• Welcome to TechPowerUp Forums, Guest! Please check out our forum guidelines for info related to our community.

Intel to Deploy Management Engine Lock to Prevent Disabling, Rollback

Raevenlord

News Editor
Joined
Aug 12, 2016
Messages
3,755 (1.33/day)
Location
Portugal
System Name The Ryzening
Processor AMD Ryzen 9 5900X
Motherboard MSI X570 MAG TOMAHAWK
Cooling Lian Li Galahad 360mm AIO
Memory 32 GB G.Skill Trident Z F4-3733 (4x 8 GB)
Video Card(s) Gigabyte RTX 3070 Ti
Storage Boot: Transcend MTE220S 2TB, Kintson A2000 1TB, Seagate Firewolf Pro 14 TB
Display(s) Acer Nitro VG270UP (1440p 144 Hz IPS)
Case Lian Li O11DX Dynamic White
Audio Device(s) iFi Audio Zen DAC
Power Supply Seasonic Focus+ 750 W
Mouse Cooler Master Masterkeys Lite L
Keyboard Cooler Master Masterkeys Lite L
Software Windows 10 x64
It's been an interesting month for users as we've discovered that the most widely-used OS in the world could be one most of us had never even heard anything about before. Intel's Management Engine, a full-fledged computer inside Intel CPUs, runs on MINIX, and after it was outed that Intel's CPUs ran on it, multiple issues have been found with the approach, which has moved Intel towards outing a detection tool.

Intel is seemingly poising to move towards a full hardware lock of the Management Engines' capabilities, thus ensuring it can't be disabled. And even if Intel does send out firmware fixes for its already deployed CPUs with ME integration, the fact remains that the memory pool where the firmware is written is, well, re-writable - given enough access, miscreants could simply re-flash the ME to an earlier, vulnerable version, and thus acquire God Mode access to a victim's computer. To tackle both issues, Intel is moving towards a hardware lock of their ME.





A recent confidential Intel Technical Advisory posted to GitHub stated that starting with ME version 12, the chip's Security Version Number (SVN), which gets incremented with updates to prevent rollbacks, "will be saved permanently in Field Programmable Fuses (FPFs) as a means to mitigate physically downgrading Intel ME [firmware] to a lower SVN." FPFs, once set, become read-only memory (ROM) and can't be so easily altered. providing Intel with a way to validate firmware versions in order to avoid a version rollback.

However, Purism, a company which has made its business to sell privacy-focused Librem laptops in which the Intel Management Engine has been (mostly) disabled, said that while the move was bound to improve security, it didn't fix the fundamental flaws in Intel's ME integration. Purism founder Todd Weaver told The Register that "The ME [Management Engine] hardware still ships on all Intel CPUs; the ME firmware (where this Positive Technologies security exploit is at) is still required by Intel," he said. "If users do not want the ME at all, there is no current Intel based CPU option."



View at TechPowerUp Main Site
 
Joined
Aug 20, 2007
Messages
20,787 (3.41/day)
System Name Pioneer
Processor Ryzen R9 7950X
Motherboard GIGABYTE Aorus Elite X670 AX
Cooling Noctua NH-D15 + A whole lotta Sunon and Corsair Maglev blower fans...
Memory 64GB (4x 16GB) G.Skill Flare X5 @ DDR5-6000 CL30
Video Card(s) XFX RX 7900 XTX Speedster Merc 310
Storage 2x Crucial P5 Plus 2TB PCIe 4.0 NVMe SSDs
Display(s) 55" LG 55" B9 OLED 4K Display
Case Thermaltake Core X31
Audio Device(s) TOSLINK->Schiit Modi MB->Asgard 2 DAC Amp->AKG Pro K712 Headphones or HDMI->B9 OLED
Power Supply FSP Hydro Ti Pro 850W
Mouse Logitech G305 Lightspeed Wireless
Keyboard WASD Code v3 with Cherry Green keyswitches + PBT DS keycaps
Software Gentoo Linux x64
Antirollback qfuses, essentially. You simply can't downgrade. It's not new, they've been doing it in phones for some time. Very difficult to defeat, if done right.

