Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

At first it looks nice "oh now we can get rid of it" but it also opens up a very scary near future security-wise.

We've now entered a realm where an attacker could simply plug a device on an usb port of your computer for a few seconds to have it access your cpu's ME through USB JTAG and take over it, allowing him to have full access and control over what you do/read/open/type over the network, without you ever knowing it since you can't see it. And the only way to get rid of it for sure would be to pretty much throw that cpu away and buy a new one.

Or am I being overly paranoid and there is something I haven't considered that makes this scenario impossible ?

EDIT: given the answers I think my main concern wasn't well expressed above. I'm not saying this as in "ME is making it easier to be compromised". That may or may not be true, but that's not my point.

My point is, we all know that once compromised, you can't clean it and need to burn it all and start from scratch: recover from backup (not files on the compromised machine), format everything, reinstall. Due to the nature of the ME, this is not a solution here. The cleanup needs to be done at the hardware level. Unless I misunderstood something, once it happens, your cpu is done for, period. And 'using a hack to cleanup the hack' is still in the realm of cleaning up rather than start from scratch, it's not a solution for the same reason than cleaning up your comprised linux box is not one and you need to start from scratch.



The 'evil maid' attack is well known, and states that once someone has physical access to your computer, all bets are off. Anything that has DMA enabled (e.g. Firewire or Thunderbolt) offers an external device direct access to the system RAM that is very difficult to defend against, or they could attach a keylogger or modify your bootloader, basically unleash all manner of havok. USB JTAG is really no different from a security POV.

The concern with the Intel ME is that it has a native network adapter. You can bet efforts are currently underway to discover how to exploit the ME remotely. THAT'S when things get scary.

Your paranoia is not unjustified. Personally, I am nervous that some of my systems have the ME. When attention turned to it about a year ago, i knew it would only be a matter of time before someone broke into it.


> The concern with the Intel ME is that it has a native network adapter.

Yep, this is the big deal. After I "discovered" the ME, my first stop on my home network was the switch, to block all that crap. (And I found my storage server, equipped with a Supermicro all-in-one motherboard, helpfully grabbed an IP for the ME to listen on with an 'admin/admin' password.)

I just wish the empire builders at the NSA would care about something other than their own little power center. They knew this would happen - it always does. The NSA is probably the biggest security threat to the U.S. people[1] at this point, because they keep building concentrated, high-value targets and then lose control of them.

[1] Not to be confused with 'U.S. government interests'.


Am curious how and what exactly you blocked?! What precautions can be taken to make systems more secure?!


As usual, it depends on what exactly you have. Not all chips have the AMT enabled, for instance.

This is a useful document for understanding what exactly you're dealing with and what to do about it:

https://www.blackhat.com/docs/us-17/thursday/us-17-Evdokimov...


The BMC is listening on that IP, not the ME.


https://www.supermicro.com/products/nfo/IPMI.cfm IPMI / BMC != ME. Intel’s is basically the version of this that you can’t disable, that works through the same PHY (most BMCs have their own), that you’re not allowed to use. https://en.m.wikipedia.org/wiki/Intel_Management_Engine


I know that the BMC isn't the same as the ME, but in his case that's the BMC getting an IP and default web login for admin/admin. It's not the ME.

BMC doesn't always use a dedicated physical port, and it's commonly bridged in sideband to the other NICs on a server.


> Anything that has DMA enabled (e.g. Firewire or Thunderbolt) offers an external device direct access to the system RAM that is very difficult to defend against

IOMMU effectively solves the "DMA is completely broken" problem, as far as I'm aware.

Evil Maid attacks are mostly worrisome because even UEFI cannot protect you against some bootloader attacks (what if you disable UEFI or reflash the firmware and then have a bootloader that just looks like a UEFI boot). There are some usages of TPMs that seem quite promising (they revolve around doing a reverse-TOTP-style verification of your laptop to ensure that the TPM has certified the entire boot chain).

It's quite a hard problem, made significantly harder by the fact that every fucking hardware vendor seems to want to make our machines even less secure.


The problem is hard mostly because the entire architecture of the personal computer made absolutely no provision for security. Everything is patches upon patches to add superficial security. Fundamentally, a computer is dumb, it will perform whatever task it is told to do, and all our security measures revolve around stopping a malicious actor from telling the computer to do something 'bad'. Eventually, someone gets around the bouncer or in through an open window and here we are.


Oh so....every port on my laptop? Fuck Apple


It's a pity that law was passed that forced people to buy Apple products.


My point here was not about it coming from a USB JTAG, but by it targeting ME AND having full debugger access, meaning it isn't limited to reading nor to RAM/volatile memory.

