headless home servers. Its like having a built-in Cyclades serial console server. For running headless systems its almost essential.

    The only thing I don't like about it is that you need to have Windows installed to be able to update it as part of the updates released by Dell.

    1. Re: Love and use AMT by ArmoredDragon · · Score: 5, Informative

      I use AMT a lot as well, and have for years. My main question here is: How the fuck is this even remotely news material? Furthermore, why is it presented as some sort of conspiracy? Intel advertises this as a feature and never made any attempt to hide it. AMT is also off by default, by the way.

      The only Intel feature I'm at all concerned about is SGX, which by design can't be audited, and has nothing to do with anything mentioned in TFS.

    2. Re: Love and use AMT by meadow · · Score: 1

      I use AMT a lot as well, and have for years. My main question here is: How the fuck is this even remotely news material? Furthermore, why is it presented as some sort of conspiracy? Intel advertises this as a feature and never made any attempt to hide it. AMT is also off by default, by the way.

      The only Intel feature I'm at all concerned about is SGX, which by design can't be audited, and has nothing to do with anything mentioned in TFS.

      I agree. Seems like shitty "news" curating on the part of /.

    3. Re: Love and use AMT by meadow · · Score: 2

      Maybe the next /. story will be how all mobile devices have a secret, hidden OS called the bootloader that can be compromised by three-letter agencies...

    4. Re: Love and use AMT by Anonymous Coward · · Score: 0

      I've got one of those AMT, but it only shoots .22 shorts.

      Good thing Intel cant shoot back.

    5. Re: Love and use AMT by dfsmith · · Score: 2

      Did you know that some doors—maybe even your door—can be opened by using a MASTER KEY! This, and other secret conspiracies, at 11...

    6. Re: Love and use AMT by Anonymous Coward · · Score: 0

      Not just that... Nearly all doors can be opened by something that's illegal to carry in some states, illegal to own without a license in some areas, and difficult to acquire in others. Mere possession of them can lead to criminal charges in some areas.

      Even worse, some doors can be opened with things that people wear on their feet.

  21. Nefarious Uses for a Stupid Implementation by Anonymous Coward · · Score: 0

    There are better ways of doing this than a black box with such power and no possible over-site from the OS or user, even BIOS is usually better, which is saying something!

  22. true by dissy · · Score: 5, Informative

    Editor's note: The summary is written with inputs from an anonymous reader, who also shared the story. We've been unable to verify the claims made by the author.

    Uh, the claims are quite true. I've been using these features at work for about a decade to perform remote OS installs and HD re-imaging at remote locations, where the on-site staff only pop in a new blank HD.

    All Core i7 CPUs have this in them standard, and many i5's too especially at the higher end.

    [PDF] Datasheet on the MEBX management engine:
    http://download.intel.com/supp...

    [PDF] How to enable and use the AMT active management engine:
    http://www.intel.com/content/d...

    And here is the SCS software used on another computer to control an AMT enabled computer:
    http://www.intel.com/content/w...

    RealVNC works with an AMT enabled computer out of the box too and with all the normal features you would expect like remote keyboard/video/mouse control, redirected drives, etc. But isn't a free program.

    Other VNC clients seem to be hit or miss but even when they work you only get remote KVM, you'd have to use the built-in AMT web server to configure drive redirection and issue power on/off/reboot commands.
    There is a similarly limited VNC client included in the SCS software link above, and a second web browser window will let you do the rest, even if slightly clunky, but still for free.

    1. Re:true by sinij · · Score: 1

      If AMT is enabled by default, why don't we see widespread compromises?

    2. Re:true by dissy · · Score: 5, Informative

      Because it is not enabled by default.

      You need to know how to get to the configuration menu, then enable the engine, then assign it a method to access the network (either static IP on a unique MAC, or to piggyback on the host OS's MAC), and set a password.

      Only then are the ports opened for the HTTPS interface on port 16993 to continue the rest of the setup or use AMT.

      On boot (where you normally can hit Delete or a function key to enter bios setup), hold down control-p to get to the ME setup menu.
      Assuming you aren't at work or something and using your own computer, you'll see it is disabled.

    3. Re:true by kheldan · · Score: 3, Informative

      This is all true. You can disable the ME coprocessor in BIOS settings. You also aren't required to install the ME driver in your (Windows) OS in order for Windows to function.

      Could the ME coprocessor/firmware be compromised by an attacker? Maybe. But it can all be disabled. It's firmware could also be hacked out of the BIOS entirely without compromising the operation of the rest of the system.

      The ME is mainly for remote administration/management of corporate systems. It allows access to the machine remotely even in the event of a hardware failure, like the HDD failing completely. It can bring the system out of a completely powered-off state, so long as the box is still connected to the mains and the switch in the back is still 'on'. But so far as I know it's not necessary for the rest of the computer to operate.

      --
      Are YOU using the TOOL, or is the TOOL using YOU? Think about it!
    4. Re:true by rahvin112 · · Score: 1

      You forgot the part where you write Intel a big fat check to use the feature. Intel charges big bucks for vPro software and these features are part of vPro and you can't enable them without the vPro software. IIRC it's all tied to a digital signature that Intel controls and you can't even look at it without giving Intel money.

      Intel is making a pretty chunk of change on their enterprise management software that uses features built into their CPU's which are normally disabled. Intel is going to keep building more and more enterprise big brother abilities into their hardware and charging big money for the software to use it. It's proved a rather lucrative addition to their hardware business.

    5. Re:true by hyades1 · · Score: 1

      A cynic might suggest that their self-proclaimed inability to verify the claims of the author is a pretty bold statement about their level of competence.

      --
      I've calculated my velocity with such exquisite precision that I have no idea where I am.
    6. Re:true by dissy · · Score: 4, Informative

      You forgot the part where you write Intel a big fat check to use the feature. Intel charges big bucks for vPro software and these features are part of vPro and you can't enable them without the vPro software. IIRC it's all tied to a digital signature that Intel controls and you can't even look at it without giving Intel money.

      I didn't forget it, because that isn't true.

      The control software is free. I didn't pay for my web browser, VNC client, or the intel SCS client (I even have you the download link)

      The firmware is already included in any vPro CPU, you turn it on by holding control-p at boot.

      I've even played with this feature at home on my own hardware before deploying it at work. Other than having purchased the computer/CPU, there is no further cost.

      I'm not sure where you got your information from but it is certainly incorrect.

    7. Re:true by AbRASiON · · Score: 1

      With RealVNC - can I remote into a machine which is still at the bios / boot stage?

    8. Re:true by dissy · · Score: 4, Informative

      With RealVNC - can I remote into a machine which is still at the bios / boot stage?

      Yup, AMT can provide remote access when the system is in any of its sleep states from s0 (fully on) down to s5 (powered off), so long as the system is plugged in and has power available.

      You will see the whole BIOS bootup sequence, including seeing and able to send the usual interrupt keys like del or F9 or whatever to get to BIOS setup.

      I've had some older HP workstations be a little funky between the BIOS setup and the OS taking using the GPU. Generally I'll see a screen flash and get disconnected, after which VNC reconnects immediately and all is well again.
      Newer HPs we have haven't done this that I recall, nor have the Dells or my home built franken-pc so guessing it's a fixed bug with older AMT versions?

