Does anyone have an idea to what extent macbooks are affected? Intel ME is baked in every CPU but according to The Register [0] the AMT part is not running on Apple hardware. [0]: https://www.theregister.co.uk/2017/05/01/intel_amt_me_vulner...
An in-depth security review of the Intel Management Engine
141–150 of 192 posts
Re: An in-depth security review of the Intel Management Engine
#142Wow all 6th, 7th and 8th gen are all vulnerable along with a bunch of Xeon processors. Even the laptop I am typing this on is vulnerable, this is going to be messy. Plus all the fun vulnerabilities like arbitrary code execution, unauthorized access to privileged content. These must be related to the blackhat talk coming up in December about hacking a turned-off computer and running unsigned code on ME [0]. Yep and th…
Do we really think older systems are magically not vulnerable to any of these? It seems more likely that they're vulnerable but old enough that they're getting ignored... and so they'll never get fixes.
Intel sales slump solved? :-/
Re: An in-depth security review of the Intel Management Engine
#143Earlier quoted context omitted.
I guess I'm "Normal-for-HN". IPMI is so useful that I wouldn't buy a server without it, even one I'm going to use in the same building.
IPMI is fantastic, so long that the understanding is in place that access to your IPMI vlan may as well be considered root access to the node. BMCs tend to be pretty miserable when it comes to security. It's generally a good idea to have ACLs in place to ensure BMCs can only communicate with a secured management node, and importantly that BMCs cannot communicate with each other .
Now, on many motherboards the BMC stuff will aggressively talk in-band even if you think you've disabled that.
Re: An in-depth security review of the Intel Management Engine
#144Earlier quoted context omitted.
> I think many discussions miss the nuance here. The problem is that the functionality is hidden, not necessarily that the function is there. > If they were more transparent, then they could be used by normal users for remote administration as well. The fundamental objection with ME isn't that it's "proprietary" or "non-libre" or whatever other ideological objections, it's that it's an opaque embuggerance that makes…
> The fundamental objection with ME isn't that it's "proprietary" or "non-libre" or whatever other ideological objections, it's that it's an opaque embuggerance that makes any analysis or reasoning about the system's security/trustworthiness/reliability completely impossible and specious. Erm, your fundamental objection is exactly the same objection as it being non-libre. You presented the same argument while trying…
Access to the firmware binary running on the ME processor and documentation for the latter would be even better than having source, since the latter assumes you trust the toolchain too.
Re: An in-depth security review of the Intel Management Engine
#145Earlier quoted context omitted.
> I wonder if this will at all dissuade either Intel or AMD into continuing to make these super privileged processors whose functions are completely hidden. I think many discussions miss the nuance here. The problem is that the functionality is hidden, not necessarily that the function is there. In corporate use, these tools can be incredibly useful. If they were more transparent, then they could be used by normal us…
> I think many discussions miss the nuance here. The problem is that the functionality is hidden, not necessarily that the function is there. > If they were more transparent, then they could be used by normal users for remote administration as well. The fundamental objection with ME isn't that it's "proprietary" or "non-libre" or whatever other ideological objections, it's that it's an opaque embuggerance that makes…
Re: An in-depth security review of the Intel Management Engine
#146Re: An in-depth security review of the Intel Management Engine
#147Earlier quoted context omitted.
> I think many discussions miss the nuance here. The problem is that the functionality is hidden, not necessarily that the function is there. > If they were more transparent, then they could be used by normal users for remote administration as well. The fundamental objection with ME isn't that it's "proprietary" or "non-libre" or whatever other ideological objections, it's that it's an opaque embuggerance that makes…
> The fundamental objection with ME isn't that it's "proprietary" or "non-libre" or whatever other ideological objections, it's that it's an opaque embuggerance that makes any analysis or reasoning about the system's security/trustworthiness/reliability completely impossible and specious. Erm, your fundamental objection is exactly the same objection as it being non-libre. You presented the same argument while trying…
Re: An in-depth security review of the Intel Management Engine
#148I'd have preferred to hear something along the lines of "We'll be stopping implementing this technology in future CPUs"
Re: An in-depth security review of the Intel Management Engine
#149Could someone explain what Management Engine is actually used for? It’s still not really clear to me why it needs to exist at all. Serious question.
Remote administration. Installing a new OS remotely, for example. There is legit demand for that. Imagine manually re-imaging 1000 workstations or servers.
Re: An in-depth security review of the Intel Management Engine
#150The ME should not even exist. Best way to secure it is to remove it. Problem solved. They will of course not let go because it's a backdoor. It's an overprivileged computer within your computer.