Intel patches new ME vulnerabilities
231–240 of 337 posts
Re: Intel patches new ME vulnerabilities
#232Earlier quoted context omitted.
Also worth noting that they're not patching it for 1st, 2nd or 3rd generation Core CPUs. I'm sure there's plenty of Sandy Bridge/Ivy Bridge CPUs in the wild, and it's not like you have an option to discontinue use of the Intel ME :(
There's always me_cleaner. It's a bit of a pain and requires hardware access to run but better than being exposed to an unpatchable vuln. I encourage every hackspace to set up an ME removal station (I'm building one for EMF Camp this year, and will document it so others can easily replicate)
Re: Intel patches new ME vulnerabilities
#233Purism[0] sell nice MBP-style, Debian-based laptops with modern Intel processors with the NSA's 'High Assurance Platform' bit set, and as much of the ME code removed as possible. It still runs briefly at boot, but this is the most-disabled you can currently get on any i3/i5/i7 processor[1].
[0]: https://puri.sm/
[1]: https://puri.sm/posts/deep-dive-into-intel-me-disablement/
System76 are planning to do something similar[2].
[2]: http://blog.system76.com/post/168050597573/system76-me-firmw...
The last Intel processors where the ME could be removed entirely without bricking, were the non-AMT Core Duos (2008ish), which were used on the Thinkpad T400 (good for your biceps) and the X200/X200T (thick, but compact, even by today's standards).
Various companies (most prominently the Ministry of Freedom in the UK) sell these models with the ME completely removed, and a completely Free Software boot process via LibreBoot (a subset of coreboot). You can find a full list of suppliers on the FSF's 'Respects Your Freedom' hardware page[3]. Most of them will also remove the ME from a compatible laptop you send them, as a service.
[3]: https://www.fsf.org/resources/hw/endorsement/respects-your-f...
These machines are also 'naturally' resistant to both Spectre and Meltdown, and obviously have no ME to exploit. None of the Intel horror-shows of the last few years seem to have touched them.
I previously thought that running an old-machine for largely hypothetical freedoms was bizarre. After these CVEs, I'm beginning to re-examine how bizarre it really is. And I do miss those old ThinkPad keyboards :)
Re: Intel patches new ME vulnerabilities
#234I don't want a patch. I don't use that thing for anything. I want them to disable that thing by default! Leaving those backdoors open in older products should lead to a recall because the flaw was there all along.
Re: Intel patches new ME vulnerabilities
#235Earlier quoted context omitted.
Wow. The Web really has won. We have HTTP parsing failures in our CPUs .
I'm waiting for the day where Node.js runs inside the CPU, downloads NPM packages, and then a left-pad happens. Mark my words.
Bring on open source hardware.
Re: Intel patches new ME vulnerabilities
#236Earlier quoted context omitted.
Usually the amortization of such systems is ~ 4 years. But many smaller companies choose to stay with the old systems a little longer, 5, or even 6 years lately. Simply because there is no push performance wise. The main motivation for upgrade is software support (usually for the OS, driven by Microsoft), or failure rates for the older systems. And that's for the desktop side. For servers they tend to be taken out of…
> For servers they tend to be taken out of commission when the service they provide is migrated to a whole new platform Or when the service contract expires or is too expensive to extend. You can't run a server of any importance without a service contract; it can be the difference between all the server's users and services being down for hours or a more than a week, and between IT management keeping their job for ho…
It's hard to imagine not being able to find a replacement in more than a week, especially if one skipped service contract and just bought a spare or two with a fraction of the savings.
It's why moving to cloud infrastructure can be so much cheaper for these shops.
Of course, if it is a trivial size, like a single server at a small business, that's a different story.
Re: Intel patches new ME vulnerabilities
#237Earlier quoted context omitted.
Do you have any citations that companies are replacing their intel processors every 2 years? That is not inline with what I have seen.
extrapolate as you will... https://aws.amazon.com/blogs/aws/ec2-instance-history/ I didn’t have one, but it seemed like a worthwhile thing to have and so I spent a few minutes putting the following list together (these are all announcement dates): August 2006 – m1.small. October 2007 – m1.large, m1.xlarge. May 2008 – c1.medium, c1.xlarge. October 2009 – m2.2xlarge, m2.4xlarge. February 2010 – m2.xlarge. July 2010 – c…
Re: Intel patches new ME vulnerabilities
#238I don't want a patch. I don't use that thing for anything. I want them to disable that thing by default! Leaving those backdoors open in older products should lead to a recall because the flaw was there all along.
As I understand it, ME is used to remotely control the processor like in a datacenter. If a datacenter is buying hundreds of thousands of these it makes sense to have it on by default so their people don't have to go in and turn anything on. As much as I recognize it as a vulnerability (to the extreme), it doesn't make sense to have it off by default. They should certainly support a way to _permanently_ disable it. I…
Unless you have a fuse to be pulled, or blown.
Re: Intel patches new ME vulnerabilities
#239Earlier quoted context omitted.
> For servers they tend to be taken out of commission when the service they provide is migrated to a whole new platform Or when the service contract expires or is too expensive to extend. You can't run a server of any importance without a service contract; it can be the difference between all the server's users and services being down for hours or a more than a week, and between IT management keeping their job for ho…
That's just the "enterprise" hardware model. It's overall extremely expensive to begin with and may have made sense back in the days of proprietary hardware, but makes no sense for a commodity hardware installation beyond a trivial size. It's hard to imagine not being able to find a replacement in more than a week, especially if one skipped service contract and just bought a spare or two with a fraction of the saving…
> makes no sense for a commodity hardware installation beyond a trivial size
It's not the commodity hardware - x86 servers have been mostly commodity hardware for decades - it's virtualization (or other rapid recovery and migration tech) that makes it work.
Re: Intel patches new ME vulnerabilities
#240Earlier quoted context omitted.
As I understand it, ME is used to remotely control the processor like in a datacenter. If a datacenter is buying hundreds of thousands of these it makes sense to have it on by default so their people don't have to go in and turn anything on. As much as I recognize it as a vulnerability (to the extreme), it doesn't make sense to have it off by default. They should certainly support a way to _permanently_ disable it. I…
Their motivations are irrelevant. Consumers aren't datacenters.
Consumers have also shown zero intention of paying more for secure devices. Until we have a public ME hack with real consequences, I do not expect that to change.