      In fact one of the main purposes of ME is to change the power state, meaning you can turn the main system on or off or reboot it just from there.

      That's how I re-image a remote system after a hard drive failure.

      I have someone on-site power off the system and replace the hard drive with a new one, then let me know.
      I then connect to the remote system via ME/AMT and setup a dvd-rom redirect to an ISO image on my PC, start the AMT VNC server and connect to it from my PC, lock the remote systems keyboard so anyone local can't over-type me, and then instruct the remote system to power on.

      Then during boot if the remote system gets stupid and tries to boot from the new blank HD and stops, I can issue a reboot command and use the F11 boot menu from the BIOS to point it to the DVD drive. Usually that part just works though (like I said, all related to the older HPs)

      Once the linux image boots and runs clonezilla, it's just an [enter]-[yes]-[yes] away from writing the backup image back to the new HD.

      You can of course point to an OS install media instead and do that manually, I just tend to try and avoid that for installers using a mouse, since over remote links that can suck pretty bad. Over LAN it seems nice and responsive however.

      Once done I do a normal "shutdown -h now", disable the DVD drive redirect, and power the system back on. Once I see the windows loading screen I'll disconnect VNC and shut down the VNC server in the AMT, and logout of the https interface.

      Since I let AMT piggyback on the host MAC and IP, it basically intercepts any tcp ports it is using instead of passing that info up the stack to the OS.
      I don't leave VNC running in the AMT just in case the host OS needs to run a VNC server on the default port for any reason - plus nothing good can really come from leaving it running when not needed.

      ME uses https over port 16993, which isn't likely to be used on the OS (or if so, too bad for that app I guess)
      If you already have RealVNC and a Core i7 at home to play with, boot the i7 and hit control-p where you normally would hit delete or a function key, and you'll be in the ME setup menu.
      You can enable both ME and AMT (they are separate sub-systems) and play around.

    9. Re:true by Anonymous Coward · · Score: 0

      You can disable access to the coprocessor, but not stop it from running, which it always does even if "disabled". Also, not installing the driver in Windows has nothing to do with it running on the separate CPU anyway.

    10. Re: true by Anonymous Coward · · Score: 0

      Well the official VNC client is $corporate per seat but as you say there are free (and open source) alternatives.

  23. We have technology to validate such claims. by jellomizer · · Score: 2

    Place the PC in a faraday cage. Record any radio transmission that is large enough to cross distance.
    Have a PC (lets go with Non-Intel) hooked up and set up to be a point to point network connection. Monitor all traffic being sent from the PC.
    Put barebones (say really old version of Linux on it)

    If something is unexpected then we have a theory to work on. Otherwise is is just some nut trying to get us to use AMD or something.

    --
    If something is so important that you feel the need to post it on the internet... It probably isn't that important.
    1. Re:We have technology to validate such claims. by Anonymous Coward · · Score: 0

      Or you can read the documentation. These aren't hidden features. They're IT admin features to make remote deployment and control of PCs and servers easier. It's all documented and has existed for years. There's nothing new here, only people looking at an industry they clearly don't understand and saying "hey I never knew that before" despite it being listed as a feature when you look at the tech specs. It'd be like me saying gun manufactures were trying to control when I can shoot or not after I randomly discover my gun has a trigger lock switch on it.

      This "hidden computer" is there so you can remotely configure BIOS settings and press F1 and/or enter disk encryption passwords before the computer boots into an operating system. Without it, the admin would have to manually configure every computer onsite. Automation is a good thing. The features can be disabled and if you don't trust that you can block them at the firewall. If you can't trust that, write your own IDS rules and if you're still concerned, you're either an admin for classified info or aren't mature enough to handle networked computers.

    2. Re:We have technology to validate such claims. by Anonymous Coward · · Score: 0

      No vulnerability is a problem until it is exploited.
      By your reasoning, you could put a fresh install of Windows XP in a faraday cage, and if you don't see it get hacked, call it a secure system.

      "When these are eventually compromised" --- this is the part that's important. Passive monitoring might demonstrate a problem, but it can't demonstrate invulnerability.

    3. Re:We have technology to validate such claims. by thegarbz · · Score: 1

      Easier answer, just read Intel's documentation. It's all there. It's no great secret. It's a remote admin tool and is documented as such.

      As for AMD, their only thing special about them is they are using a different acronym "PSP" for their version of pretty much the same thing. If you're paranoid the only thing you can use is a pre 2012 AMD chip or a pre 2009 Intel chip.

    4. Re:We have technology to validate such claims. by jellomizer · · Score: 1

      Umm no.
      You put Windows XP and hook it up to a private network and see what sort of internet requests it is trying to contact and what ports it has open on the system.
      The issue with a "Hidden CPU" in the CPU would be that it would be listening for a connection or communicating out.
      Being that software isn't written to interact with a "Hidden CPU" there isn't much software vulnerability going on unless there is a way to communicate out.

      --
      If something is so important that you feel the need to post it on the internet... It probably isn't that important.
    5. Re:We have technology to validate such claims. by trek00 · · Score: 1

      This method would not discover a dlink-like backdoor, a backdoor that needs to be activated with a specific procedure and do nothing in other cases.

    6. Re:We have technology to validate such claims. by Anonymous Coward · · Score: 0

      Place the PC in a faraday cage. Record any radio transmission that is large enough to cross distance.
      Have a PC (lets go with Non-Intel) hooked up and set up to be a point to point network connection. Monitor all traffic being sent from the PC.
      Put barebones (say really old version of Linux on it)

      If something is unexpected then we have a theory to work on. Otherwise is is just some nut trying to get us to use AMD or something.

      Yeah.. It likely only sends out when it receives a specially coded request from something like a black van parked outside your residence. As such you could do your little experiment for years and never see anything and yet the conclusion you'd come to, the one you want to come to, would be completely wrong.

    7. Re:We have technology to validate such claims. by Anonymous Coward · · Score: 0

      > If you're paranoid the only thing you can use is a pre 2012 AMD chip or a pre 2009 Intel chip.

      Smugly Backing us into a corner.

      FUCK YOU.

      Pro-women's rights piece of shit techie faggot.

  24. Yawn, by Obfuscant · · Score: 3, Informative
    I've used this kind of thing on Dell servers for, umm, a decade or so? It means I can have headless high-density boxes (four independent systems in a 2U rackmount, e.g.) in my computing center and when a user wedges one of them I can reboot it remotely. I can look at system status, see failed components, and do all kinds of things that I couldn't otherwise do at all. "The system is wedged" is very unsatisfying as a diagnosis. Being able to run a remote console that shows that the swap has gone to 0 and the system is busy killing things tells me right away that someone is using all the memory is great. And then telling the iDrac to "reset the system" ... priceless.

    It may use the same physical interface, but it has its own address, and it can be disabled if someone is ultra-paranoid about it.

    1. Re:Yawn, by mlts · · Score: 2

      It makes life easy for monitoring as well. Some box loses its network connection, getting a console just means going to the iDRAC/iLO web port, logging on, seeing what is going on, and getting the NIC unstuck. It also is nice to load an ISO and install the machine from scratch if the box is a one-off and not worth making a PXE boot mechanism for what it is doing. Or, just boot the ISO stashed as a virtual CD, point it to a kickstarter file, and call it done.