I still feel the whole world would be more secure without the management engine "security features" however. AMD's PSP is no better. These things should all be removed.
 
Joined
Mar 23, 2016
Messages
4,839 (1.64/day)
Processor Ryzen 9 5900X
Motherboard MSI B450 Tomahawk ATX
Cooling Cooler Master Hyper 212 Black Edition
Memory VENGEANCE LPX 2 x 16GB DDR4-3600 C18 OCed 3800
Video Card(s) XFX Speedster SWFT309 AMD Radeon RX 6700 XT CORE Gaming
Storage 970 EVO NVMe M.2 500 GB, 870 QVO 1 TB
Display(s) Samsung 28” 4K monitor
Case Phantek Eclipse P400S (PH-EC416PS)
Audio Device(s) EVGA NU Audio
Power Supply EVGA 850 BQ
Mouse SteelSeries Rival 310
Keyboard Logitech G G413 Silver
Software Windows 10 Professional 64-bit v22H2
Correction @Raevenlord: Minix is running from within the Platform Controller Hub's on die Intel Quark or ARC for Broadwell, and earlier.
 
Joined
Mar 15, 2008
Messages
1,110 (0.19/day)
lol So Intel's "solution" to the problem is to make future ME's not being able to be stoped in any way or form? This, to make you feel "safer" right? :D
 
Joined
Feb 14, 2012
Messages
2,323 (0.52/day)
System Name msdos
Processor 8086
Motherboard mainboard
Cooling passive
Memory 640KB + 384KB extended
Video Card(s) EGA
Storage 5.25"
Display(s) 80x25
Case plastic
Audio Device(s) modchip
Power Supply 45 watts
Mouse serial
Keyboard yes
Software disk commander
Benchmark Scores still running
But if your modded bios code never checks the fuses ...
 

Aquinus

Resident Wat-man
Joined
Jan 28, 2012
Messages
13,147 (2.94/day)
Location
Concord, NH, USA
System Name Apollo
Processor Intel Core i9 9880H
Motherboard Some proprietary Apple thing.
Memory 64GB DDR4-2667
Video Card(s) AMD Radeon Pro 5600M, 8GB HBM2
Storage 1TB Apple NVMe, 4TB External
Display(s) Laptop @ 3072x1920 + 2x LG 5k Ultrafine TB3 displays
Case MacBook Pro (16", 2019)
Audio Device(s) AirPods Pro, Sennheiser HD 380s w/ FIIO Alpen 2, or Logitech 2.1 Speakers
Power Supply 96w Power Adapter
Mouse Logitech MX Master 3
Keyboard Logitech G915, GL Clicky
Software MacOS 12.1
But if your modded bios code never checks the fuses ...
That depends on how it's implemented. You could have a series of fuses that cause entire segments of memory to become read-only by doing something like shorting out certain command lines going to memory that are responsible for doing writes because there are certain parts of memory circuits that can be physically shorted or broken to cause memory to become read-only at the hardware level. Something like this would allow a developer to program a region of memory up until the point where you want to lock it and prevent changes. It's also not a terrible idea either because if there is a change you want to make but, you're not entirely certain if you want it to be permanent or not, you can just not lock that region of memory and if that assumption changes or your boss tells you to flick the switch, you add a tiny bit of code and the next time it runs, it will do its magic and that memory segment will be untouchable.

It's a bit excessive but, in this day and age, I'm not at all surprised. There is a huge benefit to doing something like this because it could allow a manufacturer to even hard-code in memory information about the board is belongs to, like serial number and such. Information about the system and constants that aren't ever going to change (from their perspective.) It's not something we want but, from the perspective of Intel, it makes perfect sense.
 
