Live data from Hacker News

An in-depth security review of the Intel Management Engine

security-center.intel.com

61–70 of 192 posts

Re: An in-depth security review of the Intel Management Engine

#61
post #8

Wow all 6th, 7th and 8th gen are all vulnerable along with a bunch of Xeon processors. Even the laptop I am typing this on is vulnerable, this is going to be messy. Plus all the fun vulnerabilities like arbitrary code execution, unauthorized access to privileged content. These must be related to the blackhat talk coming up in December about hacking a turned-off computer and running unsigned code on ME [0]. Yep and th…

> I wonder if this will at all dissuade either Intel or AMD into continuing to make these super privileged processors whose functions are completely hidden. I think many discussions miss the nuance here. The problem is that the functionality is hidden, not necessarily that the function is there. In corporate use, these tools can be incredibly useful. If they were more transparent, then they could be used by normal us…

I agree with your overall conclusions, but I am having a hard time imagining the 'normal users' who would use remote administration... though perhaps if that were normal-for-HN users...

Re: An in-depth security review of the Intel Management Engine

#62
post #36

I prefer the wording in Lenovo's security advisory [0]: > "Potential Impact: An attacker could load and execute arbitrary code outside the visibility of the user, operating system, and hypervisor/virtualization platform; resulting in exfiltration of secrets, subtle manipulation of system operation, or denial of service." [0]: https://support.lenovo.com/us/en/product_security/len-17297

It is nice to know lenovo already has the updates, but sadly I'm gonna have to install windows for that :(

Go for the "bootable CD" option, if it's available. You don't need Windows for that. My ThinkPads all run Linux and I have no problems updating them.

Re: An in-depth security review of the Intel Management Engine

#63
post #8

Wow all 6th, 7th and 8th gen are all vulnerable along with a bunch of Xeon processors. Even the laptop I am typing this on is vulnerable, this is going to be messy. Plus all the fun vulnerabilities like arbitrary code execution, unauthorized access to privileged content. These must be related to the blackhat talk coming up in December about hacking a turned-off computer and running unsigned code on ME [0]. Yep and th…

Wow, who could have foreseen that this was such a risk /s

Re: An in-depth security review of the Intel Management Engine

#64
post #60
post #32

Earlier quoted context omitted.

Good luck getting a modern ARM SoC which doesn't depend on binary blobs.

At least you might be able to get a chip without a backdoor in hardware. Binary blobs are still a little easier to audit and can in theory be replaced.

ME FW is just a signed binary blob after all... Just running on an x86 core in the PCH, no difference at all compared to Qualcomm SCM/TZ firmware in that regard at least...

Re: An in-depth security review of the Intel Management Engine

#67
post #25

Earlier quoted context omitted.

> I wonder if this will at all dissuade either Intel or AMD into continuing to make these super privileged processors They clearly invested some serious money into this sort of thing and see it as a differentiator (or AMD wouldn't have followed suit). Chances that they'll throw it all away because of a few vulnerabilities are very, very thin.

Throwing it away is unlikely but the fact that this affects Xeon processors means that pretty much every single data center across the world could be affected. And that means that a lot of companies with a lot of money will complain.

> "...a lot of companies with a lot of money will complain."

Maybe, but they'll only complain for about five minutes. Then, they'll patch everything and move on and forget about it.

Until the next time. Rinse and repeat.

Re: An in-depth security review of the Intel Management Engine

#68
post #57
post #8

Wow all 6th, 7th and 8th gen are all vulnerable along with a bunch of Xeon processors. Even the laptop I am typing this on is vulnerable, this is going to be messy. Plus all the fun vulnerabilities like arbitrary code execution, unauthorized access to privileged content. These must be related to the blackhat talk coming up in December about hacking a turned-off computer and running unsigned code on ME [0]. Yep and th…

> these are the kind of vulnerabilities that the NSA would salivate over No need to salivate over something that you paid for and that you already used for 8 years. Post-Snowden if you believe the NSA has already broken into most things and has very often paid to facilitate this (like loss-making Skype US server routing, or inefficiently using valuable silicon space for IME), you are no longer a conspiracy theory lun…

> that you paid for

I don't think it's necessary to pay when you can just threaten charges of treason (Melissa Mayer) or make an example out of the uncooperative (Joe Nacchio).

Re: An in-depth security review of the Intel Management Engine

#69
post #2

Good times when kernel privilege escalation was the worst you had to fear. I'm not familiar enough with the Intel ME to tell, but could this possibly be exploited with the arbitrary code execution in the ME being used to set the HAP bit without requiring hardware intervention?

That'd be pretty sweet, wouldn't it?

Maybe I'll hold off on patching for a bit.

Re: An in-depth security review of the Intel Management Engine

#70

Anyone able to explain why Intel’s severity rating for this is “important” and not “critical”; meaning of the terms per Intel’s own words: “Critical: A vulnerability, which if exploited, would allow remote execution of malicious code without user action.” “Important: A vulnerability, which if exploited, would directly impact the confidentiality, integrity or availability of user’s data or processing resources.“

This doesn't allow remote access, just privilege escalation. So you'd already have to have some degree of access to the system to be able to use this vulnerability.
Post reply on HN