  25. Poorly written FUD by Anonymous Coward · · Score: 3, Informative

    The author's claims that the ME lacks the ability to be audited and that backdoors cannot be removed are patently false.

    - The ME is as many have pointed out an ARC processor. There are known disassemblers for ARC and there are few custom instructions (read: beyond standard ISA) - two that I'm aware of.
    - The bootrom verifies the flashrom and provides some minimal cryptography and verification related routines. This is a mask ROM, not updatable. The flashrom is overwritten when you flash the bios, hence the main OS and binaries (threadx btw) are overwritten. This would remove any backdoor.
    - The ME region of the BIOS is a FAT16 filesystem.
    - The ME binaries are unencrypted, PE executables and contain signature verification sections to prevent unauthorized code from loading.
    - The only encrypted contents of the filesystem are data files that the binaries use.

    Now all this being said, there is a way to load additional modules from the main CPU's operating system through HECI (north bridge interface), however this again requires cryptographic signing.

    Source: Former Intel engineer. Additionally none of these are details that cannot be pieced together from Intel published documents and 5 minutes with a hex editor/disassembler.

    1. Re:Poorly written FUD by cfalcon · · Score: 1

      Ok, I want to go through this with a tinfoil hat.

      > This is a mask ROM, not updatable
      So the mask ROM could check for a certain value at a certain offset in the flashrom. If the value is present, it could inject the backdoor code and/or do some exploit thing. How many people can verify the boot ROM is valid and free from a backdoor?

      > The flashrom is overwritten when you flash the bios ... This would remove any backdoor.

      This could inject any backdoor as well.

      Basically, when tech people are talking about this stuff, there's three broad categories of adversaries:

      An external hacker who has written exploit code. Checking the signatures of files should prevent this attack, exactly as you say.

      A design that trusts anyone who can claim convincingly enough to be a vendor. If the private key gets reverse engineered, leaked, or guessed, than any of that flash rom could be written by the external hacker, above. We don't see these attacks, but the danger is that some of these designs ONLY trust the vendor- they aren't a "two key" system that requires the user AND the vendor to both consent.

      An actively compromised manufacturer. With privacy revelations and state level actors in this arena, having any part not able to be verified by everyone makes it a giant target. In these cases, there could be a backdoor (if offset X = Y, then do Z), or something more subtle. Any state level actor discovered actively compromising Intel would start an economic war, at the very least. Why isn't that code inspectable? What IP is in that code that keeping it on lockdown is worth risking the prosperity of the whole of the Earth?

      These conversations are often strange because someone like you will be discussing practical real world threats and their mitigations, such as code signing, while a couple posts down someone will be convinced that the NSA is trying to steal their dickpics and compromised every firmware in the world to make that happen. But the tinfoil hat comments do refer to a valid type of attacker, and while the risk is low of such an attack, the cost would truly be immense.

    2. Re:Poorly written FUD by Mathinker · · Score: 1

      Did Intel happen to pay for one or more independent reviews of the security of this setup? Has Intel published the results of these reviews?

      Until then, I'll more or less assume that its security is still in question, thank you. (That doesn't mean I won't use it, of course. All kinds of insecure systems are useful).

      And even with such reviews, it would probably be prudent to assume that the signing keys have been compromised, at at least the nation-state level.

    3. Re:Poorly written FUD by Anonymous Coward · · Score: 0

      >What IP is in that code that keeping it on lockdown is worth risking the prosperity of the whole of the Earth?

      Keeping the world safe for democracy (read: women's right to prevent men from marrying young girls)

  26. Same deal. by Anonymous Coward · · Score: 0

    The chip is just an LM32 core instead of the ARC intel uses.

    I2P had a video from CCC two years back (2015? 2014?) from a Russian or Ukrainian guy who managed to hack his (This was back when it was still a discrete part of the chipset, newer ones are built in the APU to help with on-chip power management, and I believe the newer ones also used signed firmware images, whereas the motherboard based models used unsigned firmware, both AFAIK part of the bios image.) In his case he managed to find a method to 'jailbreak' the LM32 processor and run his own code on it. It had been discussed with AMD prior to the convention to ensure it got fixed, but who knows what new exploits are in later revisions of the code.

    At this point in time, neither Intel nor AMD chips (Unless you're still buying AM3, in which case a coreboot/libreboot bios should take care of most worries.) you should assume your non-isolated computer can be used to spy on you, or worse yet passively sniff encryption keys.

    ARM chips are not much better since Trustzone instances do essentially the same thing, either with a management core, or slicing on the primary core if earlier revisions. This means all modern cell phones should be suspect even outside of non-isolated baseband processors because without disassembly proving the trustzone/hypervisor instance is disabled means all your data could be funnelled into an isolated process space for later exfiltration.

    This isn't to say 'be paranoid about everything', but it DOES mean you should never put anything questionable on a non-trustworthy device (And anything without a fully open source firmware chain should be assumed that way today, and anything with one should be assumed to have a hardware backdoor and disallowed from running third party code. If third party data is enough, then the hardware just needs to be chucked.)

    1. Re:Same deal. by Anonymous Coward · · Score: 0

      "At this point in time, neither Intel nor AMD chips (Unless you're still buying AM3, in which case a coreboot/libreboot bios should take care of most worries.) you should assume your non-isolated computer can be used to spy on you, or worse yet passively sniff encryption keys."

      So the only solution is a violent revolution and torture?

  27. How to disable it? by TheDarkMaster · · Score: 1

    And how to ensure it stays disabled?

    --
    Religion: The greatest weapon of mass destruction of all time
    1. Re:How to disable it? by Anonymous Coward · · Score: 0

      Libreboot on an old platform, with a stub ME firmware. No way to ensure it stays disabled other than finding a way to damage a FLASH ship to destroy itself on erase.

      It is an essential component, you *need* some of the actions the ME performs for the system to work. You cannot do without ME on a modern Intel platform, although it is trivial to do without AMT (all it takes is to get a BIOS with ME but without AMT).

      Now, a vetoed, barebones Intel ME that just keeps the system running without any remote management capabilities would be very nice, even if we never could change it. But it doesn't exist.

    2. Re:How to disable it? by boondaburrah · · Score: 1

      You can't. If you have a modern intel CPU, the chip will detect that ME is disabled and shutdown the computer after 30 minutes.

    3. Re:How to disable it? by Anonymous Coward · · Score: 0

      AMT is used for enterprise remote management and anti-theft purposes (if your laptop is stolen, you can lock it down). This is actually a well documented feature that can be disabled in BIOS. Unless you have a business laptop or workstation, it is most likely off anyway.

    4. Re:How to disable it? by Anonymous Coward · · Score: 0

      Incredible. Do you have any citation to back this up?

    5. Re:How to disable it? by AHuxley · · Score: 1

      Buy another brand of computer thats well understood and has every chip looked at and the OS is open.
      If a site, country, brand or network is interesting, expect other nations security services to be all over any such offered hardware options or adding extra access option during private sector shipment.
      Why would any nation or brand risk having a computer system that can be turned on, accessed, logs altered and turned off as part of the normal network hardware as imported?

