kernel-hardening.lists.openwall.com archive mirror
 help / color / mirror / Atom feed
* [kernel-hardening] ME and PSP
@ 2017-09-06 18:37 Sandy Harris
  2017-09-07  3:06 ` Shawn
  0 siblings, 1 reply; 3+ messages in thread
From: Sandy Harris @ 2017-09-06 18:37 UTC (permalink / raw)
  To: kernel-hardening

Recently a few things have been revealed about how to disable the
Intel Management Engine (ME).

http://blog.ptsecurity.com/2017/08/disabling-intel-me.html
https://www.theregister.co.uk/2017/08/29/intel_management_engine_can_be_disabled/

I have not seen anything on disabling the similar AMD feature called
PSP. Either appears to be a huge security hazard -- a device you have
little choice but to trust but that you have little control over, that
operates below the level of the main CPU & OS, that has access to
everything & that is Turing complete so it can do anything.

By the time a hardened kernel loads, it may be too late to prevent ME
entirely, but are there other things the kernel could do? Issue a
syslog warning? Monitor ME activity somehow? Restrict its access to
the network so at least external attacks are blocked?

There are several different utilities to reduce ME danger, though I
have not looked at details & I have the impression most do not disable
it completely. Will current hardened kernels run on a system with ME
disabled? Is that tested?

The best summary of the issue I have seen -- though it is neither
up-to-date nor devoted to only the one issue is:
https://blog.invisiblethings.org/papers/2015/x86_harmful.pdf

There has been discussion on the Qubes users list:
https://groups.google.com/forum/#!forum/qubes-users

The only plausible solutions suggested there boil down to not using
recent x86 chips at all. Either use older Intel/AMD parts without the
feature or go to IBM Power CPUs.

No-one has mentioned ARM in that discussion & I am not sure where they
would fit in.

^ permalink raw reply	[flat|nested] 3+ messages in thread

end of thread, other threads:[~2017-09-07  4:30 UTC | newest]

Thread overview: 3+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2017-09-06 18:37 [kernel-hardening] ME and PSP Sandy Harris
2017-09-07  3:06 ` Shawn
2017-09-07  4:30   ` [kernel-hardening] Re: [coreboot] " ron minnich

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for NNTP newsgroup(s).