Live data from Hacker News

Intel platforms from 2008 onwards have a remotely exploitable security hole

semiaccurate.com

11–20 of 190 posts

Re: Intel platforms from 2008 onwards have a remotely exploitable security hole

#11
post #8

Zero details and zero cross references, zero mentions on Google and zero mentions in any security list I'm on. Charlie blowing nonsensical steam yet again?

Yes. It is his uncontrollable urge for getting thousands of corporate IT admins to disable the Management Engine, at it again.

Re: Intel platforms from 2008 onwards have a remotely exploitable security hole

#15
I've got a Lenovo T530 and a Lenovo T450s. I wonder if they've released a firmware update yet...?

I can't say I'm surprised, but I am surprised at the fact that finally, after all these years, someone finally got down to patching some vulnerabilities in this area.

props to whomever forced Intel's hand.

Re: Intel platforms from 2008 onwards have a remotely exploitable security hole

#16
post #8

Zero details and zero cross references, zero mentions on Google and zero mentions in any security list I'm on. Charlie blowing nonsensical steam yet again?

The article implies that they have been privately trying to get Intel to fix it, so there is no reason it would have been mentioned publicly anywhere.

Now a patch is coming out but Intel is still trying to keep it quiet, so he's trying to warn people disable AMT and be ready to apply patches ASAP.

Presumably he didn't even want to disclose the existence of the vulnerability publicly until there was some sort of fix, and he still won't want to disclose details before the fix is released.

Of course, you can doubt the veracity of this story, but I'm just pointing out that there would be no reason to expect details, cross references, or mentions on Google or security lists yet if it is true.

Re: Intel platforms from 2008 onwards have a remotely exploitable security hole

#17

My ignorance is showing, but what product lines are impacted? Obviously things like Xeons and Core iXs, but what about things like Atom processors in tablets?

The post appears to claim that literally everything is affected, albeit probably only locally exploitable. I think that's what it means at least.

[deleted]

Re: Intel platforms from 2008 onwards have a remotely exploitable security hole

#19
Can anyone add any details? The article is very very vague. Doesn't this work thru the Ethernet port in the chipset silicon?

So if you're running a desktop that has a physical Ethernet card in it, and the Intel Ethernet isn't connected, are you OK?

And if you're running on a laptop that uses Intel's Ethernet, (and most of them do?) then are you vulnerable?

Re: Intel platforms from 2008 onwards have a remotely exploitable security hole

#20
post #8

Zero details and zero cross references, zero mentions on Google and zero mentions in any security list I'm on. Charlie blowing nonsensical steam yet again?

The article implies that they have been privately trying to get Intel to fix it, so there is no reason it would have been mentioned publicly anywhere. Now a patch is coming out but Intel is still trying to keep it quiet, so he's trying to warn people disable AMT and be ready to apply patches ASAP. Presumably he didn't even want to disclose the existence of the vulnerability publicly until there was some sort of fix,…

It does seem suspicious to me that this hugely critical flaw deep in the firmware stack has been discovered by the writing staff of a tech news website rather than an infosec research team...
Post reply on HN