Live data from Hacker News

Malware Uses Obscure Intel CPU Feature to Steal Data and Avoid Firewalls

bleepingcomputer.com

51–60 of 84 posts

Re: Malware Uses Obscure Intel CPU Feature to Steal Data and Avoid Firewalls

#51
post #41
post #36

Earlier quoted context omitted.

There's a second bug that allows a non-privileged local user to provision it. "An unprivileged local attacker could provision manageability features gaining unprivileged network or local system privileges on Intel manageability SKUs" https://security-center.intel.com/advisory.aspx?intelid=INTE...

Isn't it supposed to be enabled in BIOS in order to provision it? On most laptops and desktop motherboards such features simply disable by default like VT-d (IOMMU).

See this question on the Intel forums. Seems difficult to actually disable it. https://software.intel.com/en-us/forums/intel-business-clien...

Re: Malware Uses Obscure Intel CPU Feature to Steal Data and Avoid Firewalls

#52
post #4

Money Quote: > When contacted by Microsoft, Intel said the PLATINUM group wasn't using any vulnerability in the Intel AMT SOL interface, but this was another classic case of bad guys using a technology developed for legitimate purposes to do bad things. Worst excuse ever. "Look guys, at least it's not a backdoor we left on purpose!!!" m(

Are there any open hardware computers of comparable computing power? How can the consumer stop someone from exploiting this hack?

> Are there any open hardware computers of comparable computing power?

IBMs POWER processors are comparable to high-end Xeons and the specifications are entirely open.

I'd love to see a new "Talos" effort in light of recent events: https://www.crowdsupply.com/raptor-computing-systems/talos-s...

Re: Malware Uses Obscure Intel CPU Feature to Steal Data and Avoid Firewalls

#53
post #37
post #29

Earlier quoted context omitted.

It isn't present AFAIK, because Intel cuts corners on enthusiast chips they do not expect to be used in a networked environment in order to save money, and still charge you more than the non-enthusiast counterparts.

ME is there (ability to execute below ring -1). Go ahead and check it right now, look at lspci/device manager for Management Engine Communications device. Its present on cheapest desktop H81 motherboards, and on highend (at the time) Z87 ones, no matter the cpu.

I have done that before, and I've just done it again, and I don't get anything. The only thing present on my system related to ME afaik is the MEI linux driver, which is pretty useless without a ME to talk to.

According to ARK [0], vPRO is absent. I have done various other system queries and nothing has turned up.

Anything else you want me to query? And where do you get this information that ME is present in all chips? Having a motherboard that supports ME is irrelevant, if the chip has no ME.

[0] https://ark.intel.com/products/88195/Intel-Core-i7-6700K-Pro...

Re: Malware Uses Obscure Intel CPU Feature to Steal Data and Avoid Firewalls

#54
post #32

It's surprising that everyone is up in arms about AMT and ME while not complaining in the slightest about SGX. SGX allows third parties to run code on your processor that is outside of your control. We're losing our computers to corporate interests. You are buying a device they can remotely manage, exert control with a higher privilege than yours, hide secrets inside your machine, and make all the decisions for you.…

Technology isn't intrinsically good or evil. It's how it's used, like the death ray.

Re: Malware Uses Obscure Intel CPU Feature to Steal Data and Avoid Firewalls

#55
post #29

Earlier quoted context omitted.

It isn't present AFAIK, because Intel cuts corners on enthusiast chips they do not expect to be used in a networked environment in order to save money, and still charge you more than the non-enthusiast counterparts.

ME is always there even if you don't have any of its features.

See my comment here: https://news.ycombinator.com/item?id=14522172

Same questions apply to you. This is something I would like to be proved wrong on, as I don't want a false since of security.

Re: Malware Uses Obscure Intel CPU Feature to Steal Data and Avoid Firewalls

#56
post #29

Earlier quoted context omitted.

