Earlier quoted context omitted.
Old, outdated, expensive hardware with low specs? Nope. I have a lot of respect for what they do but it's not the solution we need.
An alternative is to use ARM-based devices: they typically lack microcode updates, and while TrustZone hypervisors are often present and the situation varies by device, at least some devices should allow the user to gain full control of the CPU without having to exploit anything. (I don't know how common that is, because every device manufacturer has their own boot process, and from some quick Google searching it see…
ThinkPwn: System Management Mode arbitrary code execution
151–154 of 154 posts
Re: ThinkPwn: System Management Mode arbitrary code execution
#152Earlier quoted context omitted.
The sale happened ten years ago and it is extremely unlikely that there are any contractual obligations for this anymore. Let's put this meme to rest; Lenovo has been building solid Thinkpads.
what?! since when? I every single thinkpad I bought since my T43P has been a total piece of shit in comparison. Methinks you have never owned an IBM Thinkpad to make that statement.
Re: ThinkPwn: System Management Mode arbitrary code execution
#153Earlier quoted context omitted.
Name calling? Come on. I'm not really a fan of the trend of "branding" vulnerabilities, but it is just harmless silliness, and substantially less inflammatory than security industry smack-talking norms from not too long ago. Or put another way, I suggest adjusting your sensitivity before cracking open an issue of Phrack. And a serious question: in your view what would be a "responsible" way to release a multivendor e…
> I'm not really a fan of the trend of "branding" vulnerabilities, but it is just harmless silliness It's probably harmless but I'm not so sure it's silly. It's much more distinguishing than monikers like "CVE-2016-0093". It can sometimes convey the seriousness of the relevant exploit (not sure if that's the case this time though). These branded-vulnerabilities are also probably much more valuable on a CV as such.
I still think it is silly.
I'm less convinced the trend has any use for communicating seriousness. I don't expect product names (basically what this is) to meaningfully convey actionable information in any trustworthy way. But I'll reconsider next time I see a car named "Cheap, mostly-OK vehicle with probable future maintenance headaches" or an exploit named "Smasher of stacks of a little-known utility optionally installed alongside Enterprise Product X, so long as these 7 unlikely preconditions are met".