Through this attack, they could compromise the ME longterm, which means the long accepted "nuke it from orbit" solution to security breach (unplug everything, format everything, start from scratch) still wouldn't be enough; that entire chip is done for. And 'using a hack to cleanup the hack' is still in the realm of cleaning up rather than start from scratch, it's not a solution for the same reason than cleaning up your comprised linux box is not one and you need to start from scratch.


I remember following a tutorial along the lines of:

https://www.howtogeek.com/56538/how-to-remotely-control-your...

A couple of years back, and being absolutely horrified at the remote management available on my second-hand lenovo t420s - including management over wlan.

Sure the features are gated by price/cpu "brand" - but I think it's safe to assume a) this is complex software and will have bugs with security implications b) once it's well enough understood - it seems likely it can be "upgraded" (similar to how you today can eg: replace the bios with coreboot).

The conclusion is that we need new platforms - perhaps power5 will help.


The physical access required for an evil maid attack is very different from the "physical access" required to give you a malicious USB device. In that sense this is a lot more scary. As are aforementioned Thunderbolt and Firewire attacks; without an IOMMU, those are a security nightmare too.


An important aspect of an evil maid attack is that it requires at least two instances of physical access, once before and once after use by an authorized user.

If the attack can he pulled off with only one time access, it’s worse than an evil maid attack.


People have been trying to break ME for years, some have been paying attention to it for a long time. There are just more people in the game now


It's by far not the first time that a highly-priviledged "security" component turns out to actually reduce security, because it is a large and gainful attack surface.

I can't help but to think of all those exploits that target anti-virus software.


"I know, let's examine some suspicious code in a highly-privileged process that the user explicitly trusts to keep them safe."

When you think about it, "it seemed like a good idea at the time" can explain most tragedies in human histories.


Well, a few hours ago we had a thread on HN about eradicating a whole specy of insects. And we had in comments intelligent educated people that though that "it seems like a good idea".

So if mass disruption of the very system that support your life can have supporters among a community composed of smart and actively debating people, "it seemed like a good idea at the time" probably happens every week at gov agencies.


Lots of things are done because there's a broad consensus opinion that it's a good idea. There is nothing intrinsically bad about that, and needless or baseless skepticism is often counterproductive and paralyzing, leading to inaction even in the face of widespread consensus.

What leads to failures, and I suspect happened at Intel, was that they mistook a very localized consensus for a broader one. There's a word for this, it's called "groupthink". A group of people can talk themselves into doing something very stupid (or evil) while still thinking they're doing the right thing, given enough time and motivation.

There was no widespread consensus, outside of Intel, that the IME was a good idea. If they had solicited opinions from outside their organization, they would doubtless have gotten horrified reactions. But they didn't, or if they did they must have dismissed those concerns, because they went through with the bad idea anyway.

The apparent secrecy with which they developed the IME is also a cause for alarm; groups of people who operate in isolation are particularly prone to groupthink, and so even if their motivations are good ones, the fact that they are working without continuous feedback from anyone on the outside raises the chances of a perverse outcome.


People usually won’t do something if they think it’s a bad idea. Tragedies begin with “it seemed like a good idea at the time” because everything does.


Except it never seemed like a good idea to anyone with a clue of IT security.


From what I understand, the justification wasn't about security, but rather about remote administration. Which is even worse, because that is ACTUALLY a backdoor, just one that is supposed to only be used by the legitimate owner of the machine.


It enables DRM technologies, too.


The vulnerability exists, wether someone reveals it to the public or not. These people found it with Intel keeping the working of the system under wraps as much as possible. You can imagine the kind of access available to people who did get to see the source code.

At least now that everyone can see the problem people can make informed decisions.


I would think those people are under constant threat of being kidnapped for their information


Given the complexity of the thing, they need a LOT of high profile people to create such a stuff. It's very unlikely none of them have been either:

- bribed

- threaten

- felt guilty about it and decided to make amend

My money is that exploits have been on the blacks market for a while now. We just have an official public demo now.

Rule of thumb: when something that catastrophic is made public, the worst already happened and you are late to the party.


Many people will now start to dig in. War is started and I hope somebody will find a way to totally remove/replace(with a stub) Intel ME before some critical vulnerability will be discovered in the Intel ME's network stack.

In white hats we trust :)


Here's hoping. Intel did a great job hiding the thing and making it all but impossible to remove (at present if you nuke the firmware, the CPU will totally fail to initialise. Thanks Intel!). That said, we're talking about an embedded device with very low-level code, and any 'disabling' code is probably going to be distributed in binary form. Stands to reason somewhere along the lines, someone is going to turn that around for their own benefit.

In tin-foil hats, we trust, more like!


