Live data from Hacker News

'Unfixable' security flaw in Intel boot ROM

theregister.co.uk

11–20 of 65 posts

Re: 'Unfixable' security flaw in Intel boot ROM

#11
post #9

So ugly, I can't just replace all of our hardware. Remaining forever vigilant is tiring. CPUs are so broken that security is just a facade.

the problem is the hardware being replaced to begin with. The ME is not needed for the end user to operate thier machine in a secure manner. The ME is a trojan that allows intel to manipulate your system and lock you into the whole DRM nonsense. the only reason Intel platforms havent become as bad as mobile platforms is because there isnt enough fear of system compromise from the average user. https://en.wikipedia.or…

You know if your did less FUD there's a chance people may actually engage in a conversation with you.

Anyone from enterprise knows his much of a timesaver amt is. I make a call andi don't have to wait for the IT dude to appear on my desk- he clicks a few buttons from his desk and my problem is fixed.

Re: 'Unfixable' security flaw in Intel boot ROM

#12
post #9

Earlier quoted context omitted.

the problem is the hardware being replaced to begin with. The ME is not needed for the end user to operate thier machine in a secure manner. The ME is a trojan that allows intel to manipulate your system and lock you into the whole DRM nonsense. the only reason Intel platforms havent become as bad as mobile platforms is because there isnt enough fear of system compromise from the average user. https://en.wikipedia.or…

You know if your did less FUD there's a chance people may actually engage in a conversation with you. Anyone from enterprise knows his much of a timesaver amt is. I make a call andi don't have to wait for the IT dude to appear on my desk- he clicks a few buttons from his desk and my problem is fixed.

Why do we need ME for that?

Re: 'Unfixable' security flaw in Intel boot ROM

#13

The useful gist: > "To fully compromise EPID, hackers would need to extract the hardware key used to encrypt the Chipset Key, which resides in Secure Key Storage (SKS)," explained Positive's Mark Ermolov. > "However, this key is not platform-specific. A single key is used for an entire generation of Intel chipsets. And since the ROM vulnerability allows seizing control of code execution before the hardware key genera…

> "maintain physical possession of their platform" That ship has sailed.

>That ship has sailed.

Not in the least.

"Cloud" is merely the modern spin on "terminal in the office, mainframe at the HQ". We moved from terminals to local mini/microcomputers back then, and we will move from "cloud" to edge computing again. Notably, serverless and "installable web apps" are already a growing thing.

And no, Sun, the network is the computer will not come to pass during this cycle.

Re: 'Unfixable' security flaw in Intel boot ROM

#18

The useful gist: > "To fully compromise EPID, hackers would need to extract the hardware key used to encrypt the Chipset Key, which resides in Secure Key Storage (SKS)," explained Positive's Mark Ermolov. > "However, this key is not platform-specific. A single key is used for an entire generation of Intel chipsets. And since the ROM vulnerability allows seizing control of code execution before the hardware key genera…

> "maintain physical possession of their platform" That ship has sailed.

I think the average company should and does trust the physical security of Amazon's datacenters more than their own. If I had a nickel for every unvetted janitor allowed to clean an office alone near an easily pickable hardware closet...

Re: 'Unfixable' security flaw in Intel boot ROM

#19

Earlier quoted context omitted.

> "maintain physical possession of their platform" That ship has sailed.

What about physical possession before you own it? Will this potentially sour a used/refurbished market?

this is more about the chipset on the motherboard.

to backdoor this you need to saddle a chip or a connector onto the PCH chip and win the race to takeover the bus.

or if your intel and you send a firmware update to modify the ME behaviour /state.

it would be fairly suspect in most cases but if this was done at the factory, it would be hard to tell for most people.

What really matters is just how much of a target you might be for someone to take the effort to engage in what really amounts to industrial/corporate espianage.

Post reply on HN