> I think HN is uniquely positioned to show us the answer. Take a community of people with generally above average interest and/or knowledge in this stuff, and the comments are filled with
I think it's even more sinister: I would argue that a higher percentage of users on HN might be sworn to secrecy about any knowledge they might have anyway.
So you end up with very smart people who're either sworn to secrecy or who aren't; those who aren't are asking questions (and very few have answers, and those answers are partial or incorrect). Those who are can't answer them honestly or fully.
In the past discussions of the ME here and elsewhere, there have always been people making self-assured poo-pooing noises about what a trivial nonissue it is, make deceptive claims about exposure, and then dumb claims about how you can't trust any hardware. They never reply to particular questions that might point out how deceptive the arguments are.
I'm one of the people that claims you can't trust hardware. Care to elaborate why that's not the case. How does one trust a chip with 14nm transistors? Are you claiming that one can 'simply' decap the chip and examine it with a microscope on a Saturday night? How do I then trust that the chip I have in hand is of the same architecture as the one you decapped and examined?
You are of course correct that in the general case for threat models above a risk threshold, one cannot trust hardware. But that is not the argument under discussion. The argument being made is that it doesn't matter if the ME is a big fat target, because (f'instance) your NIC could also be a big fat target we just don't know about.
That is the argument I am asserting is dumb. And it is obviously dumb; in adversarial contests, you don't leave weaknesses exposed just because you might have other weaknesses[1]. It also ignores the presence of differential threats; I may not care about hypothetical compromised NICs because my use case my not require a network, but need anti-evil-maid defenses.
Bottom line: in the context of discussing whether or not the ME is dangerous in the general case, other potential hardware threats are irrelevant, and I believe the argument is one used to intentionally muddy the waters.
[1] Putting aside deeper strategies; I'm not going to argue about game theory here.
This is how I feel -> I've treated every device I've had for the last decade as if it were compromised, because who can prove to me otherwise? I certainly don't have the expertise to verify for myself.
You're only responding to the part after "dumb claims," right?
And your (valid) refutation of that part in no way implies spending less time reverse engineering and disabling ME, nor being less excited about this tweet. Correct?
This is what I think, too. My professional knowledge doesn't encompass anything like ME, but occasionally areas I am expert in do come up. Unfortunately I can't honestly do much more than just watch -- I'm afraid that I might give away things I shouldn't without realizing it.
I think it's even more sinister: I would argue that a higher percentage of users on HN might be sworn to secrecy about any knowledge they might have anyway.
So you end up with very smart people who're either sworn to secrecy or who aren't; those who aren't are asking questions (and very few have answers, and those answers are partial or incorrect). Those who are can't answer them honestly or fully.