Intel platforms from 2008 onwards have a remotely exploitable security hole
51–60 of 190 posts
Re: Intel platforms from 2008 onwards have a remotely exploitable security hole
#52What is the motivation behind Management Engine? From the perspective of an everyday user these things came out of nowhere to evolve into this para-computer running along side me that I cannot see and have no control of. It is on literally ALL hardware Why is it that any attempts to disable it knock your whole computer out? And this is the world of technology that we want? I'm so sick of technology companies appearin…
If, for example, an admin needed to add a dual-boot-to-Ubuntu option to every PC on a floor, he could, through ME, remotely reboot (force power reset if necessary) or power on every machine, have the machines boot to a (remote) OS install disk, run the install, and reboot.
ME allows one to do almost anything remotely to a PC, regardless of what the main processor is doing. That is both useful and frightening.
Re: Intel platforms from 2008 onwards have a remotely exploitable security hole
#53I've got a Lenovo T530 and a Lenovo T450s. I wonder if they've released a firmware update yet...? I can't say I'm surprised, but I am surprised at the fact that finally, after all these years, someone finally got down to patching some vulnerabilities in this area. props to whomever forced Intel's hand.
Otherwise check for updates at http://pcsupport.lenovo.com.
Re: Intel platforms from 2008 onwards have a remotely exploitable security hole
#54Earlier quoted context omitted.
it's a closed-source binary blob on intel chipsets with unfettered access to the CPU. it is also (often) directly connected to the RJ45 port. here's a good overview of the risk: http://hackaday.com/2016/11/28/neutralizing-intels-managemen...
So if you don't use the RJ45 port on the motherboard but instead use an RJ45 port on an expansion card instead you're safe?
But I believe newer systems with MMUs acting as "firewalls" for DMA are safe from this vector.
Re: Intel platforms from 2008 onwards have a remotely exploitable security hole
#55What is the motivation behind Management Engine? From the perspective of an everyday user these things came out of nowhere to evolve into this para-computer running along side me that I cannot see and have no control of. It is on literally ALL hardware Why is it that any attempts to disable it knock your whole computer out? And this is the world of technology that we want? I'm so sick of technology companies appearin…
The functionality ME attempts to provide is lights out a.k.a. out-of-band management (like IPMI) to the desktop. If, for example, an admin needed to add a dual-boot-to-Ubuntu option to every PC on a floor, he could, through ME, remotely reboot (force power reset if necessary) or power on every machine, have the machines boot to a (remote) OS install disk, run the install, and reboot. ME allows one to do almost anythi…
How many corporate IT environments buy off-the-shelf motherboards and CPUs from the same channels as consumers? OEMs get an entirely different set of parts and enterprise sales works in completely different channels. If there is such a clean separation between corporate and consumer markets then why is this hardware on everything, and why does it need to pull power on the machine if it's disabled?
Re: Intel platforms from 2008 onwards have a remotely exploitable security hole
#56Is there a better source for this than SemiAccurate? The article doesn't really have much beyond self-aggrandizement and "we can't tell you any details, but you're screwed". For something that could be anything from "Charlie Demerjian heard a rumor about a ME patch and wanted some pageviews" to the actual security apocalypse, I'd like credible sources.
Re: Intel platforms from 2008 onwards have a remotely exploitable security hole
#57Earlier quoted context omitted.
So if you don't use the RJ45 port on the motherboard but instead use an RJ45 port on an expansion card instead you're safe?
Partially. Expansion cards use PCI-E which has DMA capability, so a bug/backdoor in their firmware can very well be used to attack a system. But I believe newer systems with MMUs acting as "firewalls" for DMA are safe from this vector.
Re: Intel platforms from 2008 onwards have a remotely exploitable security hole
#58Earlier quoted context omitted.
Credibility issues of the author/website aside, I actually hope this is true, and I hope it's catastrophic for Intel. Maybe then we'll finally see hardware companies taking security seriously.
I'm worried that it's true and it's not catastrophic for Intel. Aka show to the world that you can get away with BS like this.
Adobe Flash has a new zero-day every week, but we were saddled with it for years past when it should have been retired because some people didn't want HTML5 to have feature-parity with Flash.
Java has a new zero-day every week but we're stuck with it because enterprises are afraid of trying something new.
Windows was wide open to attacks for years, but they got away with it by saying "yeah but Apple is so expensive" and people still parrot that. They said "yeah but Linux is stolen technology/doesn't work right" and people still parrot that.
Android has a new malware/exploit warning every week, the majority of the phones never see security updates, and are running outdated software the minute they're shipped to stores but people say "yeah but Apple is so expensive/locked down" or "Windows Phone doesn't have any apps".
I have friends who lost their credit card numbers at Home Depot but refuse to shop at Lowes because they don't like the NASCAR driver that Lowes sponsors.
People get so caught up in brand loyalty that they're willing to defend "their" company like it's a family member. Even among the tech community, security means nothing. We still use Android phones to get root access, we still use Windows to save some money on our laptops, we still program in PHP because it pays the bills.
Nothing will ever be catastrophic enough. Anyone can get away with it just by creating an "us vs them" mentality with their customers.
Re: Intel platforms from 2008 onwards have a remotely exploitable security hole
#59I've disabled ME on my PC because at some point LMS (Local Management Service) started consuming too much resources for no apparent reason.
Re: Intel platforms from 2008 onwards have a remotely exploitable security hole
#60Joanna Rutkowska, who is a renowned security researcher, warned of something like this happening sooner or later[1], so I don't think I can afford to just ignore this.
But without something more specific to act on, there is nothing I can do, except wait firmware updates to be released by various vendors. If that happens.
And what if Intel does make a statement that essentially says, "This is all total BS"? I wouldn't know whether to believe them or not.
The only scenario where I could have any degree of certainty would be if Intel came out and said, "Yeah there's an exploitable security hole in ME, here's a patch to disable it".
[1] http://blog.invisiblethings.org/papers/2015/x86_harmful.pdf