Live data from Hacker News

Intel platforms from 2008 onwards have a remotely exploitable security hole

semiaccurate.com

161–170 of 190 posts

Re: Intel platforms from 2008 onwards have a remotely exploitable security hole

#162
post #111

Earlier quoted context omitted.

first mobile quad cores were sandy bridge released january 2011

? Nehalem had mobile quad cores. I'm using one right now.

Specifically the Clarksfield processors from 2009: https://en.wikipedia.org/wiki/Clarksfield_(microprocessor)

Predating the i7 entirely, there were also quad core laptops using Core 2 Quad CPUs (Penryn QC) in 2008.

Re: Intel platforms from 2008 onwards have a remotely exploitable security hole

#163
post #87

Earlier quoted context omitted.

If Intel released a firmware update, then anyone can compare this update to a previous version and see what has changed.

That's harder in practice than you make it sound. Firmware updates for Intel ME are handled through OEMs, it's not a file that Intel publishes that an interested person can go to their website and download. The article claims that such a patch has been released to OEMs but is being kept under wraps, which might make it hard to determine when it actually ships in a downstream update. Even if you have a file that you k…

CPU firmware patches have also been released through Microsoft update, and Windows computers may well be patched on the fly in this way. I suppose it would be possible to download the update individually and examine its contents, but, as you point out, it would be extremely difficult to work out what it was doing.

Re: Intel platforms from 2008 onwards have a remotely exploitable security hole

#164
post #60

As a sysadmin at a Windows shop, I don't know what to make of this. Has Intel commented on this, yet? Any OEM? Joanna Rutkowska, who is a renowned security researcher, warned of something like this happening sooner or later[1], so I don't think I can afford to just ignore this. But without something more specific to act on, there is nothing I can do, except wait firmware updates to be released by various vendors. If…

As pointed out by another commenter, Intel has released the advisary: https://security-center.intel.com/advisory.aspx?intelid=INTE... It confirms much of the SemiAccurate report, but also includes this: "This vulnerability does not exist on Intel-based consumer PCs." Which seems to differ from what SemiAccurate was saying. I'm not sure if it's SemiAccurate being... er... not completely accurate :D, or if it's Intel t…

Looking at the Intel link, they take you down a path to see if you have vPro. That's on some i5s and i7s. So they are defining "consumer" roughly as "purchased at best buy or similar". There are certainly desktops in people's homes that have vPro. Even some of the higher end NUCs have it.

Re: Intel platforms from 2008 onwards have a remotely exploitable security hole

#165

The short version is that every Intel platform with AMT, ISM, and SBT from Nehalem in 2008 to Kaby Lake in 2017 has a remotely exploitable security hole in the ME (Management Engine) not CPU firmware. We knew this would happen. We knew that the Management Engine was a backdoor, and we knew it was only a matter of time before someone would figure out how to exploit it. This is exactly the reason why Libreboot exists (…

I'm having fun, I finally have an excuse to dust off my Libreboot X200 (refurbished and modded Thinkpad with Libreboot firmware). However, I strongly disrecommend buying from Leah Rowe unless you enjoy waiting months for payment confirmation and delivery. The worst webshop experience I've ever had. I recommend you build/flash your own, contract it out or look for a different vendor.

Has anybody tried the X200 builds from Libiquity?

https://shop.libiquity.com/product/taurinus-x200

Re: Intel platforms from 2008 onwards have a remotely exploitable security hole

#166
Warning: Baseless, Idle Speculation

With the lead time on the silent patch before Shadow Brokers published all the Microsoft exploits, I wonder if Shadow Brokers will be publishing this one soon. No chance of an Intel ME patch going out without being noticed though!

A Shadow Brokers release would be a real mess.

Re: Intel platforms from 2008 onwards have a remotely exploitable security hole

#167
post #61

Earlier quoted context omitted.

Fine, but putting it on all hardware? How many corporate IT environments buy off-the-shelf motherboards and CPUs from the same channels as consumers? OEMs get an entirely different set of parts and enterprise sales works in completely different channels. If there is such a clean separation between corporate and consumer markets then why is this hardware on everything , and why does it need to pull power on the machin…

It isn't on all hardware. Intel has two ME firmwares, a small one for consumer systems, and a big one for corporate/enterprise systems. The small one does not (or at least, should not; is not supposed to) include the remote management features. In other words, the separation that you describe exists. Systems with the full firmware sport things such as the vPro branding, and only certain combinations of CPU and chipse…

I'd be careful with assumptions on what "consumer hardware" means. There are desktops, NUC units, etc, that shipped with i5 and i7 chips that had vPro.

Re: Intel platforms from 2008 onwards have a remotely exploitable security hole

#168
post #83

Earlier quoted context omitted.

This is also what the management engine cleaner project is for: https://github.com/corna/me_cleaner

https://github.com/corna/me_cleaner/wiki/How-to-apply-me_cle... The procedure seems far from trivial and requires special hardware(?). Is there a guide or some resources I could follow as a person with no hardware/low-level technical knowledge?

You're not kidding!

> Internal flashing with OEM firmware

> --------------------------------------------

> TODO

Re: Intel platforms from 2008 onwards have a remotely exploitable security hole

#169
I have a Sun workstation that seems to be no longer supported by Oracle (Sun Ultra 24 with a Q9300). I guess I'll just be vulnerable forever.

I don't really know what AMT does, but this has me thinking, if AMT is provisioned while a machine is used inside a company and then that machine shows up on eBay still provisioned, is it going to be phoning home and still be remotely manageable? How many of these machines have what are essentially persistent rootkits managed by large corporations that have had large fleets of laptops/desktops deployed that are then sold on?

Re: Intel platforms from 2008 onwards have a remotely exploitable security hole

#170
post #26

Security is a cost center and most OEMs run on margins too thin to bother with security patches even if they cared. Most simply don’t care. I think that sums up pretty well why downstream vendors are treating security casually. So the billion dollar question is, how do we fix this, as a tech community?

Open architectures are a solution, even if there is no single common solution. Diversity is something we have been missing since windows became popular, and although security through obscurity is not a strategy, diversity certainly serves well at limiting the scope of damage possible for a single attack.
Post reply on HN