Live data from Hacker News

Intel platforms from 2008 onwards have a remotely exploitable security hole

semiaccurate.com

41–50 of 190 posts

Re: Intel platforms from 2008 onwards have a remotely exploitable security hole

#41
post #32

Earlier quoted context omitted.

Credibility issues of the author/website aside, I actually hope this is true, and I hope it's catastrophic for Intel. Maybe then we'll finally see hardware companies taking security seriously.

IME is likely not a case of Intel "not taking security seriously". It's almost certainly a case of doing what FiveEyes demanded of them.

You're probably right.

I still hope it's true, and that it's catastrophic for Intel. No change can happen otherwise.

If Intel aren't fighting against 5eyes then they aren't taking security seriously.

Re: Intel platforms from 2008 onwards have a remotely exploitable security hole

#42
Even without any newly discovered backdoor. The Intel ME was always a fuing security issue. A BACKDOOR. It is completely naive to think the NSA can't use the ME to get access to anything, but hey it needs another Snowden for people to listen again.

Re: Intel platforms from 2008 onwards have a remotely exploitable security hole

#43
What is the motivation behind Management Engine?

From the perspective of an everyday user these things came out of nowhere to evolve into this para-computer running along side me that I cannot see and have no control of. It is on literally ALL hardware

Why is it that any attempts to disable it knock your whole computer out?

And this is the world of technology that we want? I'm so sick of technology companies appearing to work for their customers but secretly working against them.

Re: Intel platforms from 2008 onwards have a remotely exploitable security hole

#44

What is the management engine, and how does one access it remotely?

it's a closed-source binary blob on intel chipsets with unfettered access to the CPU. it is also (often) directly connected to the RJ45 port. here's a good overview of the risk: http://hackaday.com/2016/11/28/neutralizing-intels-managemen...

So if you don't use the RJ45 port on the motherboard but instead use an RJ45 port on an expansion card instead you're safe?

Re: Intel platforms from 2008 onwards have a remotely exploitable security hole

#45
"It is this last point that has been causing some political unrest in the US, and the rest of the Western world. As you undoubtedly know, China is very nearly the sole producer of all electronic goods. It would be very, very easy for the Chinese government to slip a hardware backdoor into the firmware of every iPad, smartphone, PC, and wireless router." 2012 https://www.extremetech.com/computing/133773-rakshasa-the-ha...

Made in China, designed in the USA. Everyone wants their own backdoor.

Re: Intel platforms from 2008 onwards have a remotely exploitable security hole

#46
I think it is high time for companies who make hardware be financially fined for lapses like this. In this particular case, the manufacturer was warned and did nothing for years.

This is negligence especially considering these chips control critical devices that can cause damage or even loss of life if they are successfully exploited.

Can you imagine if car maker didn't fix a hardware defect they knew for years. Oh wait...

Re: Intel platforms from 2008 onwards have a remotely exploitable security hole

#48
> For obvious reasons we couldn’t publish what we found

It's not obvious to me why anyone not under an NSL or NDA would sit on this vulnerability for 5 years and wait until it's actively being exploited in the wild before public disclosure.

It's extremely negligent to global security for SemiAccurate to not immediately publicly disclose the vulnerability 5 years ago after Intel refused to fix it. Of course this is ignoring the root of the problem, which is that the US government has deeply compromised Intel since the very first security management interfaces were added to Intel chips in the early 90s.

The real solution to the root issue is legislation that forces security disclose timelines of 90 days or less for government-found vulnerabilities, and prevents the stockpiling of vulnerability exploit kits.

Re: Intel platforms from 2008 onwards have a remotely exploitable security hole

#49

Are remote management functions of portable consumer electronics (i.e.: remotely wiping your iPad) also supported by similar hardware chips from other vendors?

There is a laptop theft recovery/tracking software called LoJack for Laptops (AKA CompuTrace). Some laptop manufactures have added BIOS support for this service (Dell, HP, Lenovo, etc). According to the Wikipedia article [1] this BIOS service copies a downloader into the System32 folder on Windows, which then downloads the full service. It doesn't appear that the BIOS service itself is remotely exploitable, however it can be used for persistent root-kits [2].

[1] https://en.wikipedia.org/wiki/LoJack_for_Laptops [2] https://en.wikipedia.org/wiki/LoJack_for_Laptops#Vulnerabili...

Re: Intel platforms from 2008 onwards have a remotely exploitable security hole

#50

Great news that this finally came to light. After learning about remote management capabilities I've always suspected it had holes. Large attack surface, any exploit would have a high value, and closed source. Perhaps one day we'll be able to buy CPU's without this "feature". I'm betting AMD and ARM are in the same boat.

They are. AMD TrustZone runs an ARM core alongside your computer. I've also heard a lot of ARM SoC platforms have something similar.
Post reply on HN