Live data from Hacker News

Intel platforms from 2008 onwards have a remotely exploitable security hole

semiaccurate.com

141–150 of 190 posts

Re: Intel platforms from 2008 onwards have a remotely exploitable security hole

#141
post #126

Earlier quoted context omitted.

The article claimed: > That is the end of June for non-Intelspeak people, they will officially issue this guidance then along with OEM disclosures. We'll know in two months whether the above claim is true or false.

My prediction: At the end of June, Intel announces a fix for a minor non-RCE bug in the LAN code of Intel ME. SemiAccurate proudly and inaccurately announces that it confirms their previous reporting and adds it to the list of things to mention every time they write an article about Intel. There is no follow-up Hacker News thread with 100+ comments, so most of the people who posted here continue thinking that there w…

https://security-center.intel.com/advisory.aspx?intelid=INTE...

Looks like an almost full confirmation. They're saying consumer hardware is unaffected, but everything else matches.

Re: Intel platforms from 2008 onwards have a remotely exploitable security hole

#142
post #97
post #94

Earlier quoted context omitted.

Yes. There is A better source: http://invisiblethingslab.com/resources/bh09dc/Attacking%20I...

What is the publication date of this?

Initial confirmation below, I haven't read it through in full yet. I believe technical details are being delayed;

https://security-center.intel.com/advisory.aspx?intelid=INTE...

Re: Intel platforms from 2008 onwards have a remotely exploitable security hole

#143
post #60

As a sysadmin at a Windows shop, I don't know what to make of this. Has Intel commented on this, yet? Any OEM? Joanna Rutkowska, who is a renowned security researcher, warned of something like this happening sooner or later[1], so I don't think I can afford to just ignore this. But without something more specific to act on, there is nothing I can do, except wait firmware updates to be released by various vendors. If…

As pointed out by another commenter, Intel has released the advisary: https://security-center.intel.com/advisory.aspx?intelid=INTE... It confirms much of the SemiAccurate report, but also includes this: "This vulnerability does not exist on Intel-based consumer PCs." Which seems to differ from what SemiAccurate was saying. I'm not sure if it's SemiAccurate being... er... not completely accurate :D, or if it's Intel t…

I assume this is a bug in firmware version that's only used on enterprise class hardware, but that they assumed the bug also exists on consumer grade hardware on the basis of the circuits being mostly the same (and thus assuming the firmware is shared).

Re: Intel platforms from 2008 onwards have a remotely exploitable security hole

#144
post #66

Earlier quoted context omitted.

It does seem suspicious to me that this hugely critical flaw deep in the firmware stack has been discovered by the writing staff of a tech news website rather than an infosec research team...

The article sort of reads like he has thought (not known) there was an issue for a long time. Then, he saw that Intel released a patch related to the management engine, and took that as confirmation? Maybe he has access to the release notes via a source at an OEM?

He got the affected version numbers exactly right, but according to Intel he got the affected hardware wrong (consumer hardware unaffected).

That tells me he got the information from an unmentioned source. If he had the details himself he would be able to confirm what hardware it is present on by testing it.

The explanation for that error code be that the source have been vague about it or not tested it on a lot of hardware, or isn't even a firsthand source, or that the journalist misunderstood it.

https://security-center.intel.com/advisory.aspx?intelid=INTE...

Re: Intel platforms from 2008 onwards have a remotely exploitable security hole

#145
post #9

Is there a better source for this than SemiAccurate? The article doesn't really have much beyond self-aggrandizement and "we can't tell you any details, but you're screwed". For something that could be anything from "Charlie Demerjian heard a rumor about a ME patch and wanted some pageviews" to the actual security apocalypse, I'd like credible sources.

How about The Register? https://www.theregister.co.uk/2017/05/01/intel_amt_me_vulner... There's also an Intel advisory https://security-center.intel.com/advisory.aspx?intelid=INTE...

