Is it possible to mitigate this by blocking traffic on the ports that the ME uses for communication at the router level?
Intel patches new ME vulnerabilities
161–170 of 337 posts
Re: Intel patches new ME vulnerabilities
#162Earlier quoted context omitted.
Finally? That ME thing should be nowhere near private and confidential data. There's constantly bugs being found in it [1][2]. Honestly if you are a large company, organisation, government, etc and you are using Intel or AMD products, then you are being very irresponsible. There is no excuse, enough information is out there that even a non-technical CTO should know better. 1. https://www.wired.com/story/intel-managem…
There is quite literally no viable alternative to x86 for 95% (more like 99.9%, but I am being generous) of the server and workstation market. Pretending like there is and anyone choosing x86 is irresponsible is just being a smug fool.
Re: Intel patches new ME vulnerabilities
#163Finally it happened. Here's to hoping that after being exposed to this kind of risk, enterprises and regular customers start being more inquisitive about what code gets embedded into their hardware and why.
Finally? That ME thing should be nowhere near private and confidential data. There's constantly bugs being found in it [1][2]. Honestly if you are a large company, organisation, government, etc and you are using Intel or AMD products, then you are being very irresponsible. There is no excuse, enough information is out there that even a non-technical CTO should know better. 1. https://www.wired.com/story/intel-managem…
Certainly state actors, and militaries, have somebody somewhere being crazy mad about this and the right pay grade to act.
Re: Intel patches new ME vulnerabilities
#164Earlier quoted context omitted.
I guess I should not be surprised that the HN community doesn't really seem to care. Intel put the Management Engine into every CPU with no choice from consumers to opt out. That alone is fairly surprising, since they knew it was a big chance it would have exploits and consumers would have no defense. But nobody reacts. Nobody cares.
I care. I removed ME from mine. I'd prefer to use a competitor but the only viable one is AMD and their equivalent tech is less documented and no known way to disable it exists. Disabling/removing ME is possible for intel stuff so intel is actually the better choice if this is important to you.
Re: Intel patches new ME vulnerabilities
#165I don't want a patch. I don't use that thing for anything. I want them to disable that thing by default! Leaving those backdoors open in older products should lead to a recall because the flaw was there all along.
Re: Intel patches new ME vulnerabilities
#166My CPU has an HTTP server? But why?
Your CPU actually runs its own entire, separate operating system - MINIX. https://www.cs.vu.nl/~ast/intel/
>"I got another clue when your engineers began asking me to make a number of changes to MINIX, for example, making the memory footprint smaller and adding #ifdefs around pieces of code so they could be statically disabled by setting flags in the main configuration file."
Why would Intel ask Tannenbaum to make changes for them? Doesn't intel have unlimited resources?
Re: Intel patches new ME vulnerabilities
#167Earlier quoted context omitted.
No real advancement after Sandy Bridge was made. Only incremental 10% with each gen. That means current gen is only 2x as fast when comparing the same lines (i7 to i7). If you can't make new things better, just gimp the old ones, like Spectre/Meltdown.
well ddr4 is a huge improvement
https://img.purch.com/r/711x457/aHR0cDovL21lZGlhLmJlc3RvZm1p...
Re: Intel patches new ME vulnerabilities
#168Earlier quoted context omitted.
Certainly if the lifespan of Intel chips turns out to be much shorter than the marketplace expected (because Intel is unable to provide security updates), that affects the value of Intel products and ought to inform future buying decisions. Whether it is the unfortunate materialization of Spectre-style bugs or the deliberately insecure-by-design ME, Intel's inability to support its products is dismaying.
The ordinary life cycle of an Intel CPU is the five t̶h̶r̶e̶e̶ year depreciation schedule in the US tax system. The life cycle for Intel's most important customers is less and is based on operating cost in large data centers and these are driven by density, throughput, and energy utilization. Traditionally this has been two years or less as reflected in Intel's tick-tock iteration strategy. The critical life cycle fo…
Re: Intel patches new ME vulnerabilities
#169I'm surprised by the lack of media coverage: Intel is deliberately leaving billions of CPUs vulnerable. For a $200 billion company, refusing to spend some ressources to patch all generations is irresponsible. Think of how many governments still use <2012 CPUs.
We used to be answer with tin foil hat jokes about jokes on mass surveillance. Then came PRISM and nobody is laughing now.
Maybe it's going to be the same with this. We will learn many years later it was enforced by some state or economical entity that benefit greatly to have a standard unpatchable backdoor on most laptop and servers on the planet.
Re: Intel patches new ME vulnerabilities
#170>Perhaps the only consolation is that for CVE-2018-3628, Intel says that exploitation is possible only from the same subnet. That is at least a little more comforting.