Earlier quoted context omitted.
is why Intel needed to give an irreversible and verifiable way of completely disabling it. The article said it comes disabled by default. Isn't this a verifiable way, or is the article incorrect?
There's a second bug that allows a non-privileged local user to provision it. "An unprivileged local attacker could provision manageability features gaining unprivileged network or local system privileges on Intel manageability SKUs" https://security-center.intel.com/advisory.aspx?intelid=INTE...
Malware Uses Obscure Intel CPU Feature to Steal Data and Avoid Firewalls
41–50 of 84 posts
Re: Malware Uses Obscure Intel CPU Feature to Steal Data and Avoid Firewalls
#42Money Quote: > When contacted by Microsoft, Intel said the PLATINUM group wasn't using any vulnerability in the Intel AMT SOL interface, but this was another classic case of bad guys using a technology developed for legitimate purposes to do bad things. Worst excuse ever. "Look guys, at least it's not a backdoor we left on purpose!!!" m(
Are there any open hardware computers of comparable computing power? How can the consumer stop someone from exploiting this hack?
[Remove Intel ME](https://github.com/corna/me_cleaner) to the largest extent possible. I don't know of equivalent tools for AMD, though, which also has similar systems in place.
Re: Malware Uses Obscure Intel CPU Feature to Steal Data and Avoid Firewalls
#43It's surprising that everyone is up in arms about AMT and ME while not complaining in the slightest about SGX. SGX allows third parties to run code on your processor that is outside of your control. We're losing our computers to corporate interests. You are buying a device they can remotely manage, exert control with a higher privilege than yours, hide secrets inside your machine, and make all the decisions for you.…
SGX, if they allow arbitrary code to be signed, is amazing. It enables remote trust. You could execute jobs "in the cloud" without anyone being able to see your data. You could write a known-correct coin tumbler or trading platform. If it does only get locked to a few code authors, that would be a tremendous shame.
Re: Malware Uses Obscure Intel CPU Feature to Steal Data and Avoid Firewalls
#44It's surprising that everyone is up in arms about AMT and ME while not complaining in the slightest about SGX. SGX allows third parties to run code on your processor that is outside of your control. We're losing our computers to corporate interests. You are buying a device they can remotely manage, exert control with a higher privilege than yours, hide secrets inside your machine, and make all the decisions for you.…
SGX, if they allow arbitrary code to be signed, is amazing. It enables remote trust. You could execute jobs "in the cloud" without anyone being able to see your data. You could write a known-correct coin tumbler or trading platform. If it does only get locked to a few code authors, that would be a tremendous shame.
Re: Malware Uses Obscure Intel CPU Feature to Steal Data and Avoid Firewalls
#45Earlier quoted context omitted.
Who knows if the feature is not still present in silicon but just software-disabled? It's not really new that Intel and AMD do binning to get more yield.
It isn't present AFAIK, because Intel cuts corners on enthusiast chips they do not expect to be used in a networked environment in order to save money, and still charge you more than the non-enthusiast counterparts.
Re: Malware Uses Obscure Intel CPU Feature to Steal Data and Avoid Firewalls
#46Another round of crappy journalism. It's not obscure, it's not a CPU feature but a platform feature, and there are plenty of out-of-band communication channels out there, this isn't the only one. On top of that, this was already published two DEF CONs ago. You can exfil data and even do practival bi-directional communication over: SOL, IPMI, ASF, MT's ARC CPU via injected firmware and then via TCP/IP. Any of them wil…
Re: Malware Uses Obscure Intel CPU Feature to Steal Data and Avoid Firewalls
#47Earlier quoted context omitted.
AMT is disabled by default on most consumer PCs or at least it's not expose itself. Though AMT work on top of ME and ME is opposite: it's always active and required for system to operate. If ME firmware not found CPU will shut down every 30 minutes or something. There also way to neutralize some part of ME firmware while keeping system operational, but it's hard to tell how effective this is actually.
A privileged local user can provision AMT to its liking though, which is afaict what this malware did.
Am I missing something?
Re: Malware Uses Obscure Intel CPU Feature to Steal Data and Avoid Firewalls
#48Earlier quoted context omitted.
SGX, if they allow arbitrary code to be signed, is amazing. It enables remote trust. You could execute jobs "in the cloud" without anyone being able to see your data. You could write a known-correct coin tumbler or trading platform. If it does only get locked to a few code authors, that would be a tremendous shame.
Yeah it's will bring new amazing spyware and ransomware on millions of PCs.
Re: Malware Uses Obscure Intel CPU Feature to Steal Data and Avoid Firewalls
#49Another round of crappy journalism. It's not obscure, it's not a CPU feature but a platform feature, and there are plenty of out-of-band communication channels out there, this isn't the only one. On top of that, this was already published two DEF CONs ago. You can exfil data and even do practival bi-directional communication over: SOL, IPMI, ASF, MT's ARC CPU via injected firmware and then via TCP/IP. Any of them wil…
Of these techs, which does AMD support? Would switching to AMD make us more secure?
Read about AMD PSP / ARM TrustZone.
Re: Malware Uses Obscure Intel CPU Feature to Steal Data and Avoid Firewalls
#50Money Quote: > When contacted by Microsoft, Intel said the PLATINUM group wasn't using any vulnerability in the Intel AMT SOL interface, but this was another classic case of bad guys using a technology developed for legitimate purposes to do bad things. Worst excuse ever. "Look guys, at least it's not a backdoor we left on purpose!!!" m(
Are there any open hardware computers of comparable computing power? How can the consumer stop someone from exploiting this hack?