Live data from Hacker News

Intel patches new ME vulnerabilities

blog.ptsecurity.com

41–50 of 337 posts

Re: Intel patches new ME vulnerabilities

#41
post #2

Intel advisory: https://www.intel.com/content/www/us/en/security-center/advi... CVE-2018-3628 - "Buffer overflow in HTTP handler" Affected processor list (simplified reordered by me to reflect relevance and improve readability): • Core i3/i5/i7, generation 1-8 (that is, all of them) • Xeon E3-1200 v5/v6 • Xeon Scalable • Xeon W • Core 2 Duo vPro, Centrino 2 vPro

Wow.

The Web really has won.

We have HTTP parsing failures in our CPUs.

Re: Intel patches new ME vulnerabilities

#42
post #12

Earlier quoted context omitted.

Grandpa, it's time to upgrade.

Why? Because it's been longer than intel would like since parent gave them money?

If Intel has made currently processes ultra fast recently that wouldn't be an issue, but the Intel Core i7 2700 is actually not that slow. Roughly comparable, at least within 20%, of other 4 core + 4 HT Intel processors.

Re: Intel patches new ME vulnerabilities

#43

I finally pushed the button on my lenovo T450S there is a setting in the bios to delete the AMT. While the best route is to reprogram... I would just rather click one button and set bios passwords afterwards.

The ME (AMT) is never actually disabled or deleted as long as the FW is there and running.

Plus you should take advantage of the fact that the 450 is still supported and gets a ME FW update.

Yesterday I updated all my machines with Gen 4 CPU with new BIOS, new ME FW, and (surprisingly) new TPM FW. The Gen 3 CPU machines barely got a BIOS update for Metldown/Spectre and that's it.

Re: Intel patches new ME vulnerabilities

#46
post #40
post #15

Earlier quoted context omitted.

I'm oddly lucky that I based my fanless server off an old Atom platform.

"Luckily" most old Atoms will never get mitigations for Meltdown/Spectre :). So if you're using an Intel CPU today you'll just have to pick your poison.

I was under the impression that they weren't susceptible.

Re: Intel patches new ME vulnerabilities

#48
post #2

Intel advisory: https://www.intel.com/content/www/us/en/security-center/advi... CVE-2018-3628 - "Buffer overflow in HTTP handler" Affected processor list (simplified reordered by me to reflect relevance and improve readability): • Core i3/i5/i7, generation 1-8 (that is, all of them) • Xeon E3-1200 v5/v6 • Xeon Scalable • Xeon W • Core 2 Duo vPro, Centrino 2 vPro

I guess I should not be surprised that the HN community doesn't really seem to care.

Intel put the Management Engine into every CPU with no choice from consumers to opt out. That alone is fairly surprising, since they knew it was a big chance it would have exploits and consumers would have no defense.

But nobody reacts. Nobody cares.

Re: Intel patches new ME vulnerabilities

#49
post #40
post #15

Earlier quoted context omitted.

I'm oddly lucky that I based my fanless server off an old Atom platform.

"Luckily" most old Atoms will never get mitigations for Meltdown/Spectre :). So if you're using an Intel CPU today you'll just have to pick your poison.

Running only trusted code on a server is much simpler than on a desktop / laptop: no Javascript in browser.

Re: Intel patches new ME vulnerabilities

#50
post #15
post #2

Intel advisory: https://www.intel.com/content/www/us/en/security-center/advi... CVE-2018-3628 - "Buffer overflow in HTTP handler" Affected processor list (simplified reordered by me to reflect relevance and improve readability): • Core i3/i5/i7, generation 1-8 (that is, all of them) • Xeon E3-1200 v5/v6 • Xeon Scalable • Xeon W • Core 2 Duo vPro, Centrino 2 vPro

I'm oddly lucky that I based my fanless server off an old Atom platform.

AMD seems considerably more on top of the security game. As for ME, make sure you avoid any system on which it is enabled.
Post reply on HN