      --
      Domestic spying is now "Benign Information Gathering"
    6. Re:How to disable it? by Anonymous Coward · · Score: 0

      That's not suspicious at all.

  28. It's not new, most servers had this years ago... by Fallon · · Score: 2

    This is not new & lots of others sell similar functionality Dell DRAC, HP ILO... Those usually have dedicated Ethernet ports, but generally function the same way. I've been helping our workstation guys roll out Intell vPro for remote administration of laptops & workstations. It operates in a powered down state & can do 802.1x authention to the network while the OS is powered down. So ya, there is definately an out of band processor there that can wake the system up & do remote control type stuff. It's a feature Intel is selling & marketing.

    Can't comment on the ability of it to do arbitrary memory reads & what not, but that isn't suprising in thoery. It's much less scary than the article is making it out to be, although it is another attack surface to concerned with just like RDP or SSH.

  29. TROLOLOLOLO!!!! by Thud457 · · Score: 1, Informative

    This is the same FUD from Hack-a-day from last Janumanary

    DUPE ALL THE THINGS!
    Anononymous poster, check!
    Be sure to mine the +5 comments from old stories for cheap karma!

    --

    the preceding comment is my own and in no way reflects the opinion of the Joint Chiefs of Staff

  30. Don't blame them... by Anonymous Coward · · Score: 0

    All the editing staff that knew that got kicked out a month or two ago when the last sal^H^H^Hchange of the guard happened and as a result some posted articles were lost in the shuffle :)

    More seriously though, this was back on soylentnews a couple days ago linking to the FSF's recent rant about it. You know, years after it could make a difference. It was apparently partly due to rolling libreboot into the FSF/GNU fold. I wonder if they will go like gnupg and spin themselves back off when it turns out there aren't any benefits to being an FSF/GNU project anymore.

    GNU is the GNU old :)

  31. This is very old news by Anonymous Coward · · Score: 0

    This has been out there since 2013...
    https://software.intel.com/en-us/articles/intel-active-management-technology-start-here-guide-intel-amt-9

    Also AMD users, you are still affected....
    https://www.amd.com/Documents/out-of-band-client-management-overview.pdf

  32. Wow! This is SUPER SECRET! (Not) by kevmeister · · Score: 1
    IME and AMT have been well documented for years. The Wikipedia article has been around since at least 2007 and was flagged by an editor as reading like an Intel ad. It fully describes the basic design and functionality of the system and only varies from the article in that AMT has now been incorporated into the chipset and is no longer a separate chip.

    Even that its network connection is independent of the CPU and any filtering is described.

    I have been aware of AMT since it was discussed as a way to do an psueudo-console connection on modern systems that lack a serial port in FreeBSD kernel debugging discussions. I suspect that Linux discussions also show how to do this as IT IS NOT SECRET!

    I'm not really comfortable about it, but it is very useful, has been designed with security in mind and should be very difficult to suborn, and Intel considers it a feature that is advertised, so IS NOT A SECRET!

    --
    Kevin Oberman, Network Engineer, Retired
    1. Re:Wow! This is SUPER SECRET! (Not) by Anonymous Coward · · Score: 0

      IME and AMT have been well documented for years. The Wikipedia article has been around since at least 2007 and was flagged by an editor as reading like an Intel ad. It fully describes the basic design and functionality of the system and only varies from the article in that AMT has now been incorporated into the chipset and is no longer a separate chip.

      Even that its network connection is independent of the CPU and any filtering is described.

      I have been aware of AMT since it was discussed as a way to do an psueudo-console connection on modern systems that lack a serial port in FreeBSD kernel debugging discussions. I suspect that Linux discussions also show how to do this as IT IS NOT SECRET!

      I'm not really comfortable about it, but it is very useful, has been designed with security in mind and should be very difficult to suborn, and Intel considers it a feature that is advertised, so IS NOT A SECRET!

      FULLY documented? Not likely. Scan the actual exposed chip itself and decode all the pathways. Donuts to dollars you'll find at least a couple specials little things going on that aren't in any public documentation.

  33. Yo Dawg... by Anonymous Coward · · Score: 0

    Yo dawg I heard you liked getting hacked so we put a CPU in your CPU so we can take over your machine while we take over your machine

  34. Decades old news by Anonymous Coward · · Score: 1

    Out of band management processors are nothing new. Neither are the myriad other special purpose chips in a system that can be exploited as general purpose processors, some less predictably than others.

  35. Government backdoor? by Anonymous Coward · · Score: 0

    Its awfully convenient, and I don't think anyone would be surprised if they pushed for a hardware level backdoor like this.

  36. "No surveillance or other purposes" -- really? by l2718 · · Score: 5, Informative

    If the only goal was simply to provide low-power functionality, the coprocessor would be fully controlled by the operating system (ultimately, by the owner of the machine).

    In fact, the main goal is to provide remote administration capabilities (what they call Intel Active Management Technology). In other words, the idea is to allow a remote administrator to take over the machine in a way that is independent of and invisible to the main operating system and processor. This serves a legitimate purpose in an "enterprise" environment (one person administers a large number of diverse machines) -- for example it allows taking back control of a cracked machine, or recovering critical data from memory after OS crashes. However, this feature is not useful for a privately administered single-user machine.

    Finally, by definition a remote administration feature is a back door. This one is incredibly dangerous: a rootkit running on the coprocessor is entirely invisible to the operating system, has its own independent network access, and can monitor the disk, the memory and all other peripherals. In principle the remote management features must be activated via the System BIOS and you can set a password there, but really your only measure of safety against this back door is your trust that there are no bugs in Intel's code.

    Why isn't Intel allowing you to replace the firmware? Because it's hard to ensure that the owner of the machine is the one initiating the firmware replacement. The real troubling point is that Intel isn't allowing you to disable this feature with a hardware switch. Hardware switches (jumpers on the motherboard) are a way of controlling the system available only to the physical owner of the machine. Having a hardware switch would satisfy both the enterprise and security-concious customers.

    1. Re:"No surveillance or other purposes" -- really? by Nemyst · · Score: 1

      Hardware switches (jumpers on the motherboard) are a way of controlling the system available only to the physical owner of the machine. Having a hardware switch would satisfy both the enterprise and security-concious customers.

      Would it though? What's to stop whatever nefarious agent who's managed to obtain a sensitive laptop from disabling the switch? I know that they can just avoid connecting to any network and that'd also prevent remote access, but if they disable the entire EC, they can legitimately use the full computer without any further hurdles.

    2. Re:"No surveillance or other purposes" -- really? by sjames · · Score: 2

      Older schemes where the BMC couldn't access the system memory were safer. One safety feature would be to replace memory access with specific interfaces (serial and a general access port used by SMM) and their own independent network interface (allowing effective vlan isolation with no need for the honor system). To complete the picture, the BMC could emulate a USB device connected on the MB to an actual USB chip. At least that way they would need to compromise 2 firmware images to get anywhere.

