Is it possible to mitigate this by blocking traffic on the ports that the ME uses for communication at the router level?
Intel patches new ME vulnerabilities
81–90 of 337 posts
Re: Intel patches new ME vulnerabilities
#82Finally it happened. Here's to hoping that after being exposed to this kind of risk, enterprises and regular customers start being more inquisitive about what code gets embedded into their hardware and why.
1. https://www.wired.com/story/intel-management-engine-vulnerab...
Re: Intel patches new ME vulnerabilities
#83Earlier quoted context omitted.
Wow. The Web really has won. We have HTTP parsing failures in our CPUs .
No, this is a firmware bug. It just happens to be firmware that runs on the ME and not the main cores. The code is stored externally to the CPU along with the BIOS, and looks like it's being patched via a BIOS update.
Re: Intel patches new ME vulnerabilities
#84Has Intel offered an official "disable ME" patch? I'd like to close the door once and not worry about it again.
There are no official ways of disabling the ME. The Coreboot project and the Hardenedlinux project have worked on it, and here are some resources on their progress: https://hardenedlinux.github.io/firmware/2016/11/17/neutrali... https://www.coreboot.org/Intel_Management_Engine And here is a general writeup on the Intel chips and their "features": https://libreboot.org/faq.html#intel If Intel aren't going to patch old…
Re: Intel patches new ME vulnerabilities
#85Earlier quoted context omitted.
So, old Atoms are the only ones still usable intel systems and not vulnerable to Meltdown/Spectre/ME.
No, the Xeon Phi "accelerators" are usable too, they are basically 486 cores on modern litography (to allow for higher density/clock speeds), with a vector unit attached to them. I don't know how hard it would be to boot linux on one though...
Re: Intel patches new ME vulnerabilities
#86Earlier quoted context omitted.
Also worth noting that they're not patching it for 1st, 2nd or 3rd generation Core CPUs. I'm sure there's plenty of Sandy Bridge/Ivy Bridge CPUs in the wild, and it's not like you have an option to discontinue use of the Intel ME :(
No real advancement after Sandy Bridge was made. Only incremental 10% with each gen. That means current gen is only 2x as fast when comparing the same lines (i7 to i7). If you can't make new things better, just gimp the old ones, like Spectre/Meltdown.
Re: Intel patches new ME vulnerabilities
#87Earlier quoted context omitted.
I guess I should not be surprised that the HN community doesn't really seem to care. Intel put the Management Engine into every CPU with no choice from consumers to opt out. That alone is fairly surprising, since they knew it was a big chance it would have exploits and consumers would have no defense. But nobody reacts. Nobody cares.
I'm curious what would you consider to count as an acceptable "reaction" from the HN community? At any rate I'm unlikely to provide one. Personally I probably won't care until a Snowden-like disclosure that demonstrates exploitation of the ME in a scenario that directly affects me. i.e. I wouldn't be surprised that nation states are exploiting this in targeted fashion, but nation states already have all kinds of ways…
A good exploit is kept as invisible as possible, and when it is publicized, it may already be game over. A Trojan usually takes a lot of measure to stay undetected. Much of the recent crop of router-targeted exploits did not manifest their presence to the users in any way. Even with Snowden revelations, what has been shown was not just illicit mass data collection, but also huge reams of data already illicitly collected.
Re: Intel patches new ME vulnerabilities
#88Earlier quoted context omitted.
So, old Atoms are the only ones still usable intel systems and not vulnerable to Meltdown/Spectre/ME.
No, the Xeon Phi "accelerators" are usable too, they are basically 486 cores on modern litography (to allow for higher density/clock speeds), with a vector unit attached to them. I don't know how hard it would be to boot linux on one though...
Re: Intel patches new ME vulnerabilities
#89Earlier quoted context omitted.
I use this simply because I need to have power on/off and remoting capabilities on machines running environments where I cannot configure such capabilities (meaning I have 0 recourse, no RDP, no TeamViewer, no VNC,, etc.). The reason they don't show up on Shodan is that the search engine doesn't scan private networks and you have to explicitly configure it to be internet accessible. You have to configure AMT/ME in BI…
Does this mean that if you configure ME in your BIOS in a certain way, it is not exposed to the network? It sounds almost too good to be true: the attack surface is removed by a BIOS switch?
Unless you explicitly expose AMT to the internet you are relatively safe as long as your local network isn't compromised.
So it can be exploited only by an attacker with physical access or at least in the same network. Shodan wouldn't show you any of these machines that have ME configured and AMT blocked from crossing your router into the internet.
Re: Intel patches new ME vulnerabilities
#90I don't want a patch. I don't use that thing for anything. I want them to disable that thing by default! Leaving those backdoors open in older products should lead to a recall because the flaw was there all along.
Whether it is the unfortunate materialization of Spectre-style bugs or the deliberately insecure-by-design ME, Intel's inability to support its products is dismaying.