Live data from Hacker News

Intel patches new ME vulnerabilities

blog.ptsecurity.com

21–30 of 337 posts

Re: Intel patches new ME vulnerabilities

#21
post #18
post #13

My CPU has an HTTP server? But why?

Your CPU actually runs its own entire, separate operating system - MINIX. https://www.cs.vu.nl/~ast/intel/

This is known, but that link has no information relevant to the HTTP protocol. Do you know more about that?

Re: Intel patches new ME vulnerabilities

#25
post #3
post #2

Intel advisory: https://www.intel.com/content/www/us/en/security-center/advi... CVE-2018-3628 - "Buffer overflow in HTTP handler" Affected processor list (simplified reordered by me to reflect relevance and improve readability): • Core i3/i5/i7, generation 1-8 (that is, all of them) • Xeon E3-1200 v5/v6 • Xeon Scalable • Xeon W • Core 2 Duo vPro, Centrino 2 vPro

Also worth noting that they're not patching it for 1st, 2nd or 3rd generation Core CPUs. I'm sure there's plenty of Sandy Bridge/Ivy Bridge CPUs in the wild, and it's not like you have an option to discontinue use of the Intel ME :(

Planned obsolescence of otherwise viable product implemented via a certain-to-be-exploited architecture (the ME) followed by strategic withholding of patches?

Re: Intel patches new ME vulnerabilities

#27
post #14
post #5

I wonder, who ever uses these "management engines," let alone put them open on WANs? When first news of IME being compromised, I was surprised that Shodan showed such a small number of machines.

When dealing with consumer-grade network equipment, this is the same question that always comes to my mind: who decided these devices should have their management features open for WAN access by default? I'm still not sure if it was an early 2000s fad that nobody really thought about, or it was deliberate (and if so, why).

Most of the routers I've seen only have their management interfaces open on the local network, not on the WAN port.

Re: Intel patches new ME vulnerabilities

#28
post #2

Intel advisory: https://www.intel.com/content/www/us/en/security-center/advi... CVE-2018-3628 - "Buffer overflow in HTTP handler" Affected processor list (simplified reordered by me to reflect relevance and improve readability): • Core i3/i5/i7, generation 1-8 (that is, all of them) • Xeon E3-1200 v5/v6 • Xeon Scalable • Xeon W • Core 2 Duo vPro, Centrino 2 vPro

Every time I am about to upgrade this happens. cpu0: Intel(R) Pentium(R) D CPU 3.00GHz, 2993.01 MHz

Re: Intel patches new ME vulnerabilities

#30
post #3

Earlier quoted context omitted.

Also worth noting that they're not patching it for 1st, 2nd or 3rd generation Core CPUs. I'm sure there's plenty of Sandy Bridge/Ivy Bridge CPUs in the wild, and it's not like you have an option to discontinue use of the Intel ME :(

No real advancement after Sandy Bridge was made. Only incremental 10% with each gen. That means current gen is only 2x as fast when comparing the same lines (i7 to i7). If you can't make new things better, just gimp the old ones, like Spectre/Meltdown.

2 times faster would be quite good actually. Sadly we're barely at 50% faster per core, and that's including the usual 20-30% frequency bump on newer models. Pure IPC improvement is even lower, at maybe 2-5% per generation (~30% total at same frequency, 2nd gen vs. 7th gen).

Yeah, you could argue that doubling the core or thread count doubled performance in selected software but the reality is that for real world use, excluding specific corner cases, the improvement is hard to notice.

A reason to upgrade is to have a newer platform and the features that would bring, definitely not the CPU.

Post reply on HN