Live data from Hacker News

Intel patches new ME vulnerabilities

blog.ptsecurity.com

311–320 of 337 posts

Re: Intel patches new ME vulnerabilities

#311
post #90

I don't want a patch. I don't use that thing for anything. I want them to disable that thing by default! Leaving those backdoors open in older products should lead to a recall because the flaw was there all along.

Certainly if the lifespan of Intel chips turns out to be much shorter than the marketplace expected (because Intel is unable to provide security updates), that affects the value of Intel products and ought to inform future buying decisions. Whether it is the unfortunate materialization of Spectre-style bugs or the deliberately insecure-by-design ME, Intel's inability to support its products is dismaying.

i think you are absolutely correct. It is faulty mostly unwanted, not properly test feature. Need to be re-called and replaced at Intel cost. Period.

Re: Intel patches new ME vulnerabilities

#312

Earlier quoted context omitted.

Why is this an insurance issue? Do you expect the servers to catch on fire?

Well the distributors stamp the top of the server with a sticker that says it's safely operable for 2 years, so no one is going to insure it for more, of course. Might be European thing, though; good think for enthusiasts is that it's common to contact a company and join their next 2 years buyout and acquire cheap hardware.

Servers are "safely" operable until they die. The failure mode is that the machine stops operating. If your system has redundancy built in it keeps working possibly at reduced capacity. If not it stops. If its essential that service not be interrupted you build in redundancy and ensure that it fails in a safe way if it does.

I'm not sure where safety or insurance comes into this discussion at all.

People upgrade sooner because they stand to gain more than the upgrade costs not because its not safe to operate.

Re: Intel patches new ME vulnerabilities

#313
post #284
post #277

Earlier quoted context omitted.

FWIW, it’s a completely different architecture. GCN has support all the way down to 1.0. The graphics card in your EEE PC is upgradable, if you’re feeling adventurous[1]. [1] https://www.ifixit.com/Guide/Asus+Eee+PC+1008ha+Graphics+Car...

I know, and this kind of attitude regarding drivers is what as graphics oriented person, eventually pushed me back into the Windows/OS X world. The graphics card was working perfectly fine before they decided to reboot driver support. Now with the legacy driver I have to force enable acceleration and even then I sometimes get the feeling it isn't really working, given how the fan behaves when watching movies on the g…

Nvidia has historically supported new drivers/Xorg for old hardware for aprox 10 years whereas amd/ati cards still available at retail have been unsupported in as little as 3 years time leaving you with open source drivers as your only other option if you want to install a new version of your distro with your older hardware.

The fact that they are open source is of course a good thing whats not is that they were at one time less than half the performance.

The new drivers from AMD gpus are both open source AND performant.

Basically the proper strategy 2003-2017 was to buy nvidia and install the binary drivers.

At present you can go with either so long as you aren't buying hardware too old to be supported by the new amd drivers. I'm still using nvidia on all my hardware but maybe I will give amd a try again next time around.

It sucks that its complicated but its not as complicated as it seems.

Re: Intel patches new ME vulnerabilities

#314

Earlier quoted context omitted.

AMD has an ME equivalent, which is approximately as prevalent. It’s still a DRM/DMCA-protected remote access CPU on your CPU. What could go wrong? Buying Librebooted machines isn’t directly supporting Intel.

But not on AMD machines from 2012 and before. You can buy a high-end motherboard (KGPE-D16) that can run libreboot and 2 16core Opteron 62xx cpu's with 192GB ram. You don't have to go the old and relatively slow thinkpad route to achieve freedom.

Thank you for this information!

I’m interested in something like this (though maybe not as beefy) for self-hosting.

Are there any companies that sell the gear you describe, or guides/wikis on getting set up?

Re: Intel patches new ME vulnerabilities

#315
post #284

Earlier quoted context omitted.

I know, and this kind of attitude regarding drivers is what as graphics oriented person, eventually pushed me back into the Windows/OS X world. The graphics card was working perfectly fine before they decided to reboot driver support. Now with the legacy driver I have to force enable acceleration and even then I sometimes get the feeling it isn't really working, given how the fan behaves when watching movies on the g…

Nvidia has historically supported new drivers/Xorg for old hardware for aprox 10 years whereas amd/ati cards still available at retail have been unsupported in as little as 3 years time leaving you with open source drivers as your only other option if you want to install a new version of your distro with your older hardware. The fact that they are open source is of course a good thing whats not is that they were at o…

I know Linux since Slackware 2.0, so I am quite used to these issues regarding graphics cards, including the fun days of manually writing my own xorg.conf file.

Eventually one gets fed up and wants the laptop just to work.

Re: Intel patches new ME vulnerabilities

#316

Earlier quoted context omitted.

