Live data from Hacker News

Intel platforms from 2008 onwards have a remotely exploitable security hole

semiaccurate.com

131–140 of 190 posts

Re: Intel platforms from 2008 onwards have a remotely exploitable security hole

#131
post #64

Earlier quoted context omitted.

No, that's not how sources work. You don't get to use your assumption that the article is accurate to assert that it will eventually be proven accurate by other sources. That's circular reasoning.

If the article's claims are true, all sources (e.g. OEMs with access to a fix) should be under NDA, https://twitter.com/cdemerjian/status/859096565033693185

Devil's Advocate here, so you are assuming there is a perfectly secure software implementation in this world, and only Intel has it for their Management Engine? I get your point, SemiAccurate may or may not have an exploit, but I think it goes without saying there is a security hole somewhere in the ME, it just is not publicly known at this point.

Re: Intel platforms from 2008 onwards have a remotely exploitable security hole

#132

What is the motivation behind Management Engine? From the perspective of an everyday user these things came out of nowhere to evolve into this para-computer running along side me that I cannot see and have no control of. It is on literally ALL hardware Why is it that any attempts to disable it knock your whole computer out? And this is the world of technology that we want? I'm so sick of technology companies appearin…

"There is anything to worry about if you have nothing to hide" /s

Re: Intel platforms from 2008 onwards have a remotely exploitable security hole

#133
post #9

Is there a better source for this than SemiAccurate? The article doesn't really have much beyond self-aggrandizement and "we can't tell you any details, but you're screwed". For something that could be anything from "Charlie Demerjian heard a rumor about a ME patch and wanted some pageviews" to the actual security apocalypse, I'd like credible sources.

How about The Register? https://www.theregister.co.uk/2017/05/01/intel_amt_me_vulner...

There's also an Intel advisory https://security-center.intel.com/advisory.aspx?intelid=INTE...

Re: Intel platforms from 2008 onwards have a remotely exploitable security hole

#134
post #9

Is there a better source for this than SemiAccurate? The article doesn't really have much beyond self-aggrandizement and "we can't tell you any details, but you're screwed". For something that could be anything from "Charlie Demerjian heard a rumor about a ME patch and wanted some pageviews" to the actual security apocalypse, I'd like credible sources.

[deleted]

Re: Intel platforms from 2008 onwards have a remotely exploitable security hole

#135

The short version is that every Intel platform with AMT, ISM, and SBT from Nehalem in 2008 to Kaby Lake in 2017 has a remotely exploitable security hole in the ME (Management Engine) not CPU firmware. We knew this would happen. We knew that the Management Engine was a backdoor, and we knew it was only a matter of time before someone would figure out how to exploit it. This is exactly the reason why Libreboot exists (…

I'm having fun, I finally have an excuse to dust off my Libreboot X200 (refurbished and modded Thinkpad with Libreboot firmware).

However, I strongly disrecommend buying from Leah Rowe unless you enjoy waiting months for payment confirmation and delivery. The worst webshop experience I've ever had.

I recommend you build/flash your own, contract it out or look for a different vendor.

Re: Intel platforms from 2008 onwards have a remotely exploitable security hole

#136
post #8

Zero details and zero cross references, zero mentions on Google and zero mentions in any security list I'm on. Charlie blowing nonsensical steam yet again?

https://security-center.intel.com/advisory.aspx?intelid=INTE...

Seems legit.

Re: Intel platforms from 2008 onwards have a remotely exploitable security hole

#138
post #60

As a sysadmin at a Windows shop, I don't know what to make of this. Has Intel commented on this, yet? Any OEM? Joanna Rutkowska, who is a renowned security researcher, warned of something like this happening sooner or later[1], so I don't think I can afford to just ignore this. But without something more specific to act on, there is nothing I can do, except wait firmware updates to be released by various vendors. If…

Yes: https://security-center.intel.com/advisory.aspx?intelid=INTE...

Re: Intel platforms from 2008 onwards have a remotely exploitable security hole

#139
post #60

As a sysadmin at a Windows shop, I don't know what to make of this. Has Intel commented on this, yet? Any OEM? Joanna Rutkowska, who is a renowned security researcher, warned of something like this happening sooner or later[1], so I don't think I can afford to just ignore this. But without something more specific to act on, there is nothing I can do, except wait firmware updates to be released by various vendors. If…

As pointed out by another commenter, Intel has released the advisary:

https://security-center.intel.com/advisory.aspx?intelid=INTE...

It confirms much of the SemiAccurate report, but also includes this:

"This vulnerability does not exist on Intel-based consumer PCs."

Which seems to differ from what SemiAccurate was saying. I'm not sure if it's SemiAccurate being... er... not completely accurate :D, or if it's Intel trying to downplay things.

I guess we'll find out more over the next few days/weeks.

Re: Intel platforms from 2008 onwards have a remotely exploitable security hole

#140

The short version is that every Intel platform with AMT, ISM, and SBT from Nehalem in 2008 to Kaby Lake in 2017 has a remotely exploitable security hole in the ME (Management Engine) not CPU firmware. We knew this would happen. We knew that the Management Engine was a backdoor, and we knew it was only a matter of time before someone would figure out how to exploit it. This is exactly the reason why Libreboot exists (…

If the verilog to the chip isn't open, you can't trust it. Stallman is dangerously wrong on this point.
Post reply on HN