Joined
Mar 16, 2017
Messages
211 (0.08/day)
Location
behind you
Processor Threadripper 1950X (4.0 GHz OC)
Motherboard ASRock X399 Professional Gaming
Cooling Enermax Liqtech TR4
Memory 48GB DDR4 2934MHz
Video Card(s) Nvidia GTX 1080, GTX 660TI
Storage 2TB Western Digital HDD, 500GB Samsung 850 EVO SSD, 280GB Intel Optane 900P
Display(s) 2x 1920x1200
Power Supply Cooler Master Silent Pro M (1000W)
Mouse Logitech G602
Keyboard Corsair K70 MK.2
Software Windows 10
That depends on how it's implemented. You could have a series of fuses that cause entire segments of memory to become read-only by doing something like shorting out certain command lines going to memory that are responsible for doing writes because there are certain parts of memory circuits that can be physically shorted or broken to cause memory to become read-only at the hardware level. Something like this would allow a developer to program a region of memory up until the point where you want to lock it and prevent changes.

They've been doing this in the microcontroller world forever, they're actually called 'lock bits' (at least by Atmel). They are used to prevent program code from being read or rewritten, very useful if you have competitors who want to copy your stuff.
 
Last edited:
Joined
Aug 20, 2007
Messages
20,787 (3.41/day)
System Name Pioneer
Processor Ryzen R9 7950X
Motherboard GIGABYTE Aorus Elite X670 AX
Cooling Noctua NH-D15 + A whole lotta Sunon and Corsair Maglev blower fans...
Memory 64GB (4x 16GB) G.Skill Flare X5 @ DDR5-6000 CL30
Video Card(s) XFX RX 7900 XTX Speedster Merc 310
Storage 2x Crucial P5 Plus 2TB PCIe 4.0 NVMe SSDs
Display(s) 55" LG 55" B9 OLED 4K Display
Case Thermaltake Core X31
Audio Device(s) TOSLINK->Schiit Modi MB->Asgard 2 DAC Amp->AKG Pro K712 Headphones or HDMI->B9 OLED
Power Supply FSP Hydro Ti Pro 850W
Mouse Logitech G305 Lightspeed Wireless
Keyboard WASD Code v3 with Cherry Green keyswitches + PBT DS keycaps
Software Gentoo Linux x64
But if your modded bios code never checks the fuses ...

The idea is the unupdatable bootloader checks a cryptographically signed bios code version, not the other way around, thus no real way to "mod" it
 
Last edited:
Joined
Mar 16, 2017
Messages
211 (0.08/day)
Location
behind you
Processor Threadripper 1950X (4.0 GHz OC)
Motherboard ASRock X399 Professional Gaming
Cooling Enermax Liqtech TR4
Memory 48GB DDR4 2934MHz
Video Card(s) Nvidia GTX 1080, GTX 660TI
Storage 2TB Western Digital HDD, 500GB Samsung 850 EVO SSD, 280GB Intel Optane 900P
Display(s) 2x 1920x1200
Power Supply Cooler Master Silent Pro M (1000W)
Mouse Logitech G602
Keyboard Corsair K70 MK.2
Software Windows 10
Joined
Aug 20, 2007
Messages
20,787 (3.41/day)
System Name Pioneer
Processor Ryzen R9 7950X
Motherboard GIGABYTE Aorus Elite X670 AX
Cooling Noctua NH-D15 + A whole lotta Sunon and Corsair Maglev blower fans...
Memory 64GB (4x 16GB) G.Skill Flare X5 @ DDR5-6000 CL30
Video Card(s) XFX RX 7900 XTX Speedster Merc 310
Storage 2x Crucial P5 Plus 2TB PCIe 4.0 NVMe SSDs
Display(s) 55" LG 55" B9 OLED 4K Display
Case Thermaltake Core X31
Audio Device(s) TOSLINK->Schiit Modi MB->Asgard 2 DAC Amp->AKG Pro K712 Headphones or HDMI->B9 OLED
Power Supply FSP Hydro Ti Pro 850W
Mouse Logitech G305 Lightspeed Wireless
Keyboard WASD Code v3 with Cherry Green keyswitches + PBT DS keycaps
Software Gentoo Linux x64
Joined
Aug 17, 2017
Messages
274 (0.11/day)
Your just guessing and don't know for sure. Why not tell the truth and say so.

Because, the owner of gamersnexus .net who knows way more than various computer hardware, more than you or I, said ME started with Skylake

So, now you will both be insulted and ask me why then did i ask here. Because I wanted to see how much crap you both talk.

