Live data from Hacker News

Intel patches new ME vulnerabilities

blog.ptsecurity.com

191–200 of 337 posts

Re: Intel patches new ME vulnerabilities

#191
post #67

I wonder what other (somehow) laptop-worthy CPUs offer a better management engine story? * AMD processors do have an equivalent management engine (PSP), but I didn't hear anything about remote exploits for it. * Beefier ARM CPUs also have something like a management engine ("trustzone" only accessible to the manufacturer). I have no idea if it has any remote-access capabilities on any common hardware. On RPi the trus…

In order to support reliable mass-remote-update, what is needed is an ME which is disabled by default but can be enabled via a non-reversible opt-in, such as breaking off a pin. Then a supplier could configure bulk orders to enable the ME and it would be left up to the customer to choose the security-for-convenience tradeoff.

Why break off? Normal physical switches on motherboards work just as well.

Re: Intel patches new ME vulnerabilities

#192
Isn’t this vulnerability based on AMT, which is based on ME but disabled by default? Even then, every setup I’ve seen have AMT (a separate Ethernet interface) behind a firewall and is only accessible via local network. The outrage is hardly justified.

Re: Intel patches new ME vulnerabilities

#194

Earlier quoted context omitted.

Finally? That ME thing should be nowhere near private and confidential data. There's constantly bugs being found in it [1][2]. Honestly if you are a large company, organisation, government, etc and you are using Intel or AMD products, then you are being very irresponsible. There is no excuse, enough information is out there that even a non-technical CTO should know better. 1. https://www.wired.com/story/intel-managem…

There is quite literally no viable alternative to x86 for 95% (more like 99.9%, but I am being generous) of the server and workstation market. Pretending like there is and anyone choosing x86 is irresponsible is just being a smug fool.

I would say the server market could easily adapt to Arm, Power or RISC. However I would concede it's very difficult to replace the desktop/laptop workstation. However Chromebooks are making great strives on this. Yes, they are still sending lots of data to Googles servers, but they do a lot of opensource work. Look at coreboot with depthcharge, which can give you a pretty free (not 100%) Arm notebook.

Re: Intel patches new ME vulnerabilities

#195

I think most devices have similar vulnerabilities which aren't well known and hard to defend against, like the separate processor in most phones. Worth reading: https://news.ycombinator.com/item?id=6722292

Which is a good reason not to feel smug if your device isn't an Intel device, but not an excuse for the behaviour of Intel.

Re: Intel patches new ME vulnerabilities

#196
post #177

I don't want a patch. I don't use that thing for anything. I want them to disable that thing by default! Leaving those backdoors open in older products should lead to a recall because the flaw was there all along.

Buy an X200, install libreboot, and you won't have an ME anymore :)

And let Intel know that you and your business won't be buying new Intel machines until they provide a way of completely disabling/removing the ME chip.

Re: Intel patches new ME vulnerabilities

#198

Isn’t this vulnerability based on AMT, which is based on ME but disabled by default? Even then, every setup I’ve seen have AMT (a separate Ethernet interface) behind a firewall and is only accessible via local network. The outrage is hardly justified.

One day it's "[thing] shouldn't be exploitable because [mitigation]", the next it's "welp, [mitigation] has a bug in it and they've exploited [thing]."

Re: Intel patches new ME vulnerabilities

#199

Isn’t this vulnerability based on AMT, which is based on ME but disabled by default? Even then, every setup I’ve seen have AMT (a separate Ethernet interface) behind a firewall and is only accessible via local network. The outrage is hardly justified.

One day it's "[thing] shouldn't be exploitable because [mitigation]", the next it's "welp, [mitigation] has a bug in it and they've exploited [thing]."

Right, and the network security is always part of the attack surface of an enterprise. What I’m saying, though, is that the component that’s vulnerable is 1) disabled by default and 2) near impossible for a consumer to enable.
Post reply on HN