Earlier quoted context omitted.
I'm having fun, I finally have an excuse to dust off my Libreboot X200 (refurbished and modded Thinkpad with Libreboot firmware). However, I strongly disrecommend buying from Leah Rowe unless you enjoy waiting months for payment confirmation and delivery. The worst webshop experience I've ever had. I recommend you build/flash your own, contract it out or look for a different vendor.
Has anybody tried the X200 builds from Libiquity? https://shop.libiquity.com/product/taurinus-x200
Intel platforms from 2008 onwards have a remotely exploitable security hole
171–180 of 190 posts
Re: Intel platforms from 2008 onwards have a remotely exploitable security hole
#172The short version is that every Intel platform with AMT, ISM, and SBT from Nehalem in 2008 to Kaby Lake in 2017 has a remotely exploitable security hole in the ME (Management Engine) not CPU firmware. We knew this would happen. We knew that the Management Engine was a backdoor, and we knew it was only a matter of time before someone would figure out how to exploit it. This is exactly the reason why Libreboot exists (…
Let's hope one of the other CPU manufacturers (e.g. AMD) starts supporting LibreBoot and allows to officially disable the ME-equivalent hardware feature, so that Intel get's forced by market-pressur to follow. Intel needs more competition - thanks to AMD latest new 8-core CPU Intel got forced to release a new CPU the had in their basement for years - suddently it's possible for them to release i7 notebook CPUs with m…
U-series i7s have two cores. HQ-series i7s have four cores. Both are mobile CPUs. Remember though that more cores generally means more power consumption which generally means less wallclock time on battery power.
Re: Intel platforms from 2008 onwards have a remotely exploitable security hole
#173Thank you, SemiAccurate, for sitting on a vulnerability for years when you could've reported on it long ago and not had us left with this garbage of a security hole to deal with.
Re: Intel platforms from 2008 onwards have a remotely exploitable security hole
#174Is there a better source for this than SemiAccurate? The article doesn't really have much beyond self-aggrandizement and "we can't tell you any details, but you're screwed". For something that could be anything from "Charlie Demerjian heard a rumor about a ME patch and wanted some pageviews" to the actual security apocalypse, I'd like credible sources.
How about The Register? https://www.theregister.co.uk/2017/05/01/intel_amt_me_vulner... There's also an Intel advisory https://security-center.intel.com/advisory.aspx?intelid=INTE...
> There is an escalation of privilege vulnerability in Intel® Active Management Technology (AMT), Intel® Standard Manageability (ISM), and Intel® Small Business Technology versions firmware versions 6.x, 7.x, 8.x 9.x, 10.x, 11.0, 11.5, and 11.6 that can allow an unprivileged attacker to gain control of the manageability features provided by these products. This vulnerability does not exist on Intel-based consumer PCs.
If in doubt, you can check your CPUs here:
Re: Intel platforms from 2008 onwards have a remotely exploitable security hole
#175Earlier quoted context omitted.
As pointed out by another commenter, Intel has released the advisary: https://security-center.intel.com/advisory.aspx?intelid=INTE... It confirms much of the SemiAccurate report, but also includes this: "This vulnerability does not exist on Intel-based consumer PCs." Which seems to differ from what SemiAccurate was saying. I'm not sure if it's SemiAccurate being... er... not completely accurate :D, or if it's Intel t…
Looking at the Intel link, they take you down a path to see if you have vPro. That's on some i5s and i7s. So they are defining "consumer" roughly as "purchased at best buy or similar". There are certainly desktops in people's homes that have vPro. Even some of the higher end NUCs have it.
When I've purchased VirtualBox hosts, I've deliberately avoided stuff with vPro.
Re: Intel platforms from 2008 onwards have a remotely exploitable security hole
#176Earlier quoted context omitted.
The article implies that they have been privately trying to get Intel to fix it, so there is no reason it would have been mentioned publicly anywhere. Now a patch is coming out but Intel is still trying to keep it quiet, so he's trying to warn people disable AMT and be ready to apply patches ASAP. Presumably he didn't even want to disclose the existence of the vulnerability publicly until there was some sort of fix,…
If Charlie was a security researcher and SemiAccurate was a well-regarded security firm, I would not expect details or cross-references or mentions on security lists. Charlie is not a security researcher, he's a journalist, and SemiAccurate is the tech equivalent of a supermarket tabloid. He is not a credible primary source for anything security-related, particularly given SemiAccurate's reputation for publishing rum…
Re: Intel platforms from 2008 onwards have a remotely exploitable security hole
#177EDIT: I have a Core i3-4130T. Looks like it doesn't have vPro so I'm hoping I'm safe?
Re: Intel platforms from 2008 onwards have a remotely exploitable security hole
#178Earlier quoted context omitted.
Just get a computer that doesn't have vPro.
That disqualifies a lot of otherwise really good hardware. My current Thinkpad, for example, and all current MBPs, I believe. Some manufacturers also aren't very clear about the exact hardware in their machines, either. (For example, Apple doesn't list the exact CPU on their tech specs page, only the somewhat vague "2.4GHz dual-core Intel Core i7, Turbo Boost up to 3.4GHz, with 4MB shared L3 cache". That might be un…
The filter for "Max Turbo Frequency" seems to be broken, BUT searching for "Cache: '4MB L3 SmartCache'" (which I assume means shared!) finds quite a number of results: http://ark.intel.com/Search/FeatureFilter?productType=proces...
The list is column-sortable by Max Turbo Frequency, and there are just 4 results in the 3.40GHz range:
- http://ark.intel.com/products/91169/Intel-Core-i7-6660U-Proc... - the only result with a Processor Base Frequency of 2.4GHz
- http://ark.intel.com/products/91497/Intel-Core-i7-6650U-Proc...
- http://ark.intel.com/products/88192/Intel-Core-i7-6600U-Proc...
- http://ark.intel.com/products/52231/Intel-Core-i7-2620M-Proc...
Re: Intel platforms from 2008 onwards have a remotely exploitable security hole
#179Earlier quoted context omitted.
The fact that people can stay behind platforms, companies, and technologies that are proven to be so inherently insecure that they can never be trusted just boggles my mind. Adobe Flash has a new zero-day every week, but we were saddled with it for years past when it should have been retired because some people didn't want HTML5 to have feature-parity with Flash. Java has a new zero-day every week but we're stuck wit…
>Java has a new zero-day every week but we're stuck with it Well, Java applets did die. What more do you want? The Java sandbox is only used by extremely legacy software at this point, so it doesn't matter if it has holes in it. Actually, the more holes the better, so we can get rid of the last holdouts.
Re: Intel platforms from 2008 onwards have a remotely exploitable security hole
#180> For obvious reasons we couldn’t publish what we found It's not obvious to me why anyone not under an NSL or NDA would sit on this vulnerability for 5 years and wait until it's actively being exploited in the wild before public disclosure. It's extremely negligent to global security for SemiAccurate to not immediately publicly disclose the vulnerability 5 years ago after Intel refused to fix it. Of course this is ig…
It gets more confusing because Intel is crediting Maksim Malyutin from Embedi: https://security-center.intel.com/advisory.aspx?intelid=INTE... Intel would like to thank Maksim Malyutin from Embedi for reporting this issue and working with us on coordinated disclosure.