Live data from Hacker News

An in-depth security review of the Intel Management Engine

security-center.intel.com

21–30 of 192 posts

Re: An in-depth security review of the Intel Management Engine

#21
So after it is exposed, after 3 generations of products, do they admit it is not a "feature". I can't imagine why they thought this kind of escalation couldn't be cracked by a 3rd party, or how it would bring brand value. This is "clipper" and yes, the hacker can control it. Dangit. Sell-outs.

I'm just waiting for the ransomware that lives on AME, and is burned to the various dies instead of on hard-drives. Isn't that what this open door means?

Re: An in-depth security review of the Intel Management Engine

#22
I don't see any remote exploits here (other than "attacker with remote admin access..."). Is that correct? Presumably an attacker with remote admin access is already all powerful? Or is the concern that they can backdoor the hardware in an undetectable way, remotely?

Re: An in-depth security review of the Intel Management Engine

#23
post #17

Unreal. Kept scrolling and the vulnerabilities kept coming. Most annoying thing is that there isn’t even a real alternative. If I understand it right then AMD chips have pretty much the same thing?

Well, maybe AMD does at least some security reviewing on their own? /s ARM could be a affordable alternative to x86 if that works for you.

What's the state of x86 emulation on ARM? Using ARM before that might be a dealbreaker. If I remember correctly Microsoft was working on it

Re: An in-depth security review of the Intel Management Engine

#24
post #20

It looks like they specifically label CVEs that require local access as such. Does anyone know if "via unspecified vector" means network access?

Surely in that case it would say something like "attacker with access to the lan connected to the machine's NIC" ?

Re: An in-depth security review of the Intel Management Engine

#25
post #8

Wow all 6th, 7th and 8th gen are all vulnerable along with a bunch of Xeon processors. Even the laptop I am typing this on is vulnerable, this is going to be messy. Plus all the fun vulnerabilities like arbitrary code execution, unauthorized access to privileged content. These must be related to the blackhat talk coming up in December about hacking a turned-off computer and running unsigned code on ME [0]. Yep and th…

> I wonder if this will at all dissuade either Intel or AMD into continuing to make these super privileged processors

They clearly invested some serious money into this sort of thing and see it as a differentiator (or AMD wouldn't have followed suit). Chances that they'll throw it all away because of a few vulnerabilities are very, very thin.

Re: An in-depth security review of the Intel Management Engine

#26
I prefer the wording in Lenovo's security advisory [0]:

> "Potential Impact: An attacker could load and execute arbitrary code outside the visibility of the user, operating system, and hypervisor/virtualization platform; resulting in exfiltration of secrets, subtle manipulation of system operation, or denial of service."

[0]: https://support.lenovo.com/us/en/product_security/len-17297

Re: An in-depth security review of the Intel Management Engine

#27
Does "attacker with local access to the system" mean "physical access to the system"?? Initially I thought it meant "attacker able to run an unprivileged process on the system" but then I see other wording that seems to imply that case, so does "local access" mean physical access? (e.g. connect a USB drive, boot the box off their own media?)

Re: An in-depth security review of the Intel Management Engine

#28
post #25
post #8

Wow all 6th, 7th and 8th gen are all vulnerable along with a bunch of Xeon processors. Even the laptop I am typing this on is vulnerable, this is going to be messy. Plus all the fun vulnerabilities like arbitrary code execution, unauthorized access to privileged content. These must be related to the blackhat talk coming up in December about hacking a turned-off computer and running unsigned code on ME [0]. Yep and th…

> I wonder if this will at all dissuade either Intel or AMD into continuing to make these super privileged processors They clearly invested some serious money into this sort of thing and see it as a differentiator (or AMD wouldn't have followed suit). Chances that they'll throw it all away because of a few vulnerabilities are very, very thin.

Throwing it away is unlikely but the fact that this affects Xeon processors means that pretty much every single data center across the world could be affected. And that means that a lot of companies with a lot of money will complain.

Re: An in-depth security review of the Intel Management Engine

#29
post #8

Wow all 6th, 7th and 8th gen are all vulnerable along with a bunch of Xeon processors. Even the laptop I am typing this on is vulnerable, this is going to be messy. Plus all the fun vulnerabilities like arbitrary code execution, unauthorized access to privileged content. These must be related to the blackhat talk coming up in December about hacking a turned-off computer and running unsigned code on ME [0]. Yep and th…

Mobile Atoms are affected it seems despite using TXE (SPARC CPU) instead of ME.

Re: An in-depth security review of the Intel Management Engine

#30
post #17

Unreal. Kept scrolling and the vulnerabilities kept coming. Most annoying thing is that there isn’t even a real alternative. If I understand it right then AMD chips have pretty much the same thing?

Well, maybe AMD does at least some security reviewing on their own? /s ARM could be a affordable alternative to x86 if that works for you.

it's less painful if you only pay half for being pwnd
Post reply on HN