Intel ME confirmed for running minix

Thanks to google cache someone found that Intel's ME use Minix
CUCK license strikes again.
Then developers comes bitching about how the GPL is too restrictive.

See mailing list
mail.coreboot.org/pipermail/coreboot/2017-April/084055.html
mail.coreboot.org/pipermail/coreboot/2017-April/084078.html
mail.coreboot.org/pipermail/coreboot/2017-April/084079.html
Google cache
webcache.googleusercontent.com/search?q=cache:tCcU0NRwTnQJ:ftp://ftp.supermicro.com/CDR-X11-UP_1.10_for_Intel_X11_UP_platform/Intel/ME/Other_Licenses/Minix3_License.txt &cd=1&hl=de&ct=clnk&gl=de&lr=lang_de|lang_en
mail.coreboot.org/pipermail/coreboot/2017-April/084080.html

Other urls found in this thread:

archive.is/JXjan
en.wikipedia.org/wiki/ARC_(processor)
security-center.intel.com/advisory.aspx?intelid=INTEL-SA-00075&languageid=en-fr
meshcommander.com/meshcommander
mail.coreboot.org/pipermail/coreboot/2017-April/084055.html
archive.fo/WGJe0
mail.coreboot.org/pipermail/coreboot/2017-April/084078.html
archive.fo/gWvka
mail.coreboot.org/pipermail/coreboot/2017-April/084079.html
archive.fo/nWpkF
webcache.googleusercontent.com/search?q=cache:tCcU0NRwTnQJ:ftp://ftp.supermicro.com/CDR-X11-UP_1.10_for_Intel_X11_UP_platform/Intel/ME/Other_Licenses/Minix3_License.txt &cd=1&hl=de&ct=clnk&gl=de&lr=lang_de|lang_en
archive.fo/fbFQe
mail.coreboot.org/pipermail/coreboot/2017-April/084080.html
archive.fo/JXjan
webcache.googleusercontent.com/search?q=cache:tCcU0NRwTnQJ:ftp://ftp.supermicro.com/CDR-X11-UP_1.10_for_Intel_X11_UP_platform/Intel/ME/Other_Licenses/Minix3_License.txt &cd=1&hl=de&ct=clnk&gl=de&lr=lang_de|lang_en)
blog.ptsecurity.com/2017/04/intel-me-way-of-static-analysis.html
archive.fo/b08ga
recon.cx/2014/slides/Recon 2014 Skochinsky.pdf
archive.fo/34jbi
troopers.de/downloads/troopers17/TR17_ME11_Static.pdf
archive.fo/4WIVg
youtube.com/watch?v=2_aokrfcoUk
mail.coreboot.org/mailman/listinfo/coreboot
youtube.com/watch?v=j30RxSoayxg
twitter.com/NSFWRedditVideo

W H E W

That's the first time I've seen MINIX be used.

What's better as far as microkernels go, MINIX, HURD, QNX, or seL4?

archive.is/JXjan

You need to archive google cache, it will disappear eventually.

No, it was used a *lot* even in the 90's for university courses in CS. But that was older version, that fitted on single floppy disk and ran ok on a 286-class machine. Now all software is bloated shits, just as the hardware dangerously complicated, because that's "progress".

I agree that it's bloated but the reason it's bloated is because the hardware manufacturers are so eager to shill the next version of the hardware (plus the fact that they aren't sharing firmwares and manuals) that there's no optimization or understanding possible.
So instead of having a specific piece of hardware for 15+ years to develop and study on we get 15 different motherboards with little differences and we don't know what's running on them.

Well, too be fair the firmware that Intel ME uses is nowhere near as unusual as the architecture is uses;
en.wikipedia.org/wiki/ARC_(processor)

Its actually pretty impressive how resourceful Intels engineers are

I don't know QNX, but MINIX3 is the only thing that can be considered somewhat deployment ready. HURD in itself isn't a microkernel but a collection of heavily modified MACH microkernels. SeL4 will probably end up being the nicest of the bunch but is still in the early stages of development

Hurd isn't a microkernel but a collection of programs known as "servers" that are designed to work as a platform to replace the traditional Unix kernel. GNU Mach is a microkernel.

security-center.intel.com/advisory.aspx?intelid=INTEL-SA-00075&languageid=en-fr

LOL!!

