Live data from Hacker News

Intel patches new ME vulnerabilities

blog.ptsecurity.com

301–310 of 337 posts

Re: Intel patches new ME vulnerabilities

#301
post #282

Earlier quoted context omitted.

And yet, customers still aren't datacenters, but still they carry the risks.

I'm not talking about datacenters, I'm talking about workstations.

In my reply, I used datacenters as a term to describe mass deployed computers (for which a ME actually makes sense). I’m sorry, I should’ve clarified.

Re: Intel patches new ME vulnerabilities

#302

Just a note that if you want to avoid Intel's disastrous Management Engine, there are companies you can support that disable it. Purism[0] sell nice MBP-style, Debian-based laptops with modern Intel processors with the NSA's 'High Assurance Platform' bit set, and as much of the ME code removed as possible. It still runs briefly at boot, but this is the most-disabled you can currently get on any i3/i5/i7 processor[1].…

At that point you should just buy AMD, if only to not support a company like Intel with such a bad security track record.

AMD has an ME equivalent, which is approximately as prevalent. It’s still a DRM/DMCA-protected remote access CPU on your CPU. What could go wrong?

Buying Librebooted machines isn’t directly supporting Intel.

Re: Intel patches new ME vulnerabilities

#303
post #294
post #284

Earlier quoted context omitted.

I know, and this kind of attitude regarding drivers is what as graphics oriented person, eventually pushed me back into the Windows/OS X world. The graphics card was working perfectly fine before they decided to reboot driver support. Now with the legacy driver I have to force enable acceleration and even then I sometimes get the feeling it isn't really working, given how the fan behaves when watching movies on the g…

> Now with the legacy driver I have to force enable acceleration and even then I sometimes get the feeling it isn't really working, given how the fan behaves when watching movies on the go. If you want zero-copy video playback for optimizing battery life use mpv with --hwdec=vaapi. Or vdpau or whatever API is supported with that driver. You can also try switching -vo to vdpau/vaapi from OpenGL. > I know, and this kin…

Thanks for the hints, already tried them.

The issue is that AMD's legacy driver is not the same code as the driver it replaced.

https://www.omgubuntu.co.uk/2016/03/ubuntu-drops-amd-catalys...

On Windows and OS X, the legacy drivers keep working.

Re: Intel patches new ME vulnerabilities

#304

Earlier quoted context omitted.

IIRC AMD allows their PSP to be disabled via the BIOS.

Some do. Though it's unclear what that does yet

It definitely prevents the OS from accessing it over PCI, but whether it prevents the PSP from accessing the OS is indeed unclear.

Re: Intel patches new ME vulnerabilities

#305

Earlier quoted context omitted.

At that point you should just buy AMD, if only to not support a company like Intel with such a bad security track record.

AMD has an ME equivalent, which is approximately as prevalent. It’s still a DRM/DMCA-protected remote access CPU on your CPU. What could go wrong? Buying Librebooted machines isn’t directly supporting Intel.

Sure it's not good that we still have a coprocessor running a proprietary blob, but it's not known to have the ability to use your network card.

Re: Intel patches new ME vulnerabilities

#306

Earlier quoted context omitted.

At that point you should just buy AMD, if only to not support a company like Intel with such a bad security track record.

AMD has an ME equivalent, which is approximately as prevalent. It’s still a DRM/DMCA-protected remote access CPU on your CPU. What could go wrong? Buying Librebooted machines isn’t directly supporting Intel.

But not on AMD machines from 2012 and before. You can buy a high-end motherboard (KGPE-D16) that can run libreboot and 2 16core Opteron 62xx cpu's with 192GB ram. You don't have to go the old and relatively slow thinkpad route to achieve freedom.

Re: Intel patches new ME vulnerabilities

#307
post #159

Earlier quoted context omitted.

There is quite literally no viable alternative to x86 for 95% (more like 99.9%, but I am being generous) of the server and workstation market. Pretending like there is and anyone choosing x86 is irresponsible is just being a smug fool.

POWER is actually competitive on price/performance now.

Eh… Not for the home enthusiast workstation market.

The CPUs are actually kinda reasonable (Raptor sells the 8-core for $595, which is only $95 more than the launch price of the Ryzen 1800X).

But the lite mainboard is $1,099.

That's 5-10 times more that a board for Ryzen. And a lot is missing on the "lite".

Re: Intel patches new ME vulnerabilities

#308
post #54

Finally it happened. Here's to hoping that after being exposed to this kind of risk, enterprises and regular customers start being more inquisitive about what code gets embedded into their hardware and why.

I heard Google spends a lot of money and effort to (slowly) move to Power9. It does have a management processor but it's open for inspection and modification. Maybe other cloud providers, and/or private clouds, would consider that.

Would be incredibly awesome to see POWER9 options on Google's public cloud VMs…

Meanwhile, ARMv8 is already available to the public!

packet.net offers access to a full dedicated dual ThunderX box for $0.5/hr (or 0.1 with spot instances).

Scaleway offers KVM virtual machines (also on ThunderX) for as little as €2.99/month (€0.006/hr).

First gen ThunderX kinda sucks at single-thread performance, but you get many cores and… well, you get to start using non-x86 machines, on public cloud, right now.

If developers start actually using ARM boxes for their projects, the providers will be more likely to expand in this direction, and maybe in a year (or less?) we'll see the much more powerful ThunderX2 boxes available, and hopefully more providers will get into this…

Re: Intel patches new ME vulnerabilities

#309
post #263

Earlier quoted context omitted.

As I understand it, ME is used to remotely control the processor like in a datacenter. If a datacenter is buying hundreds of thousands of these it makes sense to have it on by default so their people don't have to go in and turn anything on. As much as I recognize it as a vulnerability (to the extreme), it doesn't make sense to have it off by default. They should certainly support a way to _permanently_ disable it. I…

It might make sense only on Xeon CPUs, but consumer models like i7 are not meant for data centers.

This is something obvious I had not considered. Good point!

Re: Intel patches new ME vulnerabilities

#310
post #159

Earlier quoted context omitted.

POWER is actually competitive on price/performance now.

Eh… Not for the home enthusiast workstation market. The CPUs are actually kinda reasonable (Raptor sells the 8-core for $595, which is only $95 more than the launch price of the Ryzen 1800X). But the lite mainboard is $1,099. That's 5-10 times more that a board for Ryzen. And a lot is missing on the "lite".

Context here is "server and workstation market".

The Ryzen 1800X is not a comparable CPU.

Post reply on HN