AMT/ME being used by malware created by well-resourced adversaries is no surprise, and is why Intel needed to give an irreversible and verifiable way of completely disabling it.
Malware Uses Obscure Intel CPU Feature to Steal Data and Avoid Firewalls
11–20 of 84 posts
Re: Malware Uses Obscure Intel CPU Feature to Steal Data and Avoid Firewalls
#12Re: Malware Uses Obscure Intel CPU Feature to Steal Data and Avoid Firewalls
#13Earlier quoted context omitted.
This just means that it is broken by design and will probably never be fixed. Nice. Does anyone know about similar AMD vulnerabilities?
Yes, AMD chips have almost exactly the same features as Intel ME. The cynic in me thinks that some execs got FISA orders.
Re: Malware Uses Obscure Intel CPU Feature to Steal Data and Avoid Firewalls
#14Do ARM cpus have this? Seriously... profanity here
The former, probably not.
The latter probably have something similar --- and they're even less publicly documented than Intel ME/AMT or AMD's equivalent.
Re: Malware Uses Obscure Intel CPU Feature to Steal Data and Avoid Firewalls
#15"Intel AMT SOL technology" - a most ironic acronym for this situation...
Re: Malware Uses Obscure Intel CPU Feature to Steal Data and Avoid Firewalls
#16This site denies access to the article from a German proxy. What a weird reason can be for this?
Re: Malware Uses Obscure Intel CPU Feature to Steal Data and Avoid Firewalls
#17Aaaand I think this is the first public disclosure of malware using the Intel Management Engine / AMT's network connection (that uses SMBus, i talked about it here https://news.ycombinator.com/item?id=14309557 and gave links to appropriate datasheets). Welp. AMT/ME being used by malware created by well-resourced adversaries is no surprise, and is why Intel needed to give an irreversible and verifiable way of complete…
The article said it comes disabled by default. Isn't this a verifiable way, or is the article incorrect?
Re: Malware Uses Obscure Intel CPU Feature to Steal Data and Avoid Firewalls
#18Aaaand I think this is the first public disclosure of malware using the Intel Management Engine / AMT's network connection (that uses SMBus, i talked about it here https://news.ycombinator.com/item?id=14309557 and gave links to appropriate datasheets). Welp. AMT/ME being used by malware created by well-resourced adversaries is no surprise, and is why Intel needed to give an irreversible and verifiable way of complete…
is why Intel needed to give an irreversible and verifiable way of completely disabling it. The article said it comes disabled by default. Isn't this a verifiable way, or is the article incorrect?
If ME firmware not found CPU will shut down every 30 minutes or something. There also way to neutralize some part of ME firmware while keeping system operational, but it's hard to tell how effective this is actually.
Re: Malware Uses Obscure Intel CPU Feature to Steal Data and Avoid Firewalls
#19Do ARM cpus have this? Seriously... profanity here
ARMs vary from simple microcontrollers to the SoCs used in smartphones and tablets. The former, probably not. The latter probably have something similar --- and they're even less publicly documented than Intel ME/AMT or AMD's equivalent.
Re: Malware Uses Obscure Intel CPU Feature to Steal Data and Avoid Firewalls
#20Issues with that doesn't seem to have scratched Intel's reputation as much as I expected.