Live data from Hacker News

Intel platforms from 2008 onwards have a remotely exploitable security hole

semiaccurate.com

181–190 of 190 posts

Re: Intel platforms from 2008 onwards have a remotely exploitable security hole

#181
post #2

>>every Intel platform with AMT, ISM, and SBT from Nehalem in 2008 to Kaby Lake in 2017 has a remotely exploitable security hole in the ME (Management Engine) not CPU firmware. >>there is literally no Intel box made in the last 9+ years that isn’t at risk >>SemiAccurate has been begging Intel to fix this issue for literally years Am I the only one who is so cynical to think it must have been deliberate? Intel draggin…

reminds me of CIA's Simple Sabotage Field Manual[0]

https://www.cia.gov/news-information/featured-story-archive/...

Re: Intel platforms from 2008 onwards have a remotely exploitable security hole

#182
post #85
post #71

Earlier quoted context omitted.

Let's hope one of the other CPU manufacturers (e.g. AMD) starts supporting LibreBoot and allows to officially disable the ME-equivalent hardware feature, so that Intel get's forced by market-pressur to follow. Intel needs more competition - thanks to AMD latest new 8-core CPU Intel got forced to release a new CPU the had in their basement for years - suddently it's possible for them to release i7 notebook CPUs with m…

That was the top request in their March AMA: https://www.reddit.com/r/Amd/comments/5x4hxu/we_are_amd_crea... I wouldn't hold my breath, though.

The sad thing with that is that

- releasing the source doesn't tell you what's on the chip.

- PSP is kind of "Ring ∞", so there would be no good outcome from providing general-purpose access to it. So, the keys will never be released.

- it's thusly not possible to map the signed (encrypted) firmware to the source.

- even if the source had a clearly documented "master off" in it, you can never know if the firmware's copy reads "master-except-if-A-and-B-say-C off" :(

Re: Intel platforms from 2008 onwards have a remotely exploitable security hole

#183
post #114
post #38

Earlier quoted context omitted.

OEMs are not involved at all with ME afaik, it's exculusively controlled by Intel.

OEMs have to ship ME firmware updates; Intel has no way to get them to you directly.

Can't they install an update remotely via this vulnerability? :p

Re: Intel platforms from 2008 onwards have a remotely exploitable security hole

#184

The short version is that every Intel platform with AMT, ISM, and SBT from Nehalem in 2008 to Kaby Lake in 2017 has a remotely exploitable security hole in the ME (Management Engine) not CPU firmware. We knew this would happen. We knew that the Management Engine was a backdoor, and we knew it was only a matter of time before someone would figure out how to exploit it. This is exactly the reason why Libreboot exists (…

If the verilog to the chip isn't open, you can't trust it. Stallman is dangerously wrong on this point.

[deleted]

Re: Intel platforms from 2008 onwards have a remotely exploitable security hole

#185
post #71

Earlier quoted context omitted.

Let's hope one of the other CPU manufacturers (e.g. AMD) starts supporting LibreBoot and allows to officially disable the ME-equivalent hardware feature, so that Intel get's forced by market-pressur to follow. Intel needs more competition - thanks to AMD latest new 8-core CPU Intel got forced to release a new CPU the had in their basement for years - suddently it's possible for them to release i7 notebook CPUs with m…

> release i7 notebook CPUs with more then two cores U-series i7s have two cores. HQ-series i7s have four cores. Both are mobile CPUs. Remember though that more cores generally means more power consumption which generally means less wallclock time on battery power.

Intel's U-8XXX CPUs are rumored to offer 4 cores with a variable TDP from 18-45W this autumn.

It's my tinfoil hat theory why MS waits for an earnest update on their highend Surfacebook. A high-end quad-core Surfacebook with a 10-series GPU and 32GB LPDDR with real Thunderbolt 3 Ports would make for a 13" dreammachine...

Re: Intel platforms from 2008 onwards have a remotely exploitable security hole

#186
post #60

As a sysadmin at a Windows shop, I don't know what to make of this. Has Intel commented on this, yet? Any OEM? Joanna Rutkowska, who is a renowned security researcher, warned of something like this happening sooner or later[1], so I don't think I can afford to just ignore this. But without something more specific to act on, there is nothing I can do, except wait firmware updates to be released by various vendors. If…

This thread (and the link for it) have some decent information, for those looking for it. It had a cross-link here, figured I might as well link back to it: https://news.ycombinator.com/item?id=14242508

Re: Intel platforms from 2008 onwards have a remotely exploitable security hole

#187

Earlier quoted context omitted.

If the verilog to the chip isn't open, you can't trust it. Stallman is dangerously wrong on this point.

Somewhere you have to externalize trust. What use is the open HDL code for a chip if you cannot be sure someone down in the manufacturing chain hasn't... modified it? Certainly this kind of attack is not your average script kiddy but nation-level instead, but I wouldn't put it past the NSA to pull this off.

If only we could checksum the commercial hardware and compare it to a reference implementation checksum.

Re: Intel platforms from 2008 onwards have a remotely exploitable security hole

#188

Earlier quoted context omitted.

? Nehalem had mobile quad cores. I'm using one right now.

Specifically the Clarksfield processors from 2009: https://en.wikipedia.org/wiki/Clarksfield_(microprocessor) Predating the i7 entirely, there were also quad core laptops using Core 2 Quad CPUs (Penryn QC) in 2008.

Indeed (have some of those too), but I assumed we'd artificially limited ourselves to talking about i7. I'm not sure why I assumed that, because you're right of course.

Re: Intel platforms from 2008 onwards have a remotely exploitable security hole

#189
post #167
post #61

Earlier quoted context omitted.

It isn't on all hardware. Intel has two ME firmwares, a small one for consumer systems, and a big one for corporate/enterprise systems. The small one does not (or at least, should not; is not supposed to) include the remote management features. In other words, the separation that you describe exists. Systems with the full firmware sport things such as the vPro branding, and only certain combinations of CPU and chipse…

I'd be careful with assumptions on what "consumer hardware" means. There are desktops, NUC units, etc, that shipped with i5 and i7 chips that had vPro.

Even with the CPU, you also need the right chipset and the right firmware to actually light this stuff up. While especially in the laptop sector there are consumer devices that include this, it's far from universal.

Re: Intel platforms from 2008 onwards have a remotely exploitable security hole

#190
post #183
post #114

Earlier quoted context omitted.

OEMs have to ship ME firmware updates; Intel has no way to get them to you directly.

Can't they install an update remotely via this vulnerability? :p

No joke, this would be the best thing for everyone. Especially if we find a way to do it ourselves rather than wait for a vendor to.

I've been thinking for years about writing a virus that patches the vulnerability it used to spread as it goes.

Post reply on HN