Live data from Hacker News

Intel platforms from 2008 onwards have a remotely exploitable security hole

semiaccurate.com

111–120 of 190 posts

Re: Intel platforms from 2008 onwards have a remotely exploitable security hole

#111
post #71

The short version is that every Intel platform with AMT, ISM, and SBT from Nehalem in 2008 to Kaby Lake in 2017 has a remotely exploitable security hole in the ME (Management Engine) not CPU firmware. We knew this would happen. We knew that the Management Engine was a backdoor, and we knew it was only a matter of time before someone would figure out how to exploit it. This is exactly the reason why Libreboot exists (…

Let's hope one of the other CPU manufacturers (e.g. AMD) starts supporting LibreBoot and allows to officially disable the ME-equivalent hardware feature, so that Intel get's forced by market-pressur to follow. Intel needs more competition - thanks to AMD latest new 8-core CPU Intel got forced to release a new CPU the had in their basement for years - suddently it's possible for them to release i7 notebook CPUs with m…

first mobile quad cores were sandy bridge released january 2011

Re: Intel platforms from 2008 onwards have a remotely exploitable security hole

#112
post #64

Earlier quoted context omitted.

No, that's not how sources work. You don't get to use your assumption that the article is accurate to assert that it will eventually be proven accurate by other sources. That's circular reasoning.

If the article's claims are true, all sources (e.g. OEMs with access to a fix) should be under NDA, https://twitter.com/cdemerjian/status/859096565033693185

...and if the article's claims aren't true, there wouldn't be any sources to confirm the claims at all. The evidence we've been presented with so far (no sources) is consistent with both possibilities. When you make a claim as big as SemiAccurate did, it's on you to provide sources to back it up. If you can't present any kind of proof, you don't have a story, you have a rumor.

Re: Intel platforms from 2008 onwards have a remotely exploitable security hole

#113
post #32

Earlier quoted context omitted.

Credibility issues of the author/website aside, I actually hope this is true, and I hope it's catastrophic for Intel. Maybe then we'll finally see hardware companies taking security seriously.

I'm not familiar with the author. Can you elaborate on the credibility issues?

Charlie Demerjian is a massive hater. That doesn't mean he's wrong, but everything he writes about Intel or Nvidia has a negative slant.

Re: Intel platforms from 2008 onwards have a remotely exploitable security hole

#114
post #38
post #26

Security is a cost center and most OEMs run on margins too thin to bother with security patches even if they cared. Most simply don’t care. I think that sums up pretty well why downstream vendors are treating security casually. So the billion dollar question is, how do we fix this, as a tech community?

OEMs are not involved at all with ME afaik, it's exculusively controlled by Intel.

OEMs have to ship ME firmware updates; Intel has no way to get them to you directly.

Re: Intel platforms from 2008 onwards have a remotely exploitable security hole

#115

Earlier quoted context omitted.

I think the problem is not that this technology exists but rather that the operation of this engine is not transparent, the user cannot examine or disable the software in this engine, cannot write his own software.

IME should exist on an external TPM chip so it's only for those that want it, like enterprises. I really don't understand why the would just shove it into every chipset out there. I understand it needs to get its claws all over the system, but the core should be external and optional.

Because a separate chip costs more.

Re: Intel platforms from 2008 onwards have a remotely exploitable security hole

#116
post #32

Earlier quoted context omitted.

Credibility issues of the author/website aside, I actually hope this is true, and I hope it's catastrophic for Intel. Maybe then we'll finally see hardware companies taking security seriously.

IME is likely not a case of Intel "not taking security seriously". It's almost certainly a case of doing what FiveEyes demanded of them.

this was my first thought as well, but surely there would have been some hint of it in snowden docs or the recent wikileaks cia malware docs?

Re: Intel platforms from 2008 onwards have a remotely exploitable security hole

#117

Earlier quoted context omitted.

It's a semiconductor news site.

Semiconductor Accurate? Doesn't really sound right grammatically, also the arrows missing the target in their logo lead me to believe half accurate was how they intended the name to be interpreted.

The name is a joke. The whole purpose of SemiAccurate is to report leaks and rumors and one can never expect such reporting to be fully accurate.

Re: Intel platforms from 2008 onwards have a remotely exploitable security hole

#118
post #112

Earlier quoted context omitted.

If the article's claims are true, all sources (e.g. OEMs with access to a fix) should be under NDA, https://twitter.com/cdemerjian/status/859096565033693185

...and if the article's claims aren't true, there wouldn't be any sources to confirm the claims at all. The evidence we've been presented with so far (no sources) is consistent with both possibilities. When you make a claim as big as SemiAccurate did, it's on you to provide sources to back it up. If you can't present any kind of proof, you don't have a story, you have a rumor.

The article claimed:

> That is the end of June for non-Intelspeak people, they will officially issue this guidance then along with OEM disclosures.

We'll know in two months whether the above claim is true or false.

Re: Intel platforms from 2008 onwards have a remotely exploitable security hole

#119

Earlier quoted context omitted.

The fact that people can stay behind platforms, companies, and technologies that are proven to be so inherently insecure that they can never be trusted just boggles my mind. Adobe Flash has a new zero-day every week, but we were saddled with it for years past when it should have been retired because some people didn't want HTML5 to have feature-parity with Flash. Java has a new zero-day every week but we're stuck wit…

Java has a new zero-day every week No it doesn't. The last one was in 2015. Before that I think there was a two year gap to the prior one. Zero days in Java are actually very rare these days. That doesn't mean bugs are rare - like any large piece of software Java gets regular security patches, but those are flaws found by the developers themselves rather than attackers, so they aren't zero days.

I think it's implied that "a new X every week" is always going to be hyperbole. I'm intentionally overstating the point so someone just like you could hop in and prove it better than I ever could.

Remember in 2012 when Apple stopped shipping Java with their browser because it was so insecure?

Re: Intel platforms from 2008 onwards have a remotely exploitable security hole

#120
post #62

Earlier quoted context omitted.

>Java has a new zero-day every week but we're stuck with it Well, Java applets did die. What more do you want? The Java sandbox is only used by extremely legacy software at this point, so it doesn't matter if it has holes in it. Actually, the more holes the better, so we can get rid of the last holdouts.

Java is the most widely-used programming language in the world. Applets are an insignificantly tiny drop in the bucket of what Java is used for.

[deleted]
Post reply on HN