Live data from Hacker News

An in-depth security review of the Intel Management Engine

security-center.intel.com

161–170 of 192 posts

Re: An in-depth security review of the Intel Management Engine

#161

what i don't get is how would the consumer benefit of having these features? it all looks like a nonsense to me and I'd rather live without it. i think it's time to say goodbye to Intel and opt for another vendor.

That's the problem. There are no REAL alternatives.

I'd be glad to switch to raspberry pie or AMD, but I don't know whether or not those chips have similar crap in them. is the Intel alone with this? do others do it too?

Re: An in-depth security review of the Intel Management Engine

#162
post #125

Don't rush to apply the Intel ME patch! Several HN users here (beefhash, jlgaddis, joe_the_user) have raised the possibility that applying the patch might make it impossible to get rid of the Intel ME entirely. If you don't apply the patch, someone may come up with a nice new exploit (using the security bugs) to completely remove the Intel ME. If you do apply the patch, it might close off possible exploits and you'll…

Right now to remove ME you need to connect an external flash programmer. It seems really unlikely that anything they do with a firmware update will be able to block that at least if someone can get a pre-change image. Maybe there is a way to reprogram to disable ME without the flash programmer which these fixes may block. If my laptop weren't already ME disabled, I'd probably apply the fixes.

> .. can get a pre-change image.

Isn't there an "eFUSE-like" counter that prevents firmware rollback?

Re: An in-depth security review of the Intel Management Engine

#163
post #8

Wow all 6th, 7th and 8th gen are all vulnerable along with a bunch of Xeon processors. Even the laptop I am typing this on is vulnerable, this is going to be messy. Plus all the fun vulnerabilities like arbitrary code execution, unauthorized access to privileged content. These must be related to the blackhat talk coming up in December about hacking a turned-off computer and running unsigned code on ME [0]. Yep and th…

> this is going to be one of those situations that ends up leaving millions of devices unpatched and vulnerable a few years down the road.

Intel managed to make PCs as safe as Android.

Re: An in-depth security review of the Intel Management Engine

#164
post #8

Wow all 6th, 7th and 8th gen are all vulnerable along with a bunch of Xeon processors. Even the laptop I am typing this on is vulnerable, this is going to be messy. Plus all the fun vulnerabilities like arbitrary code execution, unauthorized access to privileged content. These must be related to the blackhat talk coming up in December about hacking a turned-off computer and running unsigned code on ME [0]. Yep and th…

> I wonder if this will at all dissuade either Intel or AMD into continuing to make these super privileged processors whose functions are completely hidden Our brightest hope for reform involves (a) a breach involving ME and (b) European regulators laying fines on Intel.

What about fully libre firmware such as libreboot? What about isolating and disabling the ME as what Purism has done? What about fully open processors based upon open instruction sets such as RISC-V?

Re: An in-depth security review of the Intel Management Engine

#165
post #8

Wow all 6th, 7th and 8th gen are all vulnerable along with a bunch of Xeon processors. Even the laptop I am typing this on is vulnerable, this is going to be messy. Plus all the fun vulnerabilities like arbitrary code execution, unauthorized access to privileged content. These must be related to the blackhat talk coming up in December about hacking a turned-off computer and running unsigned code on ME [0]. Yep and th…

Please let this give rise to a class-action lawsuit. It's the only way this crap will stop.

What exactly would be the identifyable damage?

Re: An in-depth security review of the Intel Management Engine

#166

Earlier quoted context omitted.

My alternative is a Librem: https://puri.sm/posts/purism-librem-laptops-completely-disab...

Note that the ME still runs on their platforms. They are not being honest about that fact.

Actually Purism is being completely honest that they have isolated and disabled the ME while not actually removing it.

Re: An in-depth security review of the Intel Management Engine

#167
post #17

Earlier quoted context omitted.

Well, maybe AMD does at least some security reviewing on their own? /s ARM could be a affordable alternative to x86 if that works for you.

AMD PSP is an ARM core. Running some derivative of Trustonic OS (based on L4), if I'm not mistaken.

Somewhat numerous that the most secure OS kernel (the L4) is utilized in a bad way to result in a less secure system overall.

Re: An in-depth security review of the Intel Management Engine

#168

Earlier quoted context omitted.

It's sad to me that manually setting an IRQ is so horrible a prospect that it's better to compromise the entire system. Honestly, I don't understand why there needs to be another CPU in the system. Do systems really need arbitrary bus protocol translation in real time? If people could agree to reasonable standards (a real possibility in the technological asymptote we have entered) we can eliminate this complexity ent…

> Honestly, I don't understand why there needs to be another CPU in the system. There are tons of processors in modern systems. Most separate chips for controlling sub-systems have them, like DRAM, NICs, USB, keyboards, monitors, storage devices, video cards, etc... The reasons are performance and flexibility - when separate components act like remote hosts, the device manufacturer can divide up work between the OS d…

To add to that: this is really nothing new, hard drives have had such chips for decades now, and even floppy disk drive for Commodore [0] was powered by its own 6502 CPU back in the 1980s.

[0] https://en.m.wikipedia.org/wiki/Commodore_1541

Post reply on HN