It isn't present AFAIK, because Intel cuts corners on enthusiast chips they do not expect to be used in a networked environment in order to save money, and still charge you more than the non-enthusiast counterparts.

Ah okay. I thought that Intel bins everything from high-grade Xeon to i3 from the same silicon to save costs.

I couldn't truly say whether Intel bins all of their processors with the same prefab or not, I'm not sure how to find this out either.

My working theory however is that since my chip lacks vPRO / AMT and I have not been able to find any indication it exists on the chip even in a dormant state, there may be more than one prefab used for binning.

However they could be using the same prefab for all.

Thus, "AFAIK".

Re: Malware Uses Obscure Intel CPU Feature to Steal Data and Avoid Firewalls

#57
post #5
post #2

Intel AMT strikes again. I imagine this problem will only increase in the future, now that more malware creators know they can try to use this CPU backdoor (okay, this "totally-not-intended-for-bad-things and super-useful remote connection enterprise feature" ).

Exploiting vPro / AMT / any remote access mechanism from any chip maker is hardly a new idea. AMT and AMD's equivalent (don't remember the name) has been a holy grail for security researchers and malware authors alike for many years. People have been begging Intel for a very long time to make business-tier chips without remote access capabilities. For personal computing, at least we have enthusiast chips. For example…

AMD's PSP does not have any remote access mechanism though, and it is powered off along with the processor.

Re: Malware Uses Obscure Intel CPU Feature to Steal Data and Avoid Firewalls

#58
post #4

Money Quote: > When contacted by Microsoft, Intel said the PLATINUM group wasn't using any vulnerability in the Intel AMT SOL interface, but this was another classic case of bad guys using a technology developed for legitimate purposes to do bad things. Worst excuse ever. "Look guys, at least it's not a backdoor we left on purpose!!!" m(

Are there any open hardware computers of comparable computing power? How can the consumer stop someone from exploiting this hack?

We're a long way until free hardware design are a thing, for a more immediate solution, try this:

If it's processing power you need, I guess the ASUS KGPE-D16 with Libreboot would to the trick. As a laptop - X200, X200T, T400, T400s, T500, etc. You can find a list of vendors here: https://libreboot.org/suppliers.html

Re: Malware Uses Obscure Intel CPU Feature to Steal Data and Avoid Firewalls

#59
post #35

> Intel ME runs even when the main processor is powered off, and while this feature looks pretty shady, Intel built ME to provide remote administration capabilities to companies that manage large networks of thousands of computers. So they exposed millions of consumer and business computers in order to satisfy a niche enterprise usecase? Why is this not something that has to be manually turned on? Intel ME has always…

Consensus when this was released was that intel agency use was the whole point.

Re: Malware Uses Obscure Intel CPU Feature to Steal Data and Avoid Firewalls

#60
post #32

It's surprising that everyone is up in arms about AMT and ME while not complaining in the slightest about SGX. SGX allows third parties to run code on your processor that is outside of your control. We're losing our computers to corporate interests. You are buying a device they can remotely manage, exert control with a higher privilege than yours, hide secrets inside your machine, and make all the decisions for you.…

The reason is that SGX doesn't do remotely the same thing that AMT and ME do. Code that uses SGX doesn't gain privileges it didn't have (in fact, it loses privileges even compared to normal usermode code). It can be scheduled/killed by the OS the same as any other user code, and the feature can be disabled wholesale via firmware (the processor will not shutdown after 30 minutes like it does when ME is prevented from running). The code running in the enclave is also not encrypted; only data it generates at runtime is, so you can inspect it and decide whether you want to run it just fine. Kernels can't even use it directly, so I'm not sure how SGX helps anybody "make all the decisions for you".

In fact, SGX is probably the only way to get some semblance of a defense against compromised ME and SMM code. There's even a number of open source projects that use it (e.g. [0]). To be even more dramatic, not every acronym Intel comes up with is Pure Evil.

[0]: https://github.com/ayeks/TresorSGX

Post reply on HN