    3. Re:"No surveillance or other purposes" -- really? by Immerman · · Score: 1

      Nothing. If a nefarious actor gains physical access to a machine, it's security is basically gone regardless. However, that's extremely rare, and unlikely to be a vector for either malware or mass surveillance. It's just too labor-intensive. A hardware switch at least makes sure that someone needs physical access to enable the attack vector especially if it physically disables the functionality in question (e.g. completely cuts power to the "stealth coprocessor", or at least it's data bus).

      --
      --- Most topics have many sides worth arguing, allow me to take one opposite you.
    4. Re:"No surveillance or other purposes" -- really? by Anonymous Coward · · Score: 0

      There are chassis-intrusion alarms that security conscious enterprises already use.

    5. Re:"No surveillance or other purposes" -- really? by Anonymous Coward · · Score: 0

      One safety feature [is using] specific interfaces [..] and their own independent network interface. To complete the picture, the BMC emulate[s] a USB [hub or composite] device [and peripherals] connected on the MB to an actual USB [interface].

      FTFY. This is pretty much exactly how IPMI works.

    6. Re:"No surveillance or other purposes" -- really? by AmiMoJo · · Score: 1

      The down side to that is you can't implement Secure Boot. Secure Boot allows you to verify that the OS hasn't been tampered with before it is booted, mitigating many rootkits.

      It's a trade-off. Which security feature is more useful?

      --
      const int one = 65536; (Silvermoon, Texture.cs)
      SJW, n: "Someone I don't like, and by the way I'm a fuckwit" - AC
    7. Re:"No surveillance or other purposes" -- really? by Anonymous Coward · · Score: 0

      If someone has enough access to change motherboard jumpers they can also solder / de-solder things from the circuitboard(s). At this point you either have to pot the whole damn thing with nonconducting JB weld (disabling the switch via jumper no longer trivial) or admit you have bigger security problems if an unauthorized someone has that level of access.

    8. Re:"No surveillance or other purposes" -- really? by Anonymous Coward · · Score: 0

      A hardware switch does nothing against the "evil maid" attack.

    9. Re:"No surveillance or other purposes" -- really? by sjames · · Score: 1

      You can still verify the OS, you just can't verify the BIOS. That's more than enough for most use cases. The only time it isn't adequate is when someone like MS wants to retain authority over your hardware (mostly so you can't load a driver that copies out decrypted media) or in cloak and dagger scenarios.

      Personally, I wouldn't want a machine with Secure Boot that I couldn't disable in the configuration. YMMV

      I definitely do not want a setup where someone might re-flash my BIOS from half way around the world and doesn't even have to reboot to do it.

  37. Article Verification by Anonymous Coward · · Score: 0

    Slashdot is unable to verify the claims of this article..... But do they ever verify the claims?

  38. ME's been around awhile. by Anonymous Coward · · Score: 0

    ME's been around awhile.
    I can with 100% certainty say that in addition to the things they're discussing, ME is also used to lock in chipset feature sets, for example whether or not the motherboard will do RAID 0, 1, 5, etc. In order to bypass the ME, it requires a special version of the BIOS, with ME nerfed in software, and a corresponding CPU with the appropriate fuses blown to disable the hardware. It was incredibly difficult to obtain proper authorization to have one of the these CPUs created for testing and getting the BIOS wasn't any easier. It took months.
    Source: worked in Intel's Storage Lab.

    1. Re: ME's been around awhile. by Anonymous Coward · · Score: 0

      Nerf (video gaming) - Wikipedia, the free encyclopedia
      https://en.m.wikipedia.org â wiki â Nerf_...
      Mobile-friendly - In video gaming, a nerf is a change to a game that makes something less effective or desirable. The word can be used as a verb to describe that change. The opposite of nerf is buff or revamp.

  39. Unplug your computer by fustakrakich · · Score: 1

    To be extra safe, remove the BIOS battery (it was an old habit of mine to remove the distributor rotor to keep my car from being stolen).

    --
    “He’s not deformed, he’s just drunk!”
  40. How the FUCK did this make it to "story" status? by Anonymous Coward · · Score: 0

    Please, will someone tell me? Intel vPro x86 processors have had an IPMI and RDS/KVM server for YEARS.

    YEEEEAAARRRRSSSS!!!!! What the fuck, Slashdot? Are you all really that fucking stupid? This isn't some NSA hack. It's a feature that large businesses pay a lot of money for to be able to remotely control their PC assets regardless of whether the user has done something to attempt to lock the PC down.

    Idiots. Jesus Christ.

  41. More of this FUD? by RightSaidFred99 · · Score: 0

    Good God. I swear to fucking god I see one of these articles every few months when some asshole "discovers" AMT and makes up all sorts of ridiculous doomsday scenarios. It's about as silly as all those "OMGWTFBBQ UEFI WILL BLOCK LINUX FROM BEING INSTALLED WINDOZZZEE EVIL MICKEY$OFT OMG PANIC!!!!" posts we saw and will probably continue to see.

    Between this and the "you can figure out an RSA key if you listen to your computer really hard!" articles I swear this site is being just inundated with even more nonsense than usual.

  42. I think this is oversold as a risk by cfalcon · · Score: 3, Interesting

    I'm of the opinion that management features need to get data from the motherboard, and each mobo manufacturer would have to be complicit for this potential attack to affect everything (assuming a bug or backdoor exists). *IF* there's a backdoor in the ME, and *IF* all (or at least YOUR) motherboard manufacturers are complicit, even *THEN* a good external firewall would stop most conceivable attacks.

    It really is unfortunate that it is so clouded with mystery and seemingly waiting for a clever enough exploit.

    If you are concerned a little, ensure that AMT is disabled.
    If you are concerned a little more, consider grabbing an AMD next time. While AMD has similar things, Intel seems like it is both more featured and a larger attack surface, so an AMD exploit might be absent or would take longer to surface.
    If you are concerned moderately, ensure that external sources can never successfully send a packet to your PC, by use of an external firewall that is trusted.
    If you are concerned a lot, exclusively use open source products from before the mandatory inclusion of the ME. Have one to act as your firewall / router (maybe running OpenBSD or Trisquel), and another to do productivity on. You'll be limited on the power of the chip, of course.

    Frankly, I think it is wise to distrust the ME a little bit. Especially because, as part of Intel chips, it is going to be in so many places- it is a lot of faith to put in untested code. But for the ME to be able to hurt or help you, the motherboard has to support its features, and there are a lot of motherboards, a lot of BIOSes- it is still a pretty diverse setup, and many don't support AMT at all.

  43. Disable? by ugen · · Score: 1

    So, how do I turn the damn thing off? (I suspect the answer to be "can not", but anyone that knows otherwise - let me know)
    I do, however, notice that there are no open listening ports on my current Intel computer, when scanned externally. Is this thing always on? What conditions enable it (so that I'd know to avoid those)?

  44. Don't tell them about the mouse or keyboard by WillAffleckUW · · Score: 1

    those have executable memory space too, just like the printers

    look, if you have a camera, it's hackable

    if you have a video card, it has memory and chips that can be used by someone else

    face it, you're being spied on, and the Gestapo loves that

    --
    -- Tigger warning: This post may contain tiggers! --
  45. Repeat? by Anonymous Coward · · Score: 0

    Regardless of the caveats from the Editors I'm pretty damn sure this is a repeat of a story from some months ago. I don't know that in either story there's anything to be TOO concerned about at lease in terms of Intel's intensions (management layer etc.) except the fact that people know very little about this extra processor, it can't be controlled easily or locked down etc. As the summary says IF (or when) the cpu gets compromised than that's a big pickle.

