Does VT-d protect against this?

124 views
Skip to first unread message

David Schissler

unread,
Nov 10, 2017, 6:45:07 PM11/10/17
to qubes-users
Researchers find almost EVERY computer with an Intel Skylake and above CPU can be owned via USB
https://thenextweb.com/security/2017/11/09/researchers-find-almost-every-computer-intel-skylake-cpu-can-owned-via-usb/?amp=1

pixel fairy

unread,
Nov 10, 2017, 10:40:28 PM11/10/17
to qubes-users
On Friday, November 10, 2017 at 3:45:07 PM UTC-8, David Schissler wrote:
> Researchers find almost EVERY computer with an Intel Skylake and above CPU can be owned via USB
> https://thenextweb.com/security/2017/11/09/researchers-find-almost-every-computer-intel-skylake-cpu-can-owned-via-usb/?amp=1

No.

You can read the actual paper here, https://www.ptsecurity.com/upload/corporate/ww-en/analytics/Where-theres-a-JTAG-theres-a-way.pdf

The update since then is access to IME.

Tai...@gmx.com

unread,
Nov 10, 2017, 10:49:53 PM11/10/17
to David Schissler, qubes-users
VT-d, intel's crappy IOMMU doesn't protect you from ME by design.
There is no disabling ME contrary to what some companies might say -
me_cleaner simply nerfs it.

If you want a PC without black box supervisor processors here are your
open source firmware options:
Ultra high performance:
TALOS 2 (POWER 9, so no qubes ATM unless you compile it yourself) -
price is appropriate for high end server hardware (for the same
performance x86-64 would cost more)
Will be RYF upon release

Performance:
KGPE-D16
KCMA-D8
Can play games in a VM via IOMMU-GFX, with the best CPU's equal to FX-8310.
They support OpenBMC for open source remote management.
I use these and they're great.

Laptop:
Lenovo G505S (needs blob for video/power management, but can be replaced
with free code as there is no hardware code signing enforcement
anti-features)
Novena (needs blob for 3D video accel)

Yuraeitha

unread,
Nov 11, 2017, 6:27:32 AM11/11/17
to qubes-users

The sheer fact that there are no massive uprisings against this, is simply astonishing on its own. It is so invasive into human rights and people's right to freedom, privacy and free speech. Not to mention to risk it poses towards the future of our democracies, or making dictatorships significantly worse than they are today.

In the name of terror, lets slowly erode and destroy democracy and all its values, bit by bit, year by year, until it collapses.
Sounds like a good deal, lets keep this facde up that it's needed to fight terrorism, it's definitely going to end well.

How on earth are these people getting away these crimes against humanity? It's truly mindblowing.

Tai...@gmx.com

unread,
Nov 11, 2017, 3:52:08 PM11/11/17
to Yuraeitha, qubes-users
On 11/11/2017 06:27 AM, Yuraeitha wrote:

> How on earth are these people getting away these crimes against humanity? It's truly mindblowing.
People keep buying their crap, or giving them their data[1], and the MSS
has paid off all the right people. (ME as an No Such Agency project is
too simple, it is probably much more than that)
When you use gmail you are supporting googles AI research which will
eventually put tens of millions out of work, every time you solve a
re-captcha you enhance their machine learning algorithms.

You are probably sitting in a chair and typing on a keyboard made in
china by some large company? why? was saving a small amount of money
worth putting your countrymen out of work? eventually putting you out of
work? helping the PRC?

The best thing you can do to stick up for yourself is stop buying their
cheap crap, it is as they say "vote with your wallet".

[1](ex: you with gmail, STOP USING IT - there are alternatives such as
paying a massive $5/mo for email where you get tech support no spying
and a professional email address without many letters and numbers after
it as all the good ones are gone, can also use your own domain name too
which is super easy)

cooloutac

unread,
Nov 13, 2017, 9:16:26 AM11/13/17
to qubes-users
On Friday, November 10, 2017 at 6:45:07 PM UTC-5, David Schissler wrote:
> Researchers find almost EVERY computer with an Intel Skylake and above CPU can be owned via USB
> https://thenextweb.com/security/2017/11/09/researchers-find-almost-every-computer-intel-skylake-cpu-can-owned-via-usb/?amp=1

make sure you install latest bios.

cooloutac

unread,
Nov 13, 2017, 9:20:40 AM11/13/17
to qubes-users
On Friday, November 10, 2017 at 6:45:07 PM UTC-5, David Schissler wrote:
> Researchers find almost EVERY computer with an Intel Skylake and above CPU can be owned via USB
> https://thenextweb.com/security/2017/11/09/researchers-find-almost-every-computer-intel-skylake-cpu-can-owned-via-usb/?amp=1

Maybe if plugged in with o/s running. Not if plugged in before. It does not even need an os to be running.

Reply all
Reply to author
Forward
0 new messages