Live data from Hacker News

Malware Uses Obscure Intel CPU Feature to Steal Data and Avoid Firewalls

bleepingcomputer.com

11–20 of 84 posts

Re: Malware Uses Obscure Intel CPU Feature to Steal Data and Avoid Firewalls

#11
Aaaand I think this is the first public disclosure of malware using the Intel Management Engine / AMT's network connection (that uses SMBus, i talked about it here https://news.ycombinator.com/item?id=14309557 and gave links to appropriate datasheets). Welp.

AMT/ME being used by malware created by well-resourced adversaries is no surprise, and is why Intel needed to give an irreversible and verifiable way of completely disabling it.

Re: Malware Uses Obscure Intel CPU Feature to Steal Data and Avoid Firewalls

#13
post #6

Earlier quoted context omitted.

This just means that it is broken by design and will probably never be fixed. Nice. Does anyone know about similar AMD vulnerabilities?

Yes, AMD chips have almost exactly the same features as Intel ME. The cynic in me thinks that some execs got FISA orders.

https://en.wikipedia.org/wiki/Communications_Assistance_for_...

Re: Malware Uses Obscure Intel CPU Feature to Steal Data and Avoid Firewalls

#14
post #9

Do ARM cpus have this? Seriously... profanity here

ARMs vary from simple microcontrollers to the SoCs used in smartphones and tablets.

The former, probably not.

The latter probably have something similar --- and they're even less publicly documented than Intel ME/AMT or AMD's equivalent.

Re: Malware Uses Obscure Intel CPU Feature to Steal Data and Avoid Firewalls

#15
It's funny that the image of the CPU in the article is a P4-era socket 478 model, which AFAIK comes from a time when Intel ME didn't exist in its current form yet... somewhat like showing a late 80s vehicle in an article about hacking self-driving cars.

"Intel AMT SOL technology" - a most ironic acronym for this situation...

Re: Malware Uses Obscure Intel CPU Feature to Steal Data and Avoid Firewalls

#17
post #11

Aaaand I think this is the first public disclosure of malware using the Intel Management Engine / AMT's network connection (that uses SMBus, i talked about it here https://news.ycombinator.com/item?id=14309557 and gave links to appropriate datasheets). Welp. AMT/ME being used by malware created by well-resourced adversaries is no surprise, and is why Intel needed to give an irreversible and verifiable way of complete…

is why Intel needed to give an irreversible and verifiable way of completely disabling it.

The article said it comes disabled by default. Isn't this a verifiable way, or is the article incorrect?

Re: Malware Uses Obscure Intel CPU Feature to Steal Data and Avoid Firewalls

#18
post #17
post #11

Aaaand I think this is the first public disclosure of malware using the Intel Management Engine / AMT's network connection (that uses SMBus, i talked about it here https://news.ycombinator.com/item?id=14309557 and gave links to appropriate datasheets). Welp. AMT/ME being used by malware created by well-resourced adversaries is no surprise, and is why Intel needed to give an irreversible and verifiable way of complete…

is why Intel needed to give an irreversible and verifiable way of completely disabling it. The article said it comes disabled by default. Isn't this a verifiable way, or is the article incorrect?

AMT is disabled by default on most consumer PCs or at least it's not expose itself. Though AMT work on top of ME and ME is opposite: it's always active and required for system to operate.

If ME firmware not found CPU will shut down every 30 minutes or something. There also way to neutralize some part of ME firmware while keeping system operational, but it's hard to tell how effective this is actually.

Re: Malware Uses Obscure Intel CPU Feature to Steal Data and Avoid Firewalls

#19
post #9

Do ARM cpus have this? Seriously... profanity here

ARMs vary from simple microcontrollers to the SoCs used in smartphones and tablets. The former, probably not. The latter probably have something similar --- and they're even less publicly documented than Intel ME/AMT or AMD's equivalent.

AMD PSP it is ARM TrustZone.

Re: Malware Uses Obscure Intel CPU Feature to Steal Data and Avoid Firewalls

#20
post #3

Issues with that doesn't seem to have scratched Intel's reputation as much as I expected.

Maybe because everyone, who had any clue, knew since the begging what was ME intended for. The only news here is that "wrong" guys used this backdoor (again, nothing unexpected).
Post reply on HN