Intel platforms from 2008 onwards have a remotely exploitable security hole
161–170 of 190 posts
Re: Intel platforms from 2008 onwards have a remotely exploitable security hole
#162Earlier quoted context omitted.
first mobile quad cores were sandy bridge released january 2011
? Nehalem had mobile quad cores. I'm using one right now.
Predating the i7 entirely, there were also quad core laptops using Core 2 Quad CPUs (Penryn QC) in 2008.
Re: Intel platforms from 2008 onwards have a remotely exploitable security hole
#163Earlier quoted context omitted.
If Intel released a firmware update, then anyone can compare this update to a previous version and see what has changed.
That's harder in practice than you make it sound. Firmware updates for Intel ME are handled through OEMs, it's not a file that Intel publishes that an interested person can go to their website and download. The article claims that such a patch has been released to OEMs but is being kept under wraps, which might make it hard to determine when it actually ships in a downstream update. Even if you have a file that you k…
Re: Intel platforms from 2008 onwards have a remotely exploitable security hole
#164As a sysadmin at a Windows shop, I don't know what to make of this. Has Intel commented on this, yet? Any OEM? Joanna Rutkowska, who is a renowned security researcher, warned of something like this happening sooner or later[1], so I don't think I can afford to just ignore this. But without something more specific to act on, there is nothing I can do, except wait firmware updates to be released by various vendors. If…
As pointed out by another commenter, Intel has released the advisary: https://security-center.intel.com/advisory.aspx?intelid=INTE... It confirms much of the SemiAccurate report, but also includes this: "This vulnerability does not exist on Intel-based consumer PCs." Which seems to differ from what SemiAccurate was saying. I'm not sure if it's SemiAccurate being... er... not completely accurate :D, or if it's Intel t…
Re: Intel platforms from 2008 onwards have a remotely exploitable security hole
#165The short version is that every Intel platform with AMT, ISM, and SBT from Nehalem in 2008 to Kaby Lake in 2017 has a remotely exploitable security hole in the ME (Management Engine) not CPU firmware. We knew this would happen. We knew that the Management Engine was a backdoor, and we knew it was only a matter of time before someone would figure out how to exploit it. This is exactly the reason why Libreboot exists (…
I'm having fun, I finally have an excuse to dust off my Libreboot X200 (refurbished and modded Thinkpad with Libreboot firmware). However, I strongly disrecommend buying from Leah Rowe unless you enjoy waiting months for payment confirmation and delivery. The worst webshop experience I've ever had. I recommend you build/flash your own, contract it out or look for a different vendor.
Re: Intel platforms from 2008 onwards have a remotely exploitable security hole
#166With the lead time on the silent patch before Shadow Brokers published all the Microsoft exploits, I wonder if Shadow Brokers will be publishing this one soon. No chance of an Intel ME patch going out without being noticed though!
A Shadow Brokers release would be a real mess.
Re: Intel platforms from 2008 onwards have a remotely exploitable security hole
#167Earlier quoted context omitted.
Fine, but putting it on all hardware? How many corporate IT environments buy off-the-shelf motherboards and CPUs from the same channels as consumers? OEMs get an entirely different set of parts and enterprise sales works in completely different channels. If there is such a clean separation between corporate and consumer markets then why is this hardware on everything , and why does it need to pull power on the machin…
It isn't on all hardware. Intel has two ME firmwares, a small one for consumer systems, and a big one for corporate/enterprise systems. The small one does not (or at least, should not; is not supposed to) include the remote management features. In other words, the separation that you describe exists. Systems with the full firmware sport things such as the vPro branding, and only certain combinations of CPU and chipse…
Re: Intel platforms from 2008 onwards have a remotely exploitable security hole
#168Earlier quoted context omitted.
This is also what the management engine cleaner project is for: https://github.com/corna/me_cleaner
https://github.com/corna/me_cleaner/wiki/How-to-apply-me_cle... The procedure seems far from trivial and requires special hardware(?). Is there a guide or some resources I could follow as a person with no hardware/low-level technical knowledge?
> Internal flashing with OEM firmware
> --------------------------------------------
> TODO
Re: Intel platforms from 2008 onwards have a remotely exploitable security hole
#169I don't really know what AMT does, but this has me thinking, if AMT is provisioned while a machine is used inside a company and then that machine shows up on eBay still provisioned, is it going to be phoning home and still be remotely manageable? How many of these machines have what are essentially persistent rootkits managed by large corporations that have had large fleets of laptops/desktops deployed that are then sold on?
Re: Intel platforms from 2008 onwards have a remotely exploitable security hole
#170Security is a cost center and most OEMs run on margins too thin to bother with security patches even if they cared. Most simply don’t care. I think that sums up pretty well why downstream vendors are treating security casually. So the billion dollar question is, how do we fix this, as a tech community?