OSdevr said to my question "No, ME has been around for about 10 years."

then provide proof.
 

TheLostSwede

News Editor
Joined
Nov 11, 2004
Messages
16,075 (2.26/day)
Location
Sweden
System Name Overlord Mk MLI
Processor AMD Ryzen 7 7800X3D
Motherboard Gigabyte X670E Aorus Master
Cooling Noctua NH-D15 SE with offsets
Memory 32GB Team T-Create Expert DDR5 6000 MHz @ CL30-34-34-68
Video Card(s) Gainward GeForce RTX 4080 Phantom GS
Storage 1TB Solidigm P44 Pro, 2 TB Corsair MP600 Pro, 2TB Kingston KC3000
Display(s) Acer XV272K LVbmiipruzx 4K@160Hz
Case Fractal Design Torrent Compact
Audio Device(s) Corsair Virtuoso SE
Power Supply be quiet! Pure Power 12 M 850 W
Mouse Logitech G502 Lightspeed
Keyboard Corsair K70 Max
Software Windows 10 Pro
Benchmark Scores https://valid.x86.fr/5za05v
Your just guessing and don't know for sure. Why not tell the truth and say so.

Because, the owner of gamersnexus .net who knows way more than various computer hardware, more than you or I, said ME started with Skylake

So, now you will both be insulted and ask me why then did i ask here. Because I wanted to see how much crap you both talk.

OSdevr said to my question "No, ME has been around for about 10 years."

then provide proof.

Since 2008 -
https://en.m.wikipedia.org/wiki/Intel_Management_Engine
 
Joined
Aug 17, 2017
Messages
274 (0.11/day)
hmmm, I wonder why gamersnexus was on video stating ME started with Skylake, back about a month or so ago when the story was first making its rounds.

my apologies, ill go eat my words now... pass the salt.
 
Joined
Jul 16, 2016
Messages
275 (0.10/day)
Location
Rochester, NY
System Name Xbox Series S
Processor AMD Zen2 8 core 3.6 GHz
Memory 10GB GDDR6
Video Card(s) RDNA2 with 20 CUs
Storage 512Gb SSD NVMe Internal + 8TB WD Black USB External
Display(s) Acer VG270U P 2k
Joined
Mar 16, 2017
Messages
211 (0.08/day)
Location
behind you
Processor Threadripper 1950X (4.0 GHz OC)
Motherboard ASRock X399 Professional Gaming
Cooling Enermax Liqtech TR4
Memory 48GB DDR4 2934MHz
Video Card(s) Nvidia GTX 1080, GTX 660TI
Storage 2TB Western Digital HDD, 500GB Samsung 850 EVO SSD, 280GB Intel Optane 900P
Display(s) 2x 1920x1200
Power Supply Cooler Master Silent Pro M (1000W)
Mouse Logitech G602
Keyboard Corsair K70 MK.2
Software Windows 10
hmmm, I wonder why gamersnexus was on video stating ME started with Skylake, back about a month or so ago when the story was first making its rounds.

my apologies, ill go eat my words now... pass the salt.

:mad:

If I'm not mistaken Intel switched to an x86 core with Skylake and were using a different architecture before. Why they didn't use an x86 core to begin with I have no idea.

EDIT: Can't find a source saying they switched architectures with Skylake but they did at least change a great deal of it according to me_cleaner. Also Libreboot agrees that it began in 2006 on the northbridge and was moved onto the CPU with Nehalem (aka the first of the Core i series).
 
Last edited:
Joined
Apr 18, 2016
Messages
184 (0.06/day)
MINIX OS inside of each intel cpu biggest designed backdoor nobody bats and eye

Finded keylogger in Synaptics Touchpad keyboard driver

 

