Live data from Hacker News

ThinkPwn: System Management Mode arbitrary code execution

github.com

141–150 of 154 posts

Re: ThinkPwn: System Management Mode arbitrary code execution

#141
post #91

> First is the FCC vs WIFI channel selection in firmware. They want the choice to interfere be removed from the user in this occasion. Fuck 'em. > Second is cell carriers are not wild about unknown basebands conversing with their networks. Fuck 'em. > In theory the network should defend against bad phones but they'd rather not test that. ... hard.

Please don't post unsubstantive comments.

We detached this subthread from https://news.ycombinator.com/item?id=12037726 and marked it off-topic.

Re: ThinkPwn: System Management Mode arbitrary code execution

#142

Earlier quoted context omitted.

As I commented elsewhere, we can, see https://news.ycombinator.com/item?id=12037410

Old, outdated, expensive hardware with low specs? Nope. I have a lot of respect for what they do but it's not the solution we need.

An alternative is to use ARM-based devices: they typically lack microcode updates, and while TrustZone hypervisors are often present and the situation varies by device, at least some devices should allow the user to gain full control of the CPU without having to exploit anything. (I don't know how common that is, because every device manufacturer has their own boot process, and from some quick Google searching it seems like most of the time nobody bothers to figure out how the TrustZone stuff or the boot chain works, being satisfied with custom Android images...)

ARM Chromebooks in particular I think are theoretically supposed to have fully open source firmware, though the documentation is a little sparse... probably mostly for the same reason, lack of interest.

Re: ThinkPwn: System Management Mode arbitrary code execution

#143

Earlier quoted context omitted.

The sale happened ten years ago and it is extremely unlikely that there are any contractual obligations for this anymore. Let's put this meme to rest; Lenovo has been building solid Thinkpads.

what?! since when? I every single thinkpad I bought since my T43P has been a total piece of shit in comparison. Methinks you have never owned an IBM Thinkpad to make that statement.

I have used exclusively Thinkpads since 1997.

The one I bought in 1999 broke through a cracked screen when a pencil got wedged between the frame and the screen because the hinges were not as strong as those today.

The T42, T43 and T60 series were absolutely incredible for their times but were now without fault; even back then they screen bezel was huge and you had to pay unreasonable money to get a screen with a higher resolution than 1024x800.

My Z60 was a fantastic machine that I ended up giving away. Its battery life, however, will not be missed.

My last T420 has an assembly that flexed far more than I liked and buttons whose pretty uniform black wore out with use, but I still keep it in the closet because it's indestructible. It's ugly as sin though.

I have my minor disagreements with the keyboard design of the X250, but the trackpad is great, the screens have actually usable brightness now with their default configuration, and battery life has gone way, way, way up.

Let's not look at the past with rose-colored glasses. Every one of those machines had a minor issue as far a Linux compatibility (always different), but back then it was a pain in the ass to get the WiFi working, whereas now if anything I might have a complaint about default keyboard bindings. Things change, but at no point in all that time did I have to send any of those machines for repairs (save for the Z60's fan getting clogged with dirt and some random memory module that died).

People get enamored with their machines and their particular quirks, but I much prefer the new, thinner machines. The tradeoffs are tradeoffs, and the defects are just different. Hell I even prefer the new chiclet keys over the old keys.

The only thing I can say is different is that the frame of the newer machines flexes more. That is not a defect; a frame that flexes is far more resistant to falls and impact. All of my machines have fallen off chairs at some point; all of them survived intact.

Re: ThinkPwn: System Management Mode arbitrary code execution

#144

Earlier quoted context omitted.

As I commented elsewhere, we can, see https://news.ycombinator.com/item?id=12037410

Old, outdated, expensive hardware with low specs? Nope. I have a lot of respect for what they do but it's not the solution we need.

Old, outadated, with low specs only for those who need high performance. For 90% everyday tasks these laptops are more than enough. For me specifically and for many of my friends, they are 100% enough.