  46. What I want to know is... by JoeDuncan · · Score: 1

    ...why didn't our ancient alien overlords stop the NSA from doing this?

    1. Re:What I want to know is... by hyades1 · · Score: 1

      Who do you think created the NSA?

      --
      I've calculated my velocity with such exquisite precision that I have no idea where I am.
    2. Re:What I want to know is... by dfsmith · · Score: 1

      The Illuminati Council of Atlantis voted them down in a poll alleged to be rigged by Lee Harvey Oswald just before Princess Diana was about to publish the real moon landing photographs.

    3. Re:What I want to know is... by JoeDuncan · · Score: 1

      Damnit, not AGAIN!

  47. Goodness Sake, by Anonymous Coward · · Score: 0

    Looks like somebody found a service processor. Gosh, me tenders!

  48. Vernor Vinge called it: Ubiquitous Law Enforcement by LionKimbro · · Score: 1

    Vernor Vinge drew up some diagrams of what this would look like, whereabouts 2005: http://vrinimi.org/front9uns.j...

  49. Useful if you need it, trivial to kill if you dont by Anonymous Coward · · Score: 0

    Egress filter. Use non-integrated NICs.

    Or, leverage it to manage 1000s of workstations in a business environment.

    Non-story.

  50. X86 as a firewall by Anonymous Coward · · Score: 0

    so how this effect things if i'm running a software firewall on an intel platform?

  51. How exactly? by Anonymous Coward · · Score: 0

    It also runs a TCP/IP server on your network interface and packets entering and leaving your machine on certain ports bypass any firewall running on your system....How exactly? Those packets would still need to be routed ... somewhere.

  52. X86? who would want one over X64? by Anonymous Coward · · Score: 0

    I didn't even know they still made them since most every modern OS requires 64bit processors.

  53. Well it's not an escape hatch. by Anonymous Coward · · Score: 0

    So it's an entry point. You wouldn't add extra points of entry yourself unless you wanted to let *your company eg. Intel* or a government agency in.

    To post this specific story with the disclaimer:
    Editor's note: The summary is written with inputs from an anonymous reader, who also shared the story. We've been unable to verify the claims made by the author.

    Well that says a lot to a mental gymnast. It means you are posting stories about Intel knowing very well this website has a large enough audience to be government monitored.

    Slashdot is government monitored. CIA 24/7

    Leaving a control mechanism in users' hardware on a large retail scale is of no good to anybody good. One could say yeahh.. in case you forget your password we have this in there and stuff you know. That's not why government's monitor your PC's. They fear losing their control over the public.

    1. Re:Well it's not an escape hatch. by Anonymous Coward · · Score: 0

      That's also why Slashdot tracks you with gn.symcd.com on port 443.

  54. Truly a Hillary Technology: From Wikipedia by Anonymous Coward · · Score: 0

    Known vulnerabilities and exploits

    A Ring -3 rootkit was demonstrated by Invisible Things Lab for the Q35 chipset; it does not work for the later Q45 chipset as Intel implemented additional protections.[39] The exploit worked by remapping the normally protected memory region (top 16 MB of RAM) reserved for the ME. The ME rootkit could be installed regardless of whether the AMT is present or enabled on the system, as the chipset always contains the ARC ME coprocessor. (The "-3" designation was chosen because the ME coprocessor works even when the system is in the S3 state, thus it was considered a layer below the System Management Mode rootkits.[32]) For the vulnerable Q35 chipset, a keystroke logger ME-based rootkit was demonstrated by Patrick Stewin.[40][41]

    Another security evaluation by Vassilios Ververis showed serious weaknesses in the GM45 chipset implementation. In particular, it criticized AMT for transmitting unencrypted passwords in the SMB (small business) provisioning mode when the IDE redirection and Serial over LAN features are used. It also found that the "zero touch" provisioning mode (ZTC) is still enabled even when the AMT appears to be disabled in BIOS. For about 60 euros, Ververis purchased from Go Daddy a certificate that is accepted by the ME firmware and allows remote "zero touch" provisioning of (possibly unsuspecting) machines, which broadcast their HELLO packets to would-be configuration servers.[42]

  55. NOT by Anonymous Coward · · Score: 0

    If Wikipedia is correct, AMT is a shitball which can be accessed with a $60 HTTPS Certificate from a shit-SSL-cert supplier.

    And then you need only one (1) PC in your network infected to enable an attacker to root 100% of your machines.

    Indeed AMT should be disabled, if that is possible.

    Or better, do not buy an Intel product. Buy some CPU without these craptastic functions. Best is to buy a product from a jurisdiction where Hillary and Carly have no saying. Because they want to pwn your computer - something they openly state.

    Fujitsu and the Chinese make CPUs. So does MCST of Moscow. Why do we need Ameri$hit with builtin N$A$hit ?

  56. Also by Anonymous Coward · · Score: 0

    Some folks from Chengdu and from the North Korean Long Range Reconnaissance Forces have been administering your information at the same time. Cheers !

  57. Conspiracy to Wiretap for Foreign Nation by Anonymous Coward · · Score: 0

    Oh wait, that is not a problem if your are a donor and chummy of Hillary Clinton.

    Also, NSA gives a copulation if they can get in. All they care is to get in, they do not care about other dicks having that capability, too.

  58. Not news by Anonymous Coward · · Score: 0

    The ME has been around for ages and ages. I met a team researching exploits for it YEARS ago.

  59. This has existed since 2008 by Anonymous Coward · · Score: 0

    There is no new information here

  60. Coreboot has been trying to work around this stuff by LaughingRadish · · Score: 2

    The Coreboot people have been trying to work out how to deal with this stuff for a long time. See https://www.coreboot.org/Intel.... They're trying to work out how to disable it, but progress is not that good.

  61. This is quite surprising by Gumbercules!! · · Score: 1

    I have to say, I am actually pretty surprised by this news. I had no idea boingboing was even still going...

    1. Re:This is quite surprising by bloodhawk · · Score: 1

      gather by the lack of technical knowledge of the author about a common feature he thinks is somehow secret and hidden it really would be better off dead.

  62. New by Anonymous Coward · · Score: 0

    Is this new? Hackers have been using this to take over networks for years

  63. Hey Let's Make a Fuss out of a Non Secret. by Anonymous Coward · · Score: 0

    Since when was the ME a secret? TFA is nonsense. It's claiming it's secret so they can make a fuss about it when it isn't a secret. It's functions, like AMT are documented in the Intel CPU manuals.

    It's also needed so you can have effective power management. The CPU can't manage it's own power when it's turned off. So a small CPU that consumes less power is useful to handle the switching on and off of sub units.

  64. Secret WTF? by bloodhawk · · Score: 1

    Secret? ummm welcome to a decade ago. The only thing secret about this appears to be the authors lack of knowledge about technology from the last decade. This has been a common selling point for a long time with its various iterations to allow management of machines regardless of OS and/or health of said OS so that you can fix shit remotely.

