Site is throwing NET::ERR_CERT_AUTHORITY_INVALID on latest Chrome Canary, is anyone else seeing that?
Intel platforms from 2008 onwards have a remotely exploitable security hole
31–40 of 190 posts
Re: Intel platforms from 2008 onwards have a remotely exploitable security hole
#32Is there a better source for this than SemiAccurate? The article doesn't really have much beyond self-aggrandizement and "we can't tell you any details, but you're screwed". For something that could be anything from "Charlie Demerjian heard a rumor about a ME patch and wanted some pageviews" to the actual security apocalypse, I'd like credible sources.
Maybe then we'll finally see hardware companies taking security seriously.
Re: Intel platforms from 2008 onwards have a remotely exploitable security hole
#33Security is a cost center and most OEMs run on margins too thin to bother with security patches even if they cared. Most simply don’t care. I think that sums up pretty well why downstream vendors are treating security casually. So the billion dollar question is, how do we fix this, as a tech community?
Re: Intel platforms from 2008 onwards have a remotely exploitable security hole
#34Is there a better source for this than SemiAccurate? The article doesn't really have much beyond self-aggrandizement and "we can't tell you any details, but you're screwed". For something that could be anything from "Charlie Demerjian heard a rumor about a ME patch and wanted some pageviews" to the actual security apocalypse, I'd like credible sources.
Credibility issues of the author/website aside, I actually hope this is true, and I hope it's catastrophic for Intel. Maybe then we'll finally see hardware companies taking security seriously.
Re: Intel platforms from 2008 onwards have a remotely exploitable security hole
#35What is the management engine, and how does one access it remotely?
here's a good overview of the risk: http://hackaday.com/2016/11/28/neutralizing-intels-managemen...
Re: Intel platforms from 2008 onwards have a remotely exploitable security hole
#36Re: Intel platforms from 2008 onwards have a remotely exploitable security hole
#37Is there a better source for this than SemiAccurate? The article doesn't really have much beyond self-aggrandizement and "we can't tell you any details, but you're screwed". For something that could be anything from "Charlie Demerjian heard a rumor about a ME patch and wanted some pageviews" to the actual security apocalypse, I'd like credible sources.
Credibility issues of the author/website aside, I actually hope this is true, and I hope it's catastrophic for Intel. Maybe then we'll finally see hardware companies taking security seriously.
Re: Intel platforms from 2008 onwards have a remotely exploitable security hole
#38Security is a cost center and most OEMs run on margins too thin to bother with security patches even if they cared. Most simply don’t care. I think that sums up pretty well why downstream vendors are treating security casually. So the billion dollar question is, how do we fix this, as a tech community?
Re: Intel platforms from 2008 onwards have a remotely exploitable security hole
#39My ignorance is showing, but what product lines are impacted? Obviously things like Xeons and Core iXs, but what about things like Atom processors in tablets?
Re: Intel platforms from 2008 onwards have a remotely exploitable security hole
#40Are remote management functions of portable consumer electronics (i.e.: remotely wiping your iPad) also supported by similar hardware chips from other vendors?
IPad remote wipe is a function of IOS and the encrypted filesystem it uses on the device, not the CPU.