7 ms·
How to verify boot firmware integrity if you prioritize neutralizing Intel ME?
It was difficult to make a title because of char limit.
when you use me_cleaner to neutralize intel ME, it also removes TPM. TPM is required for boot verification technologies like Heads or AEM. So you can't use Heads/AEM and me_cleaner, you have to choose one and in this case we choose to prioritize me_cleaner.
Heads: https://osresearch.net/
me_cleaner: https://github.com/corna/me_cleaner
Then the question becomes, what do you personally do to protect your computers boot firmware? There are many ways you can do that such as the popular glitter nailpolish technique. The problem with that technique is you need a good camera with a firm stand so you can take the before and after pictures at the exact same distance and place to compare them. It's also quite a lot of work to do that every single time you leave your computer which could be several times every day. AEM is also most popular to use when traveling and when traveling, having all that extra equipment with you is a problem.
What else? Maybe a secret camera without any internet connection capability which you can place somewhere in the room with the computer and that way you can know if someone was inside the room and if they did anything with the computer. The camera would have to record to a local storage like a micro sd card and you overwrite all data on that card every day so you won't need too much storage capacity. And maybe the camera only activates on movement triggered then its even easier to quickly check if there's any video when you come back to your computer. You would also need to be sure that the adversary doesnt replace the camera so you dont know its not your camera anymore or if they can erase the video files before they leave like hackers who erase logs. What do you think about that?
Another idea is a container for the computer. The container can of course be destroyed easily but then you will at least know they did something with the computer. But you would need a container that the evil maid can't go get a duplicate of or have one manufactured so they can replace the container after destroying original one.
Same problem with a sticker on the screws to open up the laptop, they could get a duplicate sticker to replace yours. I also heard there are ways to remove a sticker and then put it back again.
Practically I think camera technique is best to use on daily basis because its effective and relatively simple but maybe in some situations you have to gamble by using a container or sticker.
And then you also need to check your firmware once in a while even if you don't suspect anything. I'm not sure the best way to do that because I've read it is practically impossible to know if rom has been maliciously modified. So its probably not enough to simply dump the rom and do a diff against the rom you flashed. Maybe you just have to redo the flash again not knowing if it was necessary or not.
- thelastparadise 2y agoOne trick is to weld the case shut (you can get a welder on amazon for ~$100). This makes it much harder to open, especially in a non-tamper-evident way. You can open the case back up by using an angle grinder with a cutting disc to slice through the weld. I'd recommend taking a very high res photo of the welds so you can compare later if tampering is suspected.
- rolph 2y agoresocket your chipset so you can pop it out and take it with you.
- Jerrrrrrry 2y agoYou cannot protect hardware, just the things that flow through it, for a brief time. Buy a random older computer with cash. Nothing critical needs more than 512mb anyway. Faraday caged, WIFI/Bluetooth/EM sensitive heartbeat monitors, decentralized fail-safe Live feeds,full air gapped setup with UPS, white-noise machines, and only transmit data via QR codes. Hope the monitor you chose to display QR and the web-camera are also faraday'd. Hope the computer you are using to display the QR never gets compromised, and the QR-code reader, at the same time. It's easier to send a squid-team with a $5 wrench.
- dghughes 2y agoThis reminds me of my casino days. For slot machines each has several seals and the firmware and OS were checked each time anything was changed. We used a machine from a company called Kobetron for the EEPROMS but later the check was the OS on a disk. Seals were two layer foil with TAMPER when pulled off or a plastic tab that had a wire embedded in it.
- fsflover 2y agoI use Heads with TPM and Librem Key (with my own keys) just fine on my Librem 14 with neutralized ME.
- nextaccountic 2y agoThe post is about the scenario where you disabled the TPM