I just get tired of being ridiculed and then 10 years later vindicated.

In Faraday cages we trust.


2013 was the greatest 'WE TOLD YOU SO' in history for the tin-foil-hat brigade...


Why 2013 specifically?



Yep, this exactly.


Imagine how Stallman feels.


There's a whole subreddit dedicated to this https://www.reddit.com/r/StallmanWasRight/


You'd think after being right again and again people would start to trust you. Or at least distrust entity that have a track record of behaving badly.

And yet...


me_cleaner already exists[1], and it takes advantage of several flaws in Intel ME's signing to remove large sections of the code thus neutering it. Some code still exists, but Intel ME cannot actually fully initialise on "cleaned" systems. Older machines used to have a bug where if you filled the first half of the Intel ME firmware with zeros the machine would boot but ME wouldn't start at all.

But yes, I hope that with this it'll be possible to completely remove the remaining few hundred kB of Intel ME code remaining.

[1]: https://github.com/corna/me_cleaner


Is this enough to block this attack? That is, is a "cleaned" system vulnerable to a USB device?


> That is, is a "cleaned" system vulnerable to a USB device?

of course it is, because the USB DCI attack is one level below the Intel ME. Even if it is deactivated via HAP, which basically simply puts the ME code into an infinite loop or a CPU halt state - both can be reversed by JTAG.


I don't know, because there is very little detail about what this attack is and how it works. It looks like they managed to thwart whatever protections exist in the USB DCI (Direct Connect Interface)[1] which is a debugging system for Intel chips.

If they have full debugger access to what's running in Intel ME then removing the code from the firmware probably doesn't make a difference (assuming they can run un-trusted code in that context). If they cannot write their own code and so an attack requires ROP gadgets then removing the code might make it harder (or impossible) to do, but I doubt it.

[1]: http://www2.lauterbach.com/pdf/directory.pdf#M8.newlink.DIR6...


DMA/Firewire over USB makes pretty much every systen vulnerable to USB attacks (ME aside.)


DMA-based attacks are blocked by the IOMMU, which is present in all modern machines (and has been for a few years). Linux has preferential enablement of DMA such that the IOMMU is initialised first, so even plugging in a device in early boot will not be able to exploit DMA.


Does it? To use the IOMMU for VFIO, I had to explicitly enable it via a kernel parameter.


Until they fix it. Or use something else.

Huge corporations backed up by gov agencies with a lot of time, money and skilled people VS a few people working for free because they believe they should. Not a fair fight.


Is it still true that USB devices can be used to execute code on a target's system without user interaction?

I thought this behavior disappeared ~10 years ago.


They shouldn't be able to. Firewire devices can because they used DMA without memory protection. I don't think Thunderbolt has the same flaw.

However there are bugs in USB stacks, especially now you can do so many alternate protocols over USB-C.

https://www.jefftk.com/p/malicious-usb-sticks

There's nothing fundamental in the USB spec that lets devices execute code on the host.


I think you're being overly paranoid. If the attacker has physical access to the machine, chances are you're compromised anyway, even before this vulnerability.


I don't think thats the right attitude. There's a difference between being able to open a machine to install malicious hardware / steal hdd's or just plugging in a generic USB stick to pawn it.

I know some of you might argue that even generic USB sticks can do damage and, whilst I agree, this attack is still a degree worse than most of those.

Thus far the most damage an unknown USB stick could do was type commands as a fake keyboard (visible to user) or exploit a driver vulnerability to silently cause mischief.

Correct me if I'm wrong, but those cases could still be trivially stopped by a security policy set by administrators disallowing unknown USB devices. (Of course, how many places would use this is another matter, but it's still very important for places where this does matter.)

This attack on the other hand would seem to be able to completely bypass your operating systems restrictions on USB ports.


From a technical perspective there is a difference now that this is public, but from a security stance, physical access is physical access.

Why? Security knows there are always bugs in software, and assumes they exist. Thanks to @h0t_max, the rest of us know this particular bug exists, but this bug has been around for a while - who's to say evil hax0rs didn't find this bug years ago and have been exploiting it since?

Or put another way - you say an unknown USB stick could exploit a driver vulnerability to silently cause mischief, and then claim that this is easily stopped if an administrator sets a security policy to disallow unknown USB devices. (I assume you mean a Windows GPO enforced policy or similar, and not a written social policy.) Who's to say the code that enforces the policy doesn't have bugs that's exploitable? What if the driver for a known USB stick has exploits?

Physical access is physical access, and while there are mitigations for the evil maid attack (like an encrypted drive and shutting down -not just suspending, when the machine is out of sight), there simply is no way around the fact that physical access is game over.


