Live data from Hacker News

Intel patches new ME vulnerabilities

blog.ptsecurity.com

121–130 of 337 posts

Re: Intel patches new ME vulnerabilities

#121

Earlier quoted context omitted.

I thought you can in C2D (Nehalem?) era ThinkPads? https://libreboot.org/ and you can minimize ME in Sandy and Ivy Bridge, using ME_Cleaner? edit: according to sounds' comment* in HN (2016), The ME is purportedly placed in "recovery" mode [*] https://news.ycombinator.com/item?id=13056997

Minimize != Disable.

You can disable the first generation ME

https://libreboot.org/docs/hardware/gm45_remove_me.html

after that it's impossible though.

Re: Intel patches new ME vulnerabilities

#122
post #2

Intel advisory: https://www.intel.com/content/www/us/en/security-center/advi... CVE-2018-3628 - "Buffer overflow in HTTP handler" Affected processor list (simplified reordered by me to reflect relevance and improve readability): • Core i3/i5/i7, generation 1-8 (that is, all of them) • Xeon E3-1200 v5/v6 • Xeon Scalable • Xeon W • Core 2 Duo vPro, Centrino 2 vPro

I guess I should not be surprised that the HN community doesn't really seem to care. Intel put the Management Engine into every CPU with no choice from consumers to opt out. That alone is fairly surprising, since they knew it was a big chance it would have exploits and consumers would have no defense. But nobody reacts. Nobody cares.

I care. I removed ME from mine. I'd prefer to use a competitor but the only viable one is AMD and their equivalent tech is less documented and no known way to disable it exists. Disabling/removing ME is possible for intel stuff so intel is actually the better choice if this is important to you.

Re: Intel patches new ME vulnerabilities

#123
Could Intel ME be disabled in UEFI firmware setup (if the firmware were to offer a UI for it?) Or it is something that's physically enabled/disabled on the CPU and totally orthogonal to UEFI firmware?

Ergo, could the computer manufacturer release a firmware update providing such an interface option in firmware setup if they really wanted to? Or are they stuck once the product is released?

Re: Intel patches new ME vulnerabilities

#124

Earlier quoted context omitted.

I thought you can in C2D (Nehalem?) era ThinkPads? https://libreboot.org/ and you can minimize ME in Sandy and Ivy Bridge, using ME_Cleaner? edit: according to sounds' comment* in HN (2016), The ME is purportedly placed in "recovery" mode [*] https://news.ycombinator.com/item?id=13056997

ME cleaner is not claiming to render ME completely ineffective, as far as I remember.

me_cleaner removes most of the ME code (including the HTTP parser listed here) and then causes it to crash after bringing up the system, so it's impossible to communicate with the processor running ME. That's about as good as it gets.

Re: Intel patches new ME vulnerabilities

#125
post #123

Could Intel ME be disabled in UEFI firmware setup (if the firmware were to offer a UI for it?) Or it is something that's physically enabled/disabled on the CPU and totally orthogonal to UEFI firmware? Ergo, could the computer manufacturer release a firmware update providing such an interface option in firmware setup if they really wanted to? Or are they stuck once the product is released?

You can disable ME by giving it a firmware image to run that does nothing. The me_cleaner approach is to keep the module that brings up the hardware and then give it a command causing it to crash, which is as good as that. A firmware update can definitely do this too.

Re: Intel patches new ME vulnerabilities

#126
post #118

I don't want a patch. I don't use that thing for anything. I want them to disable that thing by default! Leaving those backdoors open in older products should lead to a recall because the flaw was there all along.

It's much worse than that. This "Intel patches" thing is a lie - or at least it doesn't mean that your systems are patched, which is what 99.9% of people reading such headlines believe happened. Intel only patches its own firmware, but it's normally up to manufacturers to update that firmware for devices. So most PC/laptops users really won't even see these patches. And I agree with your main point. For one of the mo…

How is this Intel ME CPU patch deployed and where does it actually go? Is there some tiny flash in the CPU itself where the Intel ME code resides? Or does the patch get deployed as part of a UEFI firmware update, but isn't actually part of UEFI firmware, and somehow the CPU can reach out and grab its own updates from UEFI?

Re: Intel patches new ME vulnerabilities

#127
post #106

Earlier quoted context omitted.

That's quite a conspiracy theory you got there. Things like these make people look at AMD again.

It doesn't have to have been a full-blown plan from years ago in order to be a viable strategy. Intel can choose planned obsolescence going forward today for selected products by not developing or releasing security patches. The extent to which this particular strategic business option was discussed during the design phase of the ME is hard to know from the outside. Surely someone within Intel pointed out that the ME…

There are many ways to to planned obsolescence. I'm sure there is a way to just manufacture the chips such that they degrade in a few years.

Planned obsolescence through major security bugs doesn't sound very smart to me.

I don't get a vibe that Intel is enjoying this publicity or the presumed replace of those chips. My understanding is that AMD is quite competitive today in the data center.

Re: Intel patches new ME vulnerabilities

#128

Earlier quoted context omitted.

The ordinary life cycle of an Intel CPU is the five t̶h̶r̶e̶e̶ year depreciation schedule in the US tax system. The life cycle for Intel's most important customers is less and is based on operating cost in large data centers and these are driven by density, throughput, and energy utilization. Traditionally this has been two years or less as reflected in Intel's tick-tock iteration strategy. The critical life cycle fo…

Do you have any citations that companies are replacing their intel processors every 2 years? That is not inline with what I have seen.

More like 5 years, or even longer, where I work.

We have some 7 year old Dell servers that are still chugging along, performing their duties as well as ever.

Re: Intel patches new ME vulnerabilities

#129
post #118

I don't want a patch. I don't use that thing for anything. I want them to disable that thing by default! Leaving those backdoors open in older products should lead to a recall because the flaw was there all along.

It's much worse than that. This "Intel patches" thing is a lie - or at least it doesn't mean that your systems are patched, which is what 99.9% of people reading such headlines believe happened. Intel only patches its own firmware, but it's normally up to manufacturers to update that firmware for devices. So most PC/laptops users really won't even see these patches. And I agree with your main point. For one of the mo…

In all honesty "most PC/laptops users" will never need these patches because their systems don't have the ME firmware. You need specific CPU, specific chipset, specific NIC, and the ME FW. Which you're only going to find in OEM systems marked as such - vPro. It's the same as the Meltdown/Spectre patches where Intel updates the code but it's up to the manufacturer to include it where applicable.

A regular desktop motherboard might include the correct HW but the manufacturer won't bother including the ME FW.

And companies like Lenovo, HP, and Dell already offer the updated ME firmware.

Re: Intel patches new ME vulnerabilities

#130
post #126
post #118

Earlier quoted context omitted.

It's much worse than that. This "Intel patches" thing is a lie - or at least it doesn't mean that your systems are patched, which is what 99.9% of people reading such headlines believe happened. Intel only patches its own firmware, but it's normally up to manufacturers to update that firmware for devices. So most PC/laptops users really won't even see these patches. And I agree with your main point. For one of the mo…

How is this Intel ME CPU patch deployed and where does it actually go? Is there some tiny flash in the CPU itself where the Intel ME code resides? Or does the patch get deployed as part of a UEFI firmware update, but isn't actually part of UEFI firmware, and somehow the CPU can reach out and grab its own updates from UEFI?

Usually a separate patch, an ME firmware patch. The ME is physically located in the chipset but I'm not entirely sure where the FW resides, whether the chipset or a flash on the motherboard (sharing with the system UEFI/BIOS).
Post reply on HN