Frick

Fishfaced Nincompoop
Joined
Feb 27, 2006
Messages
18,934 (2.85/day)
Location
Piteå
System Name Black MC in Tokyo
Processor Ryzen 5 5600
Motherboard Asrock B450M-HDV
Cooling Be Quiet! Pure Rock 2
Memory 2 x 16GB Kingston Fury 3400mhz
Video Card(s) XFX 6950XT Speedster MERC 319
Storage Kingston A400 240GB | WD Black SN750 2TB |WD Blue 1TB x 2 | Toshiba P300 2TB | Seagate Expansion 8TB
Display(s) Samsung U32J590U 4K + BenQ GL2450HT 1080p
Case Fractal Design Define R4
Audio Device(s) Line6 UX1 + some headphones, Nektar SE61 keyboard
Power Supply Corsair RM850x v3
Mouse Logitech G602
Keyboard Cherry MX Board 1.0 TKL Brown
VR HMD Acer Mixed Reality Headset
Software Windows 10 Pro
Benchmark Scores Rimworld 4K ready!
hmmm, I wonder why gamersnexus was on video stating ME started with Skylake, back about a month or so ago when the story was first making its rounds.

my apologies, ill go eat my words now... pass the salt.

I'm thinking it was because the story started out that way, essentially, and he didn't fact check it.
 
Joined
Aug 20, 2007
Messages
20,787 (3.41/day)
System Name Pioneer
Processor Ryzen R9 7950X
Motherboard GIGABYTE Aorus Elite X670 AX
Cooling Noctua NH-D15 + A whole lotta Sunon and Corsair Maglev blower fans...
Memory 64GB (4x 16GB) G.Skill Flare X5 @ DDR5-6000 CL30
Video Card(s) XFX RX 7900 XTX Speedster Merc 310
Storage 2x Crucial P5 Plus 2TB PCIe 4.0 NVMe SSDs
Display(s) 55" LG 55" B9 OLED 4K Display
Case Thermaltake Core X31
Audio Device(s) TOSLINK->Schiit Modi MB->Asgard 2 DAC Amp->AKG Pro K712 Headphones or HDMI->B9 OLED
Power Supply FSP Hydro Ti Pro 850W
Mouse Logitech G305 Lightspeed Wireless
Keyboard WASD Code v3 with Cherry Green keyswitches + PBT DS keycaps
Software Gentoo Linux x64
MINIX OS inside of each intel cpu biggest designed backdoor nobody bats and eye

Finded keylogger in Synaptics Touchpad keyboard driver


I think you've been missing quite a few comments. ME and AMS PSP are really frickin unpopular.

So are keyloggers, and they should be.
 
Joined
Jul 19, 2008
Messages
1,180 (0.20/day)
Location
Australia
Processor Intel i7 4790K
Motherboard Asus Z97 Deluxe
Cooling Thermalright Ultra Extreme 120
Memory Corsair Dominator 1866Mhz 4X4GB
Video Card(s) Asus R290X
Storage Samsung 850 Pro SSD 256GB/Samsung 840 Evo SSD 1TB
Display(s) Samsung S23A950D
Case Corsair 850D
Audio Device(s) Onboard Realtek
Power Supply Corsair AX850
Mouse Logitech G502
Keyboard Logitech G710+
Software Windows 10 x64
There was no IME installation drivers on Nehalem, at least with socket 1366, consumer boards. It may have been onboard without the need for drivers but the first platform I used with IME installation drivers was Ivy bridge. They may have started with IME drivers on socket 1156 Sandy Bridge CPUs. I skipped Sandy Bridge so I cant say but its around that time.

Edit: I just looked it up Sandy bridge was the first mainstream/consumer platform with IME installation drivers,
 
Joined
Mar 15, 2008
Messages
1,110 (0.19/day)
There was no IME installation drivers on Nehalem, at least with socket 1366, consumer boards. It may have been onboard without the need for drivers but the first platform I used with IME installation drivers was Ivy bridge. They may have started with IME drivers on socket 1156 Sandy Bridge CPUs. I skipped Sandy Bridge so I cant say but its around that time.

Edit: I just looked it up Sandy bridge was the first mainstream/consumer platform with IME installation drivers,

I don't understand why nobody compiles some real data on which systems had the ME processor in them. I've been looking everywhere to see if the x58 chipset had ME but I can't find anything conclusive. All I can find is that the other chipsets meant for enterprise from that era have it but I can't find anything on this one. I still have an i7 920 system laying around somewhere and I wanna see if I can trust it or not...
 