Re: ThinkPwn: System Management Mode arbitrary code execution

#145
post #77

This should be good news for people looking to getting rid of Computrace, effectively a rootkit, from surplus Thinkpads. http://forum.thinkpads.com/viewtopic.php?t=114641 Yes, I bought a surplus Thinkpad (T61) and found it had Computrace activated on it. Grrrr. Yes, I could call the Absolute(R) Software number and they should disable it for me. I have not been willing to sit on hold and jump their hoops to date. Sinc…

AFAIK all the ThinkPads have a BIOS option to disable CompuTrace. Mine has three options: "Enabled", "Disabled" (default option) and "Permanently disabled".

The "permanently disabled" option erases the CompuTrace blob from the flash chip, so it cannot be re-enabled afterwards.

This may not be the case for their non-business machines (i.e., not ThinkPad).

Re: ThinkPwn: System Management Mode arbitrary code execution

#146
post #54

Earlier quoted context omitted.

> and admit that they ship code of both unknown author and purpose. That's literally what every vendor does nowadays. Do you think LG can get the code for the firmware of the SoCs they use in their phones? Do you think the coreboot guys can get the source for the Intel Management Engine firmware? Do you think any of the firmware in your system comes from your OEM and is secure? This is a failure in the entire industr…

> Do you think any of the firmware in your system comes from your OEM and is secure? No, of course not. But I'm surprised that Lenovo would tacitly admit this.

To be honest this has been going on ever since the first day random OEMs started shipping X86-based machines. There's really nothing to admit.

Back then we had Amibios, Pheonix bios etc etc, but these days we call it "UEFI" and "firmware" and everyone gets up in arms about it.

Re: ThinkPwn: System Management Mode arbitrary code execution

#147
So this is traceable to the Intel reference implementation. I am going to assume incompetence but let's say I would assume malice instead (some government agent wrote the reference spec full well knowing it's exploitable with or without the knowledge of Intel) how would one go about soft-proving that?

Compare machines that are vulnerable in the wild and same spec machines from important people at Intel and/or suspected government agency (assuming they'd simply use a non-vulnerable version instead of some completely different hardware)?

Re: ThinkPwn: System Management Mode arbitrary code execution

#148
post #109
post #87

Earlier quoted context omitted.

Name calling? Come on. I'm not really a fan of the trend of "branding" vulnerabilities, but it is just harmless silliness, and substantially less inflammatory than security industry smack-talking norms from not too long ago. Or put another way, I suggest adjusting your sensitivity before cracking open an issue of Phrack. And a serious question: in your view what would be a "responsible" way to release a multivendor e…

Give the vendor a timeframe to investigate and resolve. Even sometimes ignores reports like this, at least give them the courtesy instead of expose this as an 0day.

Why?

Lenovo put users at risk and public shaming is a tool to correct their behaviour.

Lenovo could allow users to replace software on their machine, but presently choose not to because they might make less money.

However if Lenovo are shamed, people might buy less of Lenovo's products, which will also make Lenovo less money.

Re: ThinkPwn: System Management Mode arbitrary code execution

#149
post #64

Earlier quoted context omitted.

So, literally every vendor? Can you think of a single example of a vendor not running UEFI code from others, not running either Qualcomm's kernels for ARM chips, nor distributing Intel's ME firmaware, nor distributing AMD's TPM firmware? I don't think there's a single OEM that knows what they're actually running – if there is, SAMSUNG would likely be it, because they have a chance at actually doing everything in-hous…

Probably Apple, too - they prefer to implement things in-house wherever possible.

[deleted]

Re: ThinkPwn: System Management Mode arbitrary code execution

#150
post #85

Earlier quoted context omitted.

Probably Apple, too - they prefer to implement things in-house wherever possible.

Apple now ships UEFI updates with every version of OS X.

Does Apple use UEFI now? Everything I've read suggests Apple forked at EFI 1.10 and never looked back.
Post reply on HN