> while there are mitigations for the evil maid attack (like an encrypted drive and shutting down -not just suspending, when the machine is out of sight),

That mitigation is useless against Evil Maid. There are much more sophisticated mitigations (using a TPM to measure the boot, and then do something akin to TOTP in order to allow the user to actually verify the state of the machine) which actually could protect against Evil Maid almost completely (assuming you don't have something like Intel ME that cannot be verified by the TPM).

"Once you have physical access it's game over" is a very common response to these discussions, and I find it incredibly defeatist. Of course physical access means that the "clock is ticking" until your data is compromised, but sufficient protections can dampen the impact or increase the difficulty.

For example: IOMMU protects against DMA-based attacks, something that was impossible to protect against several years ago. This doesn't mean that someone cannot launch other attacks, but it does mean that the trivial "just plug anything into a USB port and you have DMA" attack is no longer possible.


Evil Maid refers to the broad spectrum of attacks a hypothetical maid could do with physical access and ranges from a drug addict simply looking to resell the laptop at a pawn shop, to a CIA agent, and not being defeatist involves differentiating between their objectives and capabilities in order to make a sensible decision.

Encrypted drive + shutdown is a defense against a specific Evil Maid attack, cold boot attacks. It is not a very expensive attack to run; for the cost of a can of compressed air, and a USB drive, anybody sophisticated can run this attack. https://en.wikipedia.org/wiki/Cold_boot_attack

Sorry to sound defeatist, but if you had been relying on IOMMU to save you, the trivial "plug anything into a USB port and you have CPU JTAG access" attack has always been possible. (Never mind that IOMMU implementations aren't guaranteed to be bug free.)

In the face of that, what do you do?

With this knowledge, all I really can do is stay up to date and patch-patch-patch. Have a travel Chromebook for leaving in hotel rooms, but ultimately I just have to know that it's not enough, especially against a CIA-grade Evil Maid, or an Evil Maid that's able to factor 4096-bit prime numbers. (That last one's not theoretical, either. It was revealed a few weeks ago that TPMs in Chromebooks and other hardware was generating weak keys, leading to cloud-factorable 4096-bit RSA keys.)

A less-sophisticated Evil Maid can still physically steal my laptop for pawning, and even if they can't get my data, I've still had my laptop stolen. Not-being-defeatist, I backup my data, although that has a totally different set of security concerns over the Internet.


The TPM is actually implemented as an Intel ME applet on a lot of PCs... >.<


Right, but there is a TPM pin-out standard -- so theoretically you could swap out the TPM of any device (which has a physical TPM obviously) with any other manufacturer's TPM and it would still "just work". While it might be implemented in Intel ME, there are a lot of laptops that have physical TPM chips.


Some manufacturers just don't pay more for an LPC or SPI-based TPM, and just use the fTPM one running as an ME applet (my Kaby Lake laptop does this)


> From a technical perspective there is a difference now that this is public, but from a security stance, physical access is physical access.

Access to a USB port is not physical access. USB is a network interface that is commonly used to connect host computers to small portable embedded systems, often tiny NAS units of other people also known as USB flash drives.


Yes, it's just like the example in the first season of House of Cards, where the journalist for some reason is conned into putting the USB into a server. That plot was really stretching to find a way to kill off a good character but still it shows how a "guest" could try to discreetly manipulate a system.


So you're saying things are so bad anyway that this one vulnerability probably doesn't make any difference?

This interpretation of "you're being overly paranoid" is new to me ;)


Come on, you can already catch aids, why do you worry about cancer ?


If the attacker has physical access to the machine, chances are you're compromised anyway, even before this vulnerability

Can you not see the difference between an attacker opening the case and stealing your HD, vs inserting USB key for a few seconds, then going away, and exploiting later at their leisure?


I wonder how long it will take until an attack over the network is found.



As I said above; I think I didn't make my point clear enough: my concern was not about it making it easier to be comprised, but about it making the clean up pretty impossible, on a hardware level.

Software do-over is a very well accepted solution (don't bother cleaning the rootkit, just format reinstall), but hardware do-over (change the cpu) is going to be a hard pill to swallow.


This was a problem even before Intel ME. Modern server motherboards (and several workstations) have a second Linux installation on your motherboard (known as a "baseboard management controller" or BMC) that cannot be removed. There have been many exploits found in the software running on BMCs, and if you want to "clean up" an infected server then you have to throw out the hardware if you want to be 100% certain.


The bmc situation is changing. There's an effort to support the ARM SoCs upstream, and there are a number of companies working on open source BMC stacks.

https://github.com/openbmc


For now. You need a first step before the next. I'm waiting for them to own ME remotely now. It's unlikely they won't succeed.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: