Is there a better source for this than SemiAccurate? The article doesn't really have much beyond self-aggrandizement and "we can't tell you any details, but you're screwed". For something that could be anything from "Charlie Demerjian heard a rumor about a ME patch and wanted some pageviews" to the actual security apocalypse, I'd like credible sources.
Yes. There is A better source: http://invisiblethingslab.com/resources/bh09dc/Attacking%20I...
Intel platforms from 2008 onwards have a remotely exploitable security hole
101–110 of 190 posts
Re: Intel platforms from 2008 onwards have a remotely exploitable security hole
#102>>every Intel platform with AMT, ISM, and SBT from Nehalem in 2008 to Kaby Lake in 2017 has a remotely exploitable security hole in the ME (Management Engine) not CPU firmware. >>there is literally no Intel box made in the last 9+ years that isn’t at risk >>SemiAccurate has been begging Intel to fix this issue for literally years Am I the only one who is so cynical to think it must have been deliberate? Intel draggin…
Believe incompetence before malice, and I'd stick economic incentives somewhere in the middle. The discussion probably went something like: Person 1: "Should we issue a recall and disable a feature which bought us a several billion dollar customer?" Person 2: ...
Re: Intel platforms from 2008 onwards have a remotely exploitable security hole
#103If it's WiFi that's damn scary.
Re: Intel platforms from 2008 onwards have a remotely exploitable security hole
#104Earlier quoted context omitted.
Partially. Expansion cards use PCI-E which has DMA capability, so a bug/backdoor in their firmware can very well be used to attack a system. But I believe newer systems with MMUs acting as "firewalls" for DMA are safe from this vector.
there's also the concern of physical attacks, via the motherboard's RJ45 or USB.
Re: Intel platforms from 2008 onwards have a remotely exploitable security hole
#105Does this affect an Apple MacBook?
Re: Intel platforms from 2008 onwards have a remotely exploitable security hole
#106Earlier quoted context omitted.
Yes. There is A better source: http://invisiblethingslab.com/resources/bh09dc/Attacking%20I...
What is the publication date of this?
Re: Intel platforms from 2008 onwards have a remotely exploitable security hole
#107Great news that this finally came to light. After learning about remote management capabilities I've always suspected it had holes. Large attack surface, any exploit would have a high value, and closed source. Perhaps one day we'll be able to buy CPU's without this "feature". I'm betting AMD and ARM are in the same boat.
> After learning about remote management capabilities I've always suspected it had holes. Large attack surface, any exploit would have a high value, and closed source. Even after reading this, I'm still not convinced it does have holes. It's so high value (pervasive, incredibly powerful, and old) that if it were possible a bad actor would have used it . The spectrum of possibilities is small: 1. The hole does not exi…
Also, there is a 5th (more likely) possibility: SA didn't find anything, but undiscovered holes do exist.
Re: Intel platforms from 2008 onwards have a remotely exploitable security hole
#108Relevant discussion: https://news.ycombinator.com/item?id=11913379
> do the first three steps of thinking for them. Make it really easy for the other person to say yes or no
source: http://firstround.com/review/how-to-become-insanely-well-con... | https://news.ycombinator.com/item?id=14195664
I've agreed to include a bit of detail when spamming all my friends links via e-mail going forward.
Re: Intel platforms from 2008 onwards have a remotely exploitable security hole
#109I've always wondering why nobody seems to notice the fact that this site is literally called "Semi Accurate". I mean sure, everyone makes mistake and even the most credible news sources are not entirely accurate all the time. But what am I to think when your organization is literally named after being only half truthful?
It's a semiconductor news site.
Re: Intel platforms from 2008 onwards have a remotely exploitable security hole
#110> For obvious reasons we couldn’t publish what we found It's not obvious to me why anyone not under an NSL or NDA would sit on this vulnerability for 5 years and wait until it's actively being exploited in the wild before public disclosure. It's extremely negligent to global security for SemiAccurate to not immediately publicly disclose the vulnerability 5 years ago after Intel refused to fix it. Of course this is ig…