Live data from Hacker News

Intel platforms from 2008 onwards have a remotely exploitable security hole

semiaccurate.com

121–130 of 190 posts

Re: Intel platforms from 2008 onwards have a remotely exploitable security hole

#121

Earlier quoted context omitted.

Can't all that be done from the main OS? Repartition, modify the boot stuff, reboot from an image in a new partition, etc... Why did they need to add another processor with closed source and all the potential security issues?

You can't change the boot media or turn on a turned-off machine via the OS. The whole point is to get underneath it, so you can even do initial OS install with it.

It might not be trivial, but you can do this w/o the ME. My understanding is that most ethernet cards support a "Wake-on-LAN" feature to turn off machines on, and from there you can trigger the machine to reboot and then netboot (by writing to its boot config to instruct whatever boots it that it should take that action).

Even if you assert that the ME is absolutely necessary for such a use-case, I don't have that use case, it isn't work the risk for me, and I should be able to disable the ME because I, as the owner of the machine, want to. (Or really, otherwise interact with it and use it for creative use-cases.)

Re: Intel platforms from 2008 onwards have a remotely exploitable security hole

#122
post #111
post #71

Earlier quoted context omitted.

Let's hope one of the other CPU manufacturers (e.g. AMD) starts supporting LibreBoot and allows to officially disable the ME-equivalent hardware feature, so that Intel get's forced by market-pressur to follow. Intel needs more competition - thanks to AMD latest new 8-core CPU Intel got forced to release a new CPU the had in their basement for years - suddently it's possible for them to release i7 notebook CPUs with m…

first mobile quad cores were sandy bridge released january 2011

? Nehalem had mobile quad cores. I'm using one right now.

Re: Intel platforms from 2008 onwards have a remotely exploitable security hole

#123
post #112

Earlier quoted context omitted.

If the article's claims are true, all sources (e.g. OEMs with access to a fix) should be under NDA, https://twitter.com/cdemerjian/status/859096565033693185

...and if the article's claims aren't true, there wouldn't be any sources to confirm the claims at all. The evidence we've been presented with so far (no sources) is consistent with both possibilities. When you make a claim as big as SemiAccurate did, it's on you to provide sources to back it up. If you can't present any kind of proof, you don't have a story, you have a rumor.

Then it's a rumor. One you probably want to keep your eye on. Which was the whole point of the article anyway.

Re: Intel platforms from 2008 onwards have a remotely exploitable security hole

#124
post #112

Earlier quoted context omitted.

If the article's claims are true, all sources (e.g. OEMs with access to a fix) should be under NDA, https://twitter.com/cdemerjian/status/859096565033693185

...and if the article's claims aren't true, there wouldn't be any sources to confirm the claims at all. The evidence we've been presented with so far (no sources) is consistent with both possibilities. When you make a claim as big as SemiAccurate did, it's on you to provide sources to back it up. If you can't present any kind of proof, you don't have a story, you have a rumor.

[deleted]

Re: Intel platforms from 2008 onwards have a remotely exploitable security hole

#125
post #112

Earlier quoted context omitted.

If the article's claims are true, all sources (e.g. OEMs with access to a fix) should be under NDA, https://twitter.com/cdemerjian/status/859096565033693185

...and if the article's claims aren't true, there wouldn't be any sources to confirm the claims at all. The evidence we've been presented with so far (no sources) is consistent with both possibilities. When you make a claim as big as SemiAccurate did, it's on you to provide sources to back it up. If you can't present any kind of proof, you don't have a story, you have a rumor.

[deleted]

Re: Intel platforms from 2008 onwards have a remotely exploitable security hole

#126
post #112

Earlier quoted context omitted.

...and if the article's claims aren't true, there wouldn't be any sources to confirm the claims at all. The evidence we've been presented with so far (no sources) is consistent with both possibilities. When you make a claim as big as SemiAccurate did, it's on you to provide sources to back it up. If you can't present any kind of proof, you don't have a story, you have a rumor.

The article claimed: > That is the end of June for non-Intelspeak people, they will officially issue this guidance then along with OEM disclosures. We'll know in two months whether the above claim is true or false.

My prediction: At the end of June, Intel announces a fix for a minor non-RCE bug in the LAN code of Intel ME. SemiAccurate proudly and inaccurately announces that it confirms their previous reporting and adds it to the list of things to mention every time they write an article about Intel. There is no follow-up Hacker News thread with 100+ comments, so most of the people who posted here continue thinking that there was a major RCE in Intel ME that we just haven't heard about because it was covered up.

Edit: Already proven wrong! We're headed for interesting times.

Re: Intel platforms from 2008 onwards have a remotely exploitable security hole

#127

Earlier quoted context omitted.

You can't change the boot media or turn on a turned-off machine via the OS. The whole point is to get underneath it, so you can even do initial OS install with it.

It might not be trivial, but you can do this w/o the ME. My understanding is that most ethernet cards support a "Wake-on-LAN" feature to turn off machines on, and from there you can trigger the machine to reboot and then netboot (by writing to its boot config to instruct whatever boots it that it should take that action). Even if you assert that the ME is absolutely necessary for such a use-case, I don't have that us…

Just get a computer that doesn't have vPro.

Re: Intel platforms from 2008 onwards have a remotely exploitable security hole

#128
post #83

The short version is that every Intel platform with AMT, ISM, and SBT from Nehalem in 2008 to Kaby Lake in 2017 has a remotely exploitable security hole in the ME (Management Engine) not CPU firmware. We knew this would happen. We knew that the Management Engine was a backdoor, and we knew it was only a matter of time before someone would figure out how to exploit it. This is exactly the reason why Libreboot exists (…

This is also what the management engine cleaner project is for: https://github.com/corna/me_cleaner

https://github.com/corna/me_cleaner/wiki/How-to-apply-me_cle...

The procedure seems far from trivial and requires special hardware(?). Is there a guide or some resources I could follow as a person with no hardware/low-level technical knowledge?

Re: Intel platforms from 2008 onwards have a remotely exploitable security hole

#129

Great news that this finally came to light. After learning about remote management capabilities I've always suspected it had holes. Large attack surface, any exploit would have a high value, and closed source. Perhaps one day we'll be able to buy CPU's without this "feature". I'm betting AMD and ARM are in the same boat.

They are. AMD TrustZone runs an ARM core alongside your computer. I've also heard a lot of ARM SoC platforms have something similar.

The key difference is that this doesn't affect every ARM processor.
Post reply on HN