Live data from Hacker News

Intel platforms from 2008 onwards have a remotely exploitable security hole

semiaccurate.com

31–40 of 190 posts

Re: Intel platforms from 2008 onwards have a remotely exploitable security hole

#32
post #9

Is there a better source for this than SemiAccurate? The article doesn't really have much beyond self-aggrandizement and "we can't tell you any details, but you're screwed". For something that could be anything from "Charlie Demerjian heard a rumor about a ME patch and wanted some pageviews" to the actual security apocalypse, I'd like credible sources.

Credibility issues of the author/website aside, I actually hope this is true, and I hope it's catastrophic for Intel.

Maybe then we'll finally see hardware companies taking security seriously.

Re: Intel platforms from 2008 onwards have a remotely exploitable security hole

#33
post #26

Security is a cost center and most OEMs run on margins too thin to bother with security patches even if they cared. Most simply don’t care. I think that sums up pretty well why downstream vendors are treating security casually. So the billion dollar question is, how do we fix this, as a tech community?

I'm not sure the tech community is able to fix this, short of the brickerbot mentioned by another poster. Frankly, I think this situation will only resolve if and only if there are dire financial consequences to OEMs that pay lip service to security.

Re: Intel platforms from 2008 onwards have a remotely exploitable security hole

#34
post #32
post #9

Is there a better source for this than SemiAccurate? The article doesn't really have much beyond self-aggrandizement and "we can't tell you any details, but you're screwed". For something that could be anything from "Charlie Demerjian heard a rumor about a ME patch and wanted some pageviews" to the actual security apocalypse, I'd like credible sources.

Credibility issues of the author/website aside, I actually hope this is true, and I hope it's catastrophic for Intel. Maybe then we'll finally see hardware companies taking security seriously.

I'm worried that it's true and it's not catastrophic for Intel. Aka show to the world that you can get away with BS like this.

Re: Intel platforms from 2008 onwards have a remotely exploitable security hole

#35

What is the management engine, and how does one access it remotely?

it's a closed-source binary blob on intel chipsets with unfettered access to the CPU. it is also (often) directly connected to the RJ45 port.

here's a good overview of the risk: http://hackaday.com/2016/11/28/neutralizing-intels-managemen...

Re: Intel platforms from 2008 onwards have a remotely exploitable security hole

#37
post #32
post #9

Is there a better source for this than SemiAccurate? The article doesn't really have much beyond self-aggrandizement and "we can't tell you any details, but you're screwed". For something that could be anything from "Charlie Demerjian heard a rumor about a ME patch and wanted some pageviews" to the actual security apocalypse, I'd like credible sources.

Credibility issues of the author/website aside, I actually hope this is true, and I hope it's catastrophic for Intel. Maybe then we'll finally see hardware companies taking security seriously.

IME is likely not a case of Intel "not taking security seriously". It's almost certainly a case of doing what FiveEyes demanded of them.

Re: Intel platforms from 2008 onwards have a remotely exploitable security hole

#38
post #26

Security is a cost center and most OEMs run on margins too thin to bother with security patches even if they cared. Most simply don’t care. I think that sums up pretty well why downstream vendors are treating security casually. So the billion dollar question is, how do we fix this, as a tech community?

OEMs are not involved at all with ME afaik, it's exculusively controlled by Intel.

Re: Intel platforms from 2008 onwards have a remotely exploitable security hole

#39

My ignorance is showing, but what product lines are impacted? Obviously things like Xeons and Core iXs, but what about things like Atom processors in tablets?

I think anything with an i5 or i7 in the name has the ME onchip. My spare Thinkpad certainly does & it’s four or five years old at this point in time. I turned the ME off in the bios the moment I acquired it, but I doubt Lenovo will be issuing any bios updates for it.

Re: Intel platforms from 2008 onwards have a remotely exploitable security hole

#40

Are remote management functions of portable consumer electronics (i.e.: remotely wiping your iPad) also supported by similar hardware chips from other vendors?

What does this mean?

IPad remote wipe is a function of IOS and the encrypted filesystem it uses on the device, not the CPU.

Post reply on HN