  65. Fuck you, Intel by Anonymous Coward · · Score: 0

    Access to fucking TCP/IP? Fuck you

    Author says '' Unfortunately, since the firmware is protected by RSA 2048, we currently have no way to execute our own code on the ME hardware because it fails validation. We have no way to move forward, even if we wanted to. ''

    Well I know someone who could call Intel and demand the RSA keys and they would get them.

    So if you care about your data security, don't buy Intel.

  66. Opentools by Anonymous Coward · · Score: 0

    http://opentools.homeip.net/

    Something else to add to the list.

  67. Home is were the enterprise is. by Anonymous Coward · · Score: 0

    With the price of servers coming down, home users may have this technology, and for the same reasons.

  68. bye Intel, hello AMD by slashmydots · · Score: 1

    When I looked up what ME was when it was invented it basically said it can do stuff while your computer is off. I thought "well that's exploitable and besides that, very suspicious." Now fast forward and people finally caught on. If this hits the news media that a computer can be permanently hackable and even while in sleep mode, every last consumer is rushing out to get AMD-based systems. Corporations will too! They don't want their data secretly stolen past their OS's anti-malware suites. Intel might as well have mailed a check for 5 billion dollars over to AMD and after the BS in their pricing lately and monopoly abuse and dishonest product naming, they deserve it.

  69. Tiny drill bit by joboss · · Score: 1

    I've had this really tiny drill bit for ages and I've been wanting to find a use for it. Thanks to Intel I now at last can do something with it.

  70. got to love slashdot comments by Anonymous Coward · · Score: 0

    Light gray text on white-ish background? I can hardly see there are comments in the white space, but maybe years have finally caught up with me.

  71. Seems quite scary by Anonymous Coward · · Score: 0

    Intel ME seems quite scary even without AMT. See https://libreboot.org/faq/#intelme.

  72. how is this news or claims? by avgapon · · Score: 1

    How is this "news" or "claims" if the Intel AMT / ME documentation described this from the very start?

  73. The remote management stuff by mumma3k · · Score: 1

    Is any of this enabled by default? Does it have to be manually activated in BIOS? None of my systems repsond on those ports. Ofcourse it's enabled for NSA already, but for us ordinary people?

  74. NSA by Anonymous Coward · · Score: 0

    Maybe the NSA has already done that "extraordinary work" you speak of.

    Of course they have, I'd be extremely disappointed in their effectiveness if they hadn't. Heck, they probably gave the idea to Intel in the first place. This doesn't mean I like the idea of them doing it, only that I am a realist and know that the NSA exists to do exactly this.

    Is it a conspiracy when its in their charter?

  75. Old news + AMD got something similar by Susinthir by Anonymous Coward · · Score: 0

    More or less old news for me: https://libreboot.org/faq/#intelme
    AMD has something similar to Intel ME called PSP: https://libreboot.org/faq/#amdpsp

  76. Safe computer? Laptop sans AMD & Intel inside? by Anonymous Coward · · Score: 0

    Knowing both AMD & Intel have ways to remotely read storage and open hardware ports, even while main CPUs are "off", where is the 64 bit alternative? ARM, MIPS & Power all might be good but who markets a 64 bit laptop without AMD or Intel inside?
    ARMv8 & ARMv9 laptops always seem to be tomorrow. What is today?

  77. Really Slashdot? by Anonymous Coward · · Score: 0

    This stupid alarmist bullshit keeps popping up every few months. Some moron even wrote a research paper on it. The fact that Slashdot sees fit to post it as a front-page article is deeply disappointing, but not surprising.

  78. Know your environment for better control it by info6568 · · Score: 1

    I have been reading many different types of justifications on the security of the CPU makers (whatever be the brand). However we can't overestimate the fact that we are humans and that anybody can make mistakes, in particular with so complex artifacts as CPUs. These hidden parts and their security mechanisms can have bugs (yesterday, today or tomorrow). And also, they are not designed only to work with previous and current scenarios, but with the unknown future ones that are completely unexpected.

    Thinking on this issue I checked quickly what CPUs have the Cisco Firewalls (just to check a famous brand), and notice that they have different ones depending on the appliance model, from the AMD Geode to some Intel Xeon variants, so there are possibilities even on security appliances for this to be exploited.

    The problem with this hidden CPU approach is that they can bypass the computer built security without the operating system noticing it, with potentially dangerous consequences. And we are updating our software regularly but the most of the people is not aware of the updating on the underlying things (if they can be updated). The lack of knowledge in this respect is a dangerous thing.

    But what can be done?

    A very few are careful enough on checking the internal hardware specifications on the networking devices, the ones could protect any not so well controlled hidden device inside our network. So, it is really important to learn more about what we really have and if it is possible to combine "different" layers of appliances. For example, not to rely only on Intel or only on AMD for both servers and security appliances, or even to combine x64 and x32 with ARM, MIPS or other type of CPUs. This way, if there is a breach because some architectural failure, the next layer won't suffer the same fate because it is different (not necessarily because it is better). This combination of suppliers is something it is already being recommended for antivirus on enterprise environments (don't trust only in one supplier).

    On the other case, when knowing extra ports and other elements that nobody is actively controlling within our network, will be possible to understand better that maybe that "extra" traffic has a hardware and not a software origin.

    Our modern environments are rich and powerful, but this richness doesn't come for free. We need to understand it and control it correctly.

    https://communities.cisco.com/...

  79. Joanna Rutkowska presentation on this topic by Mojo66 · · Score: 1

    Joanna has been researching this for a while, this is her presentation at 32c3.

  80. I am just about to buy a new machine by Anonymous Coward · · Score: 0

    And it will most definitely not be Intel based now.

