Live data from Hacker News

How Purism avoids Intel’s Active Management Technology

puri.sm

41–50 of 121 posts

Re: How Purism avoids Intel’s Active Management Technology

#41
post #5

Earlier quoted context omitted.

Even though it`s true that ME is not 100% removed, most of it is. https://puri.sm/learn/software-freedom-in-perspective/

The part that can't be removed still has had critical security vulnerabilities, though.

But how would anyone interact with that part?

If it has no NIC access and the OS doesn't have access to it because it's not hanging on PCIe anymore, so if it's only there for system bringup, it's essentially sealed off from the world.

Re: How Purism avoids Intel’s Active Management Technology

#43

I've been hearing about Intel’s Active Management Technology for years, but I'd like to see a demonstration of how an attack would work. I have an unused laptop with: 1. an Intel CPU that supports the vPro feature set 2. an Intel networking card 3. the corporate version of the Intel Management Engine (Intel ME) binary (well, definitely, a corporate laptop that used to get updates, but how do I check for ME?) Is there…

"... the fundamental rule of technological progress: if something can be done, it probably will be done, and possibly already has been." -Edward Snowden (Permanent Record)

Re: How Purism avoids Intel’s Active Management Technology

#44

I've been hearing about Intel’s Active Management Technology for years, but I'd like to see a demonstration of how an attack would work. I have an unused laptop with: 1. an Intel CPU that supports the vPro feature set 2. an Intel networking card 3. the corporate version of the Intel Management Engine (Intel ME) binary (well, definitely, a corporate laptop that used to get updates, but how do I check for ME?) Is there…

There have been two really severe AMT vulnerabilities (basically allowing complete takeover of the PC through the network). These have been patched and no widescale exploitation of them has been reported AFAIK. The other vulnerabilities essentially allow for a super-rootkit: if you can get arbitrary code execution in the AMT from the OS then you can escalate an exploit into a rootkit which is basically impossible to detect or remove, and this kind of exploitation has been seen in the wild.

Re: How Purism avoids Intel’s Active Management Technology

#45
post #44

I've been hearing about Intel’s Active Management Technology for years, but I'd like to see a demonstration of how an attack would work. I have an unused laptop with: 1. an Intel CPU that supports the vPro feature set 2. an Intel networking card 3. the corporate version of the Intel Management Engine (Intel ME) binary (well, definitely, a corporate laptop that used to get updates, but how do I check for ME?) Is there…

There have been two really severe AMT vulnerabilities (basically allowing complete takeover of the PC through the network). These have been patched and no widescale exploitation of them has been reported AFAIK. The other vulnerabilities essentially allow for a super-rootkit: if you can get arbitrary code execution in the AMT from the OS then you can escalate an exploit into a rootkit which is basically impossible to…

> severe AMT vulnerabilities (basically allowing complete takeover of the PC through the network)

Does this mean when the PC was connected by ethernet cable? Even by wifi? The exploit could have worked by visiting an arbitrary website? With no click? (I’m not being skeptical. I just want to understand what’s required for the exploit to work.)

Re: How Purism avoids Intel’s Active Management Technology

#46
post #13
post #4

Earlier quoted context omitted.

Probaly won`t happen since AMD have their own secret code which no one could neutralize yet.

Supposedly it's already in the works: https://twitter.com/jeremy_soller/status/1286457590289858560

Welp. Their response to Raptor in that thread just forever cost System76 my business.

System76 takes the position that compatibility with x86 binaries is worth having to take closed, remote-access-enabled, binary firmware. That's a position someone can take.

Responding "So what?" and "I was expecting this" is just nasty and unprofessional.

Re: How Purism avoids Intel’s Active Management Technology

#48
post #46
post #13

Earlier quoted context omitted.

Supposedly it's already in the works: https://twitter.com/jeremy_soller/status/1286457590289858560

Welp. Their response to Raptor in that thread just forever cost System76 my business. System76 takes the position that compatibility with x86 binaries is worth having to take closed, remote-access-enabled, binary firmware. That's a position someone can take. Responding "So what?" and "I was expecting this" is just nasty and unprofessional.

Yeah, that was strange. Sounds like there is some argument history behind it.

Re: How Purism avoids Intel’s Active Management Technology

#50
post #44

Earlier quoted context omitted.

There have been two really severe AMT vulnerabilities (basically allowing complete takeover of the PC through the network). These have been patched and no widescale exploitation of them has been reported AFAIK. The other vulnerabilities essentially allow for a super-rootkit: if you can get arbitrary code execution in the AMT from the OS then you can escalate an exploit into a rootkit which is basically impossible to…

> severe AMT vulnerabilities (basically allowing complete takeover of the PC through the network) Does this mean when the PC was connected by ethernet cable? Even by wifi? The exploit could have worked by visiting an arbitrary website? With no click? (I’m not being skeptical. I just want to understand what’s required for the exploit to work.)

Here’s one from 2017: https://www.tomshardware.com/news/intel-amt-patch-may-8,3434...

Connected to Ethernet (with Intel hardware), but doesn’t need to be turned on. Must have vPro and AMT enabled.

Post reply on HN