My CPU has an HTTP server? But why?
Your CPU actually runs its own entire, separate operating system - MINIX. https://www.cs.vu.nl/~ast/intel/
Intel patches new ME vulnerabilities
21–30 of 337 posts
Re: Intel patches new ME vulnerabilities
#22Re: Intel patches new ME vulnerabilities
#23Re: Intel patches new ME vulnerabilities
#24Re: Intel patches new ME vulnerabilities
#25Intel advisory: https://www.intel.com/content/www/us/en/security-center/advi... CVE-2018-3628 - "Buffer overflow in HTTP handler" Affected processor list (simplified reordered by me to reflect relevance and improve readability): • Core i3/i5/i7, generation 1-8 (that is, all of them) • Xeon E3-1200 v5/v6 • Xeon Scalable • Xeon W • Core 2 Duo vPro, Centrino 2 vPro
Also worth noting that they're not patching it for 1st, 2nd or 3rd generation Core CPUs. I'm sure there's plenty of Sandy Bridge/Ivy Bridge CPUs in the wild, and it's not like you have an option to discontinue use of the Intel ME :(
Re: Intel patches new ME vulnerabilities
#26I ask because I've never seen its webserver on my home network. Heck, I don't even get how it could connect to the internet on a powered off device without Ethernet.
Re: Intel patches new ME vulnerabilities
#27I wonder, who ever uses these "management engines," let alone put them open on WANs? When first news of IME being compromised, I was surprised that Shodan showed such a small number of machines.
When dealing with consumer-grade network equipment, this is the same question that always comes to my mind: who decided these devices should have their management features open for WAN access by default? I'm still not sure if it was an early 2000s fad that nobody really thought about, or it was deliberate (and if so, why).
Re: Intel patches new ME vulnerabilities
#28Intel advisory: https://www.intel.com/content/www/us/en/security-center/advi... CVE-2018-3628 - "Buffer overflow in HTTP handler" Affected processor list (simplified reordered by me to reflect relevance and improve readability): • Core i3/i5/i7, generation 1-8 (that is, all of them) • Xeon E3-1200 v5/v6 • Xeon Scalable • Xeon W • Core 2 Duo vPro, Centrino 2 vPro
Re: Intel patches new ME vulnerabilities
#29My CPU has an HTTP server? But why?
Re: Intel patches new ME vulnerabilities
#30Earlier quoted context omitted.
Also worth noting that they're not patching it for 1st, 2nd or 3rd generation Core CPUs. I'm sure there's plenty of Sandy Bridge/Ivy Bridge CPUs in the wild, and it's not like you have an option to discontinue use of the Intel ME :(
No real advancement after Sandy Bridge was made. Only incremental 10% with each gen. That means current gen is only 2x as fast when comparing the same lines (i7 to i7). If you can't make new things better, just gimp the old ones, like Spectre/Meltdown.
Yeah, you could argue that doubling the core or thread count doubled performance in selected software but the reality is that for real world use, excluding specific corner cases, the improvement is hard to notice.
A reason to upgrade is to have a newer platform and the features that would bring, definitely not the CPU.