Skip to content

Comment on EU "Chat Control" and Mandatory Client Side Scanningparent

Comments

Are you sure the hardware you are going to use for firewall purposes is not biased towards letting the traffic from/to Intel ME to be unnoticed? What filters are you going to set?

You can install open source software on a PC from the early 2000s that predates the Intel Management Engine and use it as a firewall.

Then you use default deny and allow only e.g. a VPN connection.

What if your computer is still accessible for Intel ME surveillance because the VPN server is also Intel ME and they would negotiate somehow to keep having your Intel ME instance an ability to phone home? Is in possible to have a VPN provider which guarantees not having any Intel machines on the network?

What if your computer is still accessible for Intel ME surveillance because the VPN server is also Intel ME and they would negotiate somehow to keep having your Intel ME instance an ability to phone home?

This would require the hardware backdoor to be aware of and integrate with the specific VPN that you used, which could be a version of the code published after the hardware shipped.

Is in possible to have a VPN provider which guarantees not having any Intel machines on the network?

Irrelevant unless the code on your side could hook the VPN, though of course you could.

The better attack would be to have the compromised firmware send its packets using the addresses and ports of some existing connection regardless of its contents, and then have a compromised ISP read them. But even that could be detected by logging the packets at the clean firewall. If it records any that aren't a part of the VPN connection then you've got yourself a rat and a scandal.

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.