>DMA, TCP/IP stack that can use onboard ethernet without the host OS being aware, closed source, unremovable, etc
You do know a wifi card has the same capabilities, right? There are many processors in your computer that can talk to the rest of the system in a privileged way.
>there absolutely have been serious exploits in ME and PSP,
Such as? I wouldn't call any of the found vulnerabilities serious.
>that they pose a grave security and privacy threat even outside the context of a government backdoor conspiracy.
Okay, but you need to balance those problems with the very real security benefits this allows Intel to offer.
Exactly. Even if we assumed for the sake of argument that wifi cards have complete access to the system, that in and of itself does not excuse CPU vendors to broaden the attack surface and prevent owners from narrowing it back down.
I can't wait for riscv systems to take off. Hopefully we'll get more than the two horrible choices we have now and, hopefully, they won't be able to abuse the market in the same way.
Screw both intel and amd for deliberately putting us all at risk.
>Screw both intel and amd for deliberately putting us all at risk.
Keep in mind, if these are government backdoors, it's likely Intel and AMD were compelled to put them in, there's a gag order on the existence of the program, and there's a gag order on the first gag order. It could be a situation where Intel and AMD really had their hands tied, so to speak.
That's why I'm rooting for riskv processors, so that we can get the equivalent of reproducible openSSL binaries. US chips that are found to be irreproducable can be rightfully ignored.
What's special about RISC-V? How does companies not having to pay for using an ISA in a processor having anything to do with whether they implement other processors inside of their processor?
It's not that RISC-V guarantees truly transparent firmware and microcode; as you correctly point out, it does not.
What RISC-V offers is the possibility of truly transparent firmware and microcode. This comes as a refreshing alternative to x86, which guarantees that firmware and microcode, including those of security coprocessors (e.g. Intel CSME & AMD ST, formerly ME and PSP) will not be transparent.
I am not as well-versed in the specifics of ARM's TrustZone as I am with Intel CSME and AMD ST, but I understand many of the people uncomfortable with the latter two are uncomfortable with the former as well. I do not believe it comes with the same capabilities as CSME or ST (PSP), but I do know that earlier versions of PSP were implemented using an ARM TrustZone core. That said, I need to do a lot more reading and research on it before forming more substantial positions on it.
None of those have any benefit for me. I have secure boot on my machine with my own keys and Librem Key hardware token: https://news.ycombinator.com/item?id=35436908. Can I disable the ME on “my” machine?
What is secure about those video and audio?
This is why I said usually. Creating a VM specifically for a wifi card is not done by >99.9% of ME users.
>I have secure boot on my machine
It's my understanding that the ME chip is involved with the secure boot process.
>Can I disable the ME on “my” machine?
No, it's a part of your CPU and the designers of the CPU rely on its existence.
>What is secure about those video and audio?
The security is about preventing other programs from being able to capture the video and audio. Sometimes programs want the ability to output something to the user, but don't want other programs to to be able to save it or analyze it.
>The security is about preventing other programs from being able to capture the video and audio. Sometimes programs want the ability to output something to the user, but don't want other programs to to be able to save it or analyze it.
The big gripe of a lot of people is that what this actually means is DRM, and that functionality is not there to offer security to the end user, rather to offer security from the end user.
At a philosophical level, when the end user purchases computing hardware, this traditionally has meant that the hardware became the end user's property, and it becomes the owner's intrinsic right to use it how they want, even to misuse it -- You wouldn't buy a car that was incapable of going 16 mph in a 15 mph zone, or making a turn without the turn signal being activated, would you?
Frankly, I even get the desire for piracy. Piracy is not theft, it does not strip another person of their property. You may argue that it strips the original content creator of their royalty (plus the parasitic organization publishing the content of their 95%+ "fee"), but I'd counter by suggesting that even of the pirates who could afford to pay for such content, ~99% would not otherwise pay for that content if they weren't pirating it, so that's really a false argument - if they even would pay for it, then they'd have just paid for it, wouldn't they? Not to mention that piracy democratizes access to diverse forms of art, making it available to the poor, who have just as much a human right to appreciate art as the rest of humanity. Further, the piracy ecosystem preserves otherwise lost forms of art. I wanted to watch a 1998 German movie called "23" a couple weeks ago. Couldn't find a legitimate copy available to purchase or stream anywhere in my country, neither physical media nor digital, but TPB had multiple copies with English subs.
Besides, it's not like these security coprocessors (including Microsoft Pluton, the private-sector newcomer to the probable public-sector "security coprocessor" club) actually prevent competent folks from capturing media. They're a nuisance that raises the cost of computing hardware, ostensibly a public good in the information age, while doing effectively nothing to prevent piracy.
If even a single argument for the legitimacy of the existence of Intel CSME and AMD ST is DRM, a.k.a. "to prevent poor people from appreciating art, ensuring that countless artistic creations are lost forever, and needlessly raising the cost of a utility that borders on a public good", I can only hope that I've demonstrated the downsides of this argument.
You do know a wifi card has the same capabilities, right? There are many processors in your computer that can talk to the rest of the system in a privileged way.
>there absolutely have been serious exploits in ME and PSP,
Such as? I wouldn't call any of the found vulnerabilities serious.
>that they pose a grave security and privacy threat even outside the context of a government backdoor conspiracy.
Okay, but you need to balance those problems with the very real security benefits this allows Intel to offer.