  81. Buy real and fake Passport ,Visa,Driving License,I by pauldocument · · Score: 0

    Buy real and fake Passport ,Visa,Driving License,ID CARDS,marriage certificates,diplomas etc for sell Guaranteed 24 hour passport,citizenship,Id cards,drivers license,diplomas,degrees,certificates service available. Tourist and business visa services available to residents of all 50 states and all nationalities Worldwide. are unique producers of Authentic High Quality passports, Real Genuine Data Base Registered and unregistered Passports and other Citizenship documents.I can guarantee you a new Identity starting from a clean new genuine Birth Certificate, ID card, Drivers License,Passports, Social security card with SSN, credit files, and credit cards, school diplomas, school degrees all in an entirely new name issued and registered in the government database system.. We use high quality equipment and materials to produce authentic and counterfeit documents.All secret features of real passports are carefully duplicated for our Registered and unregistered documents.we are unique producer of quality false and Real documents.We offer only original high-quality Registered and unregistered passports, drivers licenses, ID cards, stamps, Visa, school Diplomas and other products for a number of countries like:USA, Australia, Belgium,Brazil, Canada, Italian,Finland, France, Germany, Israel, Mexico, Netherlands, South Africa,Spain, United Kingdom. UNIVERSAL PAPERS Contact us on................pauldocument508@gmail.com General Support:-------- pauldocument508@gmail.com we are able to produce the following items; REAL BRITISH PASSPORT. REAL CANADIAN PASSPORT. REAL FRENCH PASSPORT. REAL AMERICAN PASSPORT. REAL RUSSIAN PASSPORT. REAL JAPANESSE PASSPORT. REAL CHINESSE PASSPORT. AND REAL PASSPORT FOR COUNTRIES IN THE EUROPEAN UNION. REAL DRIVERS LICENSE,I.D CARDS,BIRTH CERTIFATES,DIPLOMATS,MARRIGE CERTIFICATES,AND VISAS. REGISTERED AND UNREGISTERED BRITISH PASSPORT. REGISTERED AND UNREGISTERED CANANIAN PASSPORT. REGISTERED AND UNREGISTERED FRENCH PASSPORT. REGISTERED AND UNREGISTERED AMERICAN PASSPORT. REGISTERED AND UNREGISTERED RUSSSIAN PASSPORT. REGISTERED AND UNREGISTERED JAPANESSE PASSPORT. REGISTERED AND UNREGISTERED CHINESSE PASSPORT. REGISTERED AND UNREGISTERED PASSPORTPASSPORT FOR COUNTRIES IN THE EUROPEAN UNION. Buy Registered and unregistered USA(United States) passports, Buy Registered and unregistered Australian passports, Buy Registered and unregistered Belgium passports, Buy Registered and unregistered Brazilian(Brazil) passports, Buy Registered and unregistered Canadian(Canada) passports, Buy Registered and unregistered Finnish(Finland) passports, Buy Registered and unregistered French(France) passports, Buy Registered and unregistered German(Germany) passports, Buy Registered and unregistered Dutch(Netherland/Holland) passports, Buy Registered and unregistered Israel passports, Buy Registered and unregistered UK(United Kingdom) passports, Buy Registered and unregistered Spanish(Spain) passports, Buy Registered and unregistered Mexican(Mexico) passports, Buy Registered and unregistered South African passports. Buy Registered and unregistered Australian driver licenses, Buy Registered and unregistered Canadian driver licenses, Buy Registered and unregistered French(France) driver licenses, Buy Registered and unregistered Dutch(Netherland/Holland) driving licenses, Buy Registered and unregistered German(Germany) driving licenses, Buy Registered and unregistered UK(United Kingdom) driving licenses, Buy Registered and unregistered Diplomatic passports, Buy Registered and unregistered USA(United States) passports, Buy Registered and unregistered Australian passports, Buy Registered and unregistered Belgium passports, Buy Registered and unregistered Brazilian(Brazil) passports, Buy Registered and unregistered Canadian(Canada) passports, Buy Registered and unregistered Finnish(Finland) passports, Buy Registered and unregistered French(France) passports, Buy Registered and unregistered German(Germany) passports, Buy Registered and unregistered Dutch(Netherland/Holland) passports, Buy Registered and unregister

  82. AL foil hats may help by Anonymous Coward · · Score: 0

    When I use my i7 laptop I make sure I'm wearing my AL foil hat ;-}

  83. I for one welcome by gzuckier · · Score: 1

    our new Intel Management Engine overlords.

    --
    Star Trek transporters are just 3d printers.
  84. Why the fuss? by NoWhereMan · · Score: 1

    I fail to see why this is such a big deal. This type of approach has been used for years. I am most familiar with the Oracle ILOM but IBM, HP, and others do something similar. I guess when they do it on a chip basis people treat it differently than when they do it on a system. When I first started working with computers, the machines would use multiple boards to implement the cpu. Now people act as if the world has been recreated because we have System-in-a-chip technology. While I recognize the progress and agree that things have improved, the approach is still the same when you think in terms of functional units.

  85. AMD vs Intel war is not for this article idiots.. by Anonymous Coward · · Score: 0

    Here the point is that finally big brother has a golden backdoor to every Intel computer there is/will be. Microsoft will stop supporting older Intel CPUs and only Skyline and future Intel CPU generations will be supported in Windows 10 +. I don't think that is a coincidence. You have the most privacy careless OS (Windows 10) running on the top of a CPU that has a built in backdoor. If that is not scary then I don't know what is.

    A while back I remember reading an article where a guy was constantly getting hacked even when his laptop was not connected his network. How difficult can it be to install a radio receiver and transmitter on ME so that even if Wireless and Network card are disabled, somebody can still access your PC through a radio receiver installed in ME? All that person would have to do is get close enough to your PC to access it.

    You can fight all you want about Intel vs AMD, but at the end of the day. We all lose because AMD is probably going to be forced to add something like ME in its CPUs in order to "compete" with Intel.

    If you like Intel, then go to your garage and get those Pentium 4 and Core 2 Duo Desktop PCs otherwise you will have somebody else watching all those cat videos you keep watching in Facebook.......

  86. Ummm... by martinfb · · Score: 1

    Highly unlikely.

    --


    Self-importance and self-indulgence is the root of ALL evil.
  87. Re:Buy real and fake Passport ,Visa,Driving Licens by Anonymous Coward · · Score: 0

    Can you please urgently (within the next 24 hours) make a US passport and a US high school diploma certificate, roll them up together, and shove them up your ass? If the deadline is not too much for you, I can send you further information.

  88. Holy cow! by KenHansen · · Score: 1

    Including computers capable of out-of-band communication and control of the local machine has been a staple of server design for DECADES - corporate desktops have included this facility for years as well. This is nothing more than yet another server technology migrating to end-user desktops. It is fascinating that the article describes this as 'secret' yet includes links to public pages on intel's website that document this over 8 years ago.

  89. Open secret by Anonymous Coward · · Score: 0

    Intel ME features has been around for many many years and Intel makes no effort to hide it. Its not a secret that Intel ME operates out-of-band and its mainly supported on models targeted for businesses (non-consumers). If you don't like it, don't enable it in the first place or don't get a processor model that supports it.
    Can't wait for that developer to discover other IPMI implementations.

  90. If Intel is working for a warring faction by Anonymous Coward · · Score: 0

    I can't but think that if Intel corp is working for a warring faction, and is involved in acts of espionage, sabotage and surveillance of users of their computer chips, like with possibly other corporations, I really think such an organization would be potentially harmful and definitely threatening, hypothetically making them as dangerous and threatening as the proverbial enemy combatant.

    1. Re:If Intel is working for a warring faction by Anonymous Coward · · Score: 0

      They war to keep women's position above men.

      To make the world safe for democracy.

  91. To keep men away from girls, all eyes on wimmin by Anonymous Coward · · Score: 0

    They want to cache the pedos who like young girls and keep the world safe for women.

    Remeber: opposing men taking young female children as brides is a death sentence: (Dt 13:6 hebrew) (elohim means judges/rulers/gods/etc)

    Men are permitted to rape2own female children: (Dt 22:28-29 hebrew)

    Enticing others to follow something else is a death sentence: (Dt 13:6 hebrew)

  92. Re:How the FUCK did this make it to "story" status by Anonymous Coward · · Score: 0

    Mad the backdoor is getting some exposure, techie faggot shill?

    Aren't you too busy making the world safe for (women's) democracy?
    Hurry, there are some men marrying young girls somewhere in the world.