zlacker

[return to "Intel x86 considered harmful – survey of attacks against x86 over last 10 years"]
1. pjc50+Y8[view] [source] 2015-10-27 16:01:39
>>chei0a+(OP)
"System management mode" is a tremendous wart and should be removed wholesale, with Intel adopting a more ARM-style trusted boot chain with explicit cooperation from the OS or hypervisor. And while you're at it, kill UEFI and install a pony for me.

(Seriously, SMM serves either bizarre ILO features that high-end vendors like but are rarely used, or security agencies looking for a layer to hide in.)

◧◩
2. rwmj+yd[view] [source] 2015-10-27 16:35:17
>>pjc50+Y8
Actually ILO is pretty useful :-)

I have an APM (ARM64) Mustang, and this takes a rather different approach, but probably not one you'll think is better. The chip advertises 8 x 64 bit cores, but there's a 9th 32 bit core which runs all the time, even when the machine is powered down (although obviously still connected to mains power). It runs a separate firmware, in its own RAM, but can access the main memory at will and invisibly to the main OS.

One way to look at this is it's brilliant that we can just put a tiny Cortex-M3 in a spare bit of silicon and have it do useful management stuff.

◧◩◪
3. ctstov+5f[view] [source] 2015-10-27 16:45:15
>>rwmj+yd
Terrifying! Is there a way to disable that?
◧◩◪◨
4. bravo2+Tg[view] [source] 2015-10-27 17:01:27
>>ctstov+5f
I don't know which chip OP is using but no you can't. It is usually a small CPU which is part of the GPU video decoder that is used as the 'boot' processor. It usually executes first level ROM code and fetches the first stage boot loader from flash, USB, etc.

It can also do PMU control when the machine is 'turned off'. The alternative is to use an external microcontroller. It is actually quiet useful.

What is your reason for wanting to disable it?

[go to top]