The BSD licence was a mistake.

meshcommander.com/meshcommander

In an effort to make IntelĀ® AMT easier to use, to support cross platform and over the Internet usages, we are building a new version of the MDTK that is fully written in JavaScript. There are many advantages in doing this, but above all, it just makes a lot of sense. With HTML5 being very capable, it's a lot easier for administrators to use web applications that interact with Intel AMT within a browser, making the local installation of tools a thing of the past in some cases.

Below, we have a new version of Manageability Commander that is fully written in JavaScript and uses a new WSMAN stack, redirection stack along with remote desktop and remote terminal libraries. You can use this new version as-is or can download the source code and samples to build your own web based Intel AMT tools. Also look at the overview presentation and screen shots.

time to pack up boys, minix beat linux on the desktop.
praise BSD

s/uses/used/
it used arc, sparc(atom) and nowadays x86

nice

One can only dream.

Hate to shatter your dreams user but we're fucked no matter what.

...

buy a t60 and libreboot it.

Sure, then I'll just put it in a faraday cage and hope the 1,000 exploits in the hardware and software running on it that I don't know about don't leak anything important.

Instead of being cynical about everything, try developing sensible threat models. Do you have super secret business plans and data? For this kind of data, it's probably best to keep it on a computer that's never connected to the Internet. So what about doing stuff on the Internet? Dedicate an Internet facing computer that doesn't store any kind of data permanently but is reset every time you turn off that computer. How about Internet spying? You can work with Internet privacy tools like Tor, Freenet and GPG.

...

The only thing I know about QNX is that complete system with working web browser fits on 1,44 mb floppy

Damn! A lot of this wasn't archived!!! Fixed.

>mail.coreboot.org/pipermail/coreboot/2017-April/084055.html
archive.fo/WGJe0
>mail.coreboot.org/pipermail/coreboot/2017-April/084078.html
archive.fo/gWvka
>mail.coreboot.org/pipermail/coreboot/2017-April/084079.html
archive.fo/nWpkF
>webcache.googleusercontent.com/search?q=cache:tCcU0NRwTnQJ:ftp://ftp.supermicro.com/CDR-X11-UP_1.10_for_Intel_X11_UP_platform/Intel/ME/Other_Licenses/Minix3_License.txt &cd=1&hl=de&ct=clnk&gl=de&lr=lang_de|lang_en
archive.fo/fbFQe (made 2 weeks ago)
>mail.coreboot.org/pipermail/coreboot/2017-April/084080.html
archive.fo/JXjan

The page mail.coreboot.org/pipermail/coreboot/2017-April/084079.html contains references to other pages and documents....
---------------
Fun tidbit: The ME is running MINIX3 (confirmed by a file in the
Google cache: webcache.googleusercontent.com/search?q=cache:tCcU0NRwTnQJ:ftp://ftp.supermicro.com/CDR-X11-UP_1.10_for_Intel_X11_UP_platform/Intel/ME/Other_Licenses/Minix3_License.txt &cd=1&hl=de&ct=clnk&gl=de&lr=lang_de|lang_en)
-----------
....as mentioned before this was archived a couple of weeks back.....

------------
2017-04-26 22:47 GMT+02:00 Youness Alaoui :
> blog.ptsecurity.com/2017/04/intel-me-way-of-static-analysis.html
-------------------
archive.fo/b08ga (archived a week ago)
..and the page reference in the blog article: recon.cx/2014/slides/Recon 2014 Skochinsky.pdf is now archived at.....
archive.fo/34jbi
------------
> On Tue, Apr 25, 2017 at 10:38 AM, Shawn wrote:
>> troopers.de/downloads/troopers17/TR17_ME11_Static.pdf
-------------------
archive.fo/4WIVg (formatting is shit)
-----------
>> youtube.com/watch?v=2_aokrfcoUk
---------
Download this and share 237Mb in .webm
-------
>> mail.coreboot.org/mailman/listinfo/coreboot
> mail.coreboot.org/mailman/listinfo/coreboot
-----------------
...link to mailing list homepage. No value.

Both PDFs attached

any TL;DW for this?

How to Become the Sole Owner of Your PC
youtube.com/watch?v=j30RxSoayxg

is there a way to disable/limit it or do I have to get a different CPU?

You mean ME? Just use me_cleaner.

There's also a recent presentation on BootGuard which is preventing me_cleaner to work on machines

What CPUs affected?

That's not an actual use though.

Fuck you I spat out my kitkat

Have you actually had a look at it lately? its quite featured now, enough to build an OS on top of.

Well... its quite featured if you are on an ARM processor. x86 is a little bit behind as they are still doing the proofs for the x86 virtualisation extensions. They aren't in release yet but do exist.