Joined
Aug 20, 2007
Messages
20,787 (3.41/day)
System Name Pioneer
Processor Ryzen R9 7950X
Motherboard GIGABYTE Aorus Elite X670 AX
Cooling Noctua NH-D15 + A whole lotta Sunon and Corsair Maglev blower fans...
Memory 64GB (4x 16GB) G.Skill Flare X5 @ DDR5-6000 CL30
Video Card(s) XFX RX 7900 XTX Speedster Merc 310
Storage 2x Crucial P5 Plus 2TB PCIe 4.0 NVMe SSDs
Display(s) 55" LG 55" B9 OLED 4K Display
Case Thermaltake Core X31
Audio Device(s) TOSLINK->Schiit Modi MB->Asgard 2 DAC Amp->AKG Pro K712 Headphones or HDMI->B9 OLED
Power Supply FSP Hydro Ti Pro 850W
Mouse Logitech G305 Lightspeed Wireless
Keyboard WASD Code v3 with Cherry Green keyswitches + PBT DS keycaps
Software Gentoo Linux x64
There was no IME installation drivers on Nehalem, at least with socket 1366, consumer boards. It may have been onboard without the need for drivers but the first platform I used with IME installation drivers was Ivy bridge. They may have started with IME drivers on socket 1156 Sandy Bridge CPUs. I skipped Sandy Bridge so I cant say but its around that time.

Edit: I just looked it up Sandy bridge was the first mainstream/consumer platform with IME installation drivers,

My brothers x58 system had management engine drivers IIRC, board was a dx58so2.

Either way, it's present on anything newer than or equal to a core 2. Whether or not there are drivers, it's there.
 

eidairaman1

The Exiled Airman
Joined
Jul 2, 2007
Messages
40,435 (6.58/day)
Location
Republic of Texas (True Patriot)
System Name PCGOD
Processor AMD FX 8350@ 5.0GHz
Motherboard Asus TUF 990FX Sabertooth R2 2901 Bios
Cooling Scythe Ashura, 2×BitFenix 230mm Spectre Pro LED (Blue,Green), 2x BitFenix 140mm Spectre Pro LED
Memory 16 GB Gskill Ripjaws X 2133 (2400 OC, 10-10-12-20-20, 1T, 1.65V)
Video Card(s) AMD Radeon 290 Sapphire Vapor-X
Storage Samsung 840 Pro 256GB, WD Velociraptor 1TB
Display(s) NEC Multisync LCD 1700V (Display Port Adapter)
Case AeroCool Xpredator Evil Blue Edition
Audio Device(s) Creative Labs Sound Blaster ZxR
Power Supply Seasonic 1250 XM2 Series (XP3)
Mouse Roccat Kone XTD
Keyboard Roccat Ryos MK Pro
Software Windows 7 Pro 64
Isn't this related to the SMBus/PMBus?
 
Joined
Sep 7, 2017
Messages
3,244 (1.34/day)
System Name Grunt
Processor Ryzen 5800x
Motherboard Gigabyte x570 Gaming X
Cooling Noctua NH-U12A
Memory Corsair LPX 3600 4x8GB
Video Card(s) Gigabyte 6800 XT (reference)
Storage Samsung 980 Pro 2TB
Display(s) Samsung CFG70, Samsung NU8000 TV
Case Corsair C70
Power Supply Corsair HX750
Software Win 10 Pro
I think you've been missing quite a few comments. ME and AMS PSP are really frickin unpopular.

So are keyloggers, and they should be.

Unpopular, but it's not going to affect the typical user either way. Still, everyone should have options. These are PCs, after all.
 
Joined
Aug 17, 2017
Messages
274 (0.11/day)
I really don't want to move back to AMD product for a number of reasons, but this issue is really me make me re-think doing so. Then again, I dont have much of anything to hide, it boils down to principle I suppose. I just don't like the idea Intel has implemented this without disclosure from the start. That said, I am very curious what kind of performance increase Intel's 10nm will have. Even if it was just another 10-15% over coffee lake, I would be satisfied, because I am still using a old i7 870, but it works great! I suppose ME wont go away? I do wonder will AMD implement a version of ME?
 
Top