I'm glad that credible sources are now available. It's unfortunate that it took so long to confirm, but congrats to SemiAccurate on a massive scoop.

Edit: On the previously-mentioned scale, this sounds like a solid 8 or 9 out of 10.

Re: Intel platforms from 2008 onwards have a remotely exploitable security hole

#146
Now this less-mainstream theory about the precarious state of our communication systems has confirmed to a greater degree, would anyone here know of similar risks that few seem to be aware of right now?

I'm not sure if this would be considered OT, but considering the nature and scope of these vulnerabilities I don't consider it reasonable to exclude the possibility of intent and malice.

For this reason I'd like to ask: what do you consider to be "the next, most likely to surface, conspiracy of this flavor"?

The flavor being: "the struggle for control of any and all data and computational resources".

Re: Intel platforms from 2008 onwards have a remotely exploitable security hole

#147
post #126

Earlier quoted context omitted.

My prediction: At the end of June, Intel announces a fix for a minor non-RCE bug in the LAN code of Intel ME. SemiAccurate proudly and inaccurately announces that it confirms their previous reporting and adds it to the list of things to mention every time they write an article about Intel. There is no follow-up Hacker News thread with 100+ comments, so most of the people who posted here continue thinking that there w…

https://security-center.intel.com/advisory.aspx?intelid=INTE... Looks like an almost full confirmation. They're saying consumer hardware is unaffected, but everything else matches.

Yeah, I blew that prediction pretty badly. Congrats to SemiAccurate on the huge scoop!

Re: Intel platforms from 2008 onwards have a remotely exploitable security hole

#148

Earlier quoted context omitted.

Java has a new zero-day every week No it doesn't. The last one was in 2015. Before that I think there was a two year gap to the prior one. Zero days in Java are actually very rare these days. That doesn't mean bugs are rare - like any large piece of software Java gets regular security patches, but those are flaws found by the developers themselves rather than attackers, so they aren't zero days.

I think it's implied that "a new X every week" is always going to be hyperbole. I'm intentionally overstating the point so someone just like you could hop in and prove it better than I ever could. Remember in 2012 when Apple stopped shipping Java with their browser because it was so insecure?

Upgrading Java 5 minutes, 0 $

Upgrading your CPU 2hs, 300$

Having no secure CPU to upgrade to: priceless

Re: Intel platforms from 2008 onwards have a remotely exploitable security hole

#149
post #63
post #60

As a sysadmin at a Windows shop, I don't know what to make of this. Has Intel commented on this, yet? Any OEM? Joanna Rutkowska, who is a renowned security researcher, warned of something like this happening sooner or later[1], so I don't think I can afford to just ignore this. But without something more specific to act on, there is nothing I can do, except wait firmware updates to be released by various vendors. If…

Believe it in proportion to the supporting evidence presented. At the moment, that's nothing except an appeal to the widespread belief that an Intel ME security flaw is inevitable.

Update, Intel has now confirmed that there's an issue: https://security-center.intel.com/advisory.aspx?intelid=INTE...

They claim that it doesn't affect consumer CPUs, but that leaves a ton vulnerable. It's pants-shitting time.

Re: Intel platforms from 2008 onwards have a remotely exploitable security hole

#150

Earlier quoted context omitted.

The article implies that they have been privately trying to get Intel to fix it, so there is no reason it would have been mentioned publicly anywhere. Now a patch is coming out but Intel is still trying to keep it quiet, so he's trying to warn people disable AMT and be ready to apply patches ASAP. Presumably he didn't even want to disclose the existence of the vulnerability publicly until there was some sort of fix,…

Is there any way to avoid the patch and reverse engineer it to "root" ME and cripple it? I'd guess this would be a lot of interest for "hacker" news; i want to sign my own damn firmware.

Yes, but we've only figured out how to do that for old hardware.

Check out https://libreboot.org/docs/hardware/gm45_remove_me.html

Post reply on HN