Live data from Hacker News

Intel patches new ME vulnerabilities

blog.ptsecurity.com

251–260 of 337 posts

Re: Intel patches new ME vulnerabilities

#251

I don't want a patch. I don't use that thing for anything. I want them to disable that thing by default! Leaving those backdoors open in older products should lead to a recall because the flaw was there all along.

I hope the bad PR from ME garbage follows them to their corporate grave. It's absolutely shameless.

Re: Intel patches new ME vulnerabilities

#252

Just a note that if you want to avoid Intel's disastrous Management Engine, there are companies you can support that disable it. Purism[0] sell nice MBP-style, Debian-based laptops with modern Intel processors with the NSA's 'High Assurance Platform' bit set, and as much of the ME code removed as possible. It still runs briefly at boot, but this is the most-disabled you can currently get on any i3/i5/i7 processor[1].…

Purism published some reverse engineering information and received a "polite request" to remove the post. Hmm...

https://web.archive.org/web/20180407232908/https://puri.sm/p...

Re: Intel patches new ME vulnerabilities

#253
post #90

Earlier quoted context omitted.

Certainly if the lifespan of Intel chips turns out to be much shorter than the marketplace expected (because Intel is unable to provide security updates), that affects the value of Intel products and ought to inform future buying decisions. Whether it is the unfortunate materialization of Spectre-style bugs or the deliberately insecure-by-design ME, Intel's inability to support its products is dismaying.

The ordinary life cycle of an Intel CPU is the five t̶h̶r̶e̶e̶ year depreciation schedule in the US tax system. The life cycle for Intel's most important customers is less and is based on operating cost in large data centers and these are driven by density, throughput, and energy utilization. Traditionally this has been two years or less as reflected in Intel's tick-tock iteration strategy. The critical life cycle fo…

Depreciation determines the minimum age not the maximum. I've seen XP boxes still in use.

Re: Intel patches new ME vulnerabilities

#254

I don't want a patch. I don't use that thing for anything. I want them to disable that thing by default! Leaving those backdoors open in older products should lead to a recall because the flaw was there all along.

It’s difficult to see the reason for including this on by default other than some conspiracy involving government agencies and a lot of money.

I've been thinking on this a lot as well. Could go either way as far as I'm concerned.

Re: Intel patches new ME vulnerabilities

#255
post #109
post #41

Earlier quoted context omitted.

Wow. The Web really has won. We have HTTP parsing failures in our CPUs .

I'm waiting for the day where Node.js runs inside the CPU, downloads NPM packages, and then a left-pad happens. Mark my words.

Maybe we'll both get to laugh when we're 90

Re: Intel patches new ME vulnerabilities

#256

Earlier quoted context omitted.

There's always me_cleaner. It's a bit of a pain and requires hardware access to run but better than being exposed to an unpatchable vuln. I encourage every hackspace to set up an ME removal station (I'm building one for EMF Camp this year, and will document it so others can easily replicate)

Please do! I would love to do this, but am far too much of a sissy to mess with SPI flash. I've subscribed to your RSS feed. Do drop any guides/artifacts in the Noisebridge IRC when you have them :)

Mitch will be at EMF, probably in a tent adjacent to mine. So I'll just ask him to bring the knowledge back to noisebridge.

Re: Intel patches new ME vulnerabilities

#257

Earlier quoted context omitted.

What insurance comapny insures that? What company offers SLAs like that? I want in on that deal!

Why is this an insurance issue? Do you expect the servers to catch on fire?

Well the distributors stamp the top of the server with a sticker that says it's safely operable for 2 years, so no one is going to insure it for more, of course. Might be European thing, though; good think for enthusiasts is that it's common to contact a company and join their next 2 years buyout and acquire cheap hardware.

Re: Intel patches new ME vulnerabilities

#258

Earlier quoted context omitted.

I've seen this claim a few times but never seen it solidly verified. Can anyone make the case either way?

Well, we don't know what disabling PSP does, but we know there is an option in BIOS to do that: https://www.google.com/search?q=BIOS+psp+support&tbm=isch

Yeah, I'm aware of the BIOS option, but haven't seen any reliably sourced info on what its exact effect is.

Re: Intel patches new ME vulnerabilities

#259
post #236

Earlier quoted context omitted.

That's just the "enterprise" hardware model. It's overall extremely expensive to begin with and may have made sense back in the days of proprietary hardware, but makes no sense for a commodity hardware installation beyond a trivial size. It's hard to imagine not being able to find a replacement in more than a week, especially if one skipped service contract and just bought a spare or two with a fraction of the saving…

Yes, somehow I thought the GP was talking about small business, but I see there is nothing in the text that says so (at least not now). Yes, of course, with cloud infrastructure or just virtualization and spare hardware, service contracts have much less value. > makes no sense for a commodity hardware installation beyond a trivial size It's not the commodity hardware - x86 servers have been mostly commodity hardware…

> Yes, of course, with cloud infrastructure or just virtualization and spare hardware, service contracts have much less value.

My assertion is that service contracts for hardware have zero value for commodity hardware installations (beyond trivial size). To whit, they are, invariably, a scam.

Server hardware fails vanishingly rarely, with specific, notable exceptions of certain components. Those exceptions have predictable [1] failure rates that are therefore straightforward to budget and/or engineer around. Managers don't know to insist on this, so the scam persists.

This was true even before the advent/popularity of virtualization (and therefore "cloud" techniques).

It's also true regardless of whether or not one keeps spares on hand. With commodity hardware, vendors always have plenty of spares.. one just hasn't purchased them in advance, so there's an increased latency (not entirely unlike the spares available under a service contract).

> It's not the commodity hardware - x86 servers have been mostly commodity hardware for decades - it's virtualization (or other rapid recovery and migration tech) that makes it work.

That's where I disagree, at least partly, if I understand correctly the kind of tech you're referring to.

Those software solutions are generally just about convenience, or, ideally, reducing recovery time in the case of a non-redundant architecture. Even then, they might turn hours into minutes, not weeks into minutes.

More importantly, it's not that software that makes this work. It's the commodity hardware (and, arguably, commodity software/firmware hiding within) that makes it work. If a disk fails, any same or larger [1] can be used as a replacement. Same for RAM or even full servers. It doesn't have to be the same brand because that's the point of it being a commodity. That fact completely eliminates any problem of being down for a week due to hardware failure. In a major tech hub city, getting something delivered same day might not even require paying a premium.

Before virtualization or any similar abstraction layer, one could just move disks to a new server (best case) or restore from a backup (worst case).

[1] Other than "black swan" events like the flooding in Thailand that wrecked predictability (and reliability overall) for a generation of HDDs. Even then, if one made assumptions based on warranty length changes, those would have been close enough.

[2] Well, OK, one does have to be careful to meet minimum performance, especially for SSDs, but even a failure there won't kill basic functionality

Re: Intel patches new ME vulnerabilities

#260

Just a note that if you want to avoid Intel's disastrous Management Engine, there are companies you can support that disable it. Purism[0] sell nice MBP-style, Debian-based laptops with modern Intel processors with the NSA's 'High Assurance Platform' bit set, and as much of the ME code removed as possible. It still runs briefly at boot, but this is the most-disabled you can currently get on any i3/i5/i7 processor[1].…

This comment should be on top.
Post reply on HN