But not on AMD machines from 2012 and before. You can buy a high-end motherboard (KGPE-D16) that can run libreboot and 2 16core Opteron 62xx cpu's with 192GB ram. You don't have to go the old and relatively slow thinkpad route to achieve freedom.

Thank you for this information! I’m interested in something like this (though maybe not as beefy) for self-hosting. Are there any companies that sell the gear you describe, or guides/wikis on getting set up?

Answering my own question, suppliers of boards are available on the FSF's site (these are the boards which the FSF use themselves):

https://fsf.org/ryf

Re: Intel patches new ME vulnerabilities

#317

Earlier quoted context omitted.

I consult in verticals where uptime really matters. It's not unusual though, but yes, I know that companies do this. They usually don't care about insurance/hardware SLA though. Old hardware needs to be emulated.

Oh I'm sure some companies do it. Whatever it is you can be certain someone is doing it :). But it's nowhere near being a rule in Europe. And TBH replacing servers after 2 years because you're worried about uptime feels like a horrible overreaction and self harming at the same time. Servers that are meant to provide 99.999% uptime (so 5 nines or above, or maximum 6min downtime per year) are built to run for far longe…

> And TBH replacing servers after 2 years because you're worried about uptime feels like a horrible overreaction and self harming at the same time.

I agree. Such a tactic, in the face of modern high-availability systems design (including the notion of servers being "cattle not pets"), seems actively harmful, other than, perhaps, introducing a something akin to Netflix's "chaos monkey" into the system.

I could understand pre-emptive replacement of non-hot-swappable components, but only if they're known to degrade over time [1] and only if the server is already otherwise out of service. Even then, I'd consider 3 years the minimum.

> Servers that are meant to provide 99.999% uptime (so 5 nines or above, or maximum 6min downtime per year) are built to run for far longer than 2 years.

This kind of design sounds like it's from a different "world" (mainframes) or era (proprietary, even if x86-based, Unix hardware of the 90s), not commodity x86 servers.

[1] so, maybe RAM, which has increasing CEs with age/usage, though UEs appear to be skewed toward early RAM life and therefore the bad apples are eliminated early. non-pluggable PSUs. fans. very old internal-only HDDs.

Re: Intel patches new ME vulnerabilities

#318
post #237

Earlier quoted context omitted.

extrapolate as you will... https://aws.amazon.com/blogs/aws/ec2-instance-history/ I didn’t have one, but it seemed like a worthwhile thing to have and so I spent a few minutes putting the following list together (these are all announcement dates): August 2006 – m1.small. October 2007 – m1.large, m1.xlarge. May 2008 – c1.medium, c1.xlarge. October 2009 – m2.2xlarge, m2.4xlarge. February 2010 – m2.xlarge. July 2010 – c…

Unfortunately, announcement dates only give one endpoint of the timeline. The other endpoint, retirement date (from even previous-generation availability), is crucial to any anlysis.

Yeah, exactly. No argument that Intel keeps improving their processors. But at what cycle is the improvement so great, you are throwing money away by not replacing the hardware for the next generation.

Re: Intel patches new ME vulnerabilities

#319
post #237

Earlier quoted context omitted.

Unfortunately, announcement dates only give one endpoint of the timeline. The other endpoint, retirement date (from even previous-generation availability), is crucial to any anlysis.

Yeah, exactly. No argument that Intel keeps improving their processors. But at what cycle is the improvement so great, you are throwing money away by not replacing the hardware for the next generation.

It's also never quite as simple as looking at each generation as a discrete unit of upgradability.

Not only can the price:performance spread vary between generations, but this can change over time, particularly because the model availability within a generation broadens over time.

Add to this the dimension of low power versions of certain processor models (whose selection is therefore strictly a cost/longevity decision, presumably invisible to someone like a cloud end user), one can't safely generalize.

The other problem is that the CPU isn't even, necessarily, the majority of the purchase cost of a server.

Re: Intel patches new ME vulnerabilities

#320

Earlier quoted context omitted.

Well the distributors stamp the top of the server with a sticker that says it's safely operable for 2 years, so no one is going to insure it for more, of course. Might be European thing, though; good think for enthusiasts is that it's common to contact a company and join their next 2 years buyout and acquire cheap hardware.

Servers are "safely" operable until they die. The failure mode is that the machine stops operating. If your system has redundancy built in it keeps working possibly at reduced capacity. If not it stops. If its essential that service not be interrupted you build in redundancy and ensure that it fails in a safe way if it does. I'm not sure where safety or insurance comes into this discussion at all. People upgrade soon…

No, we literally upgrade because it's cheaper than the billions in damages.
Post reply on HN