Live data from Hacker News

Intel AMT Checker for Linux

github.com

61–70 of 93 posts

Re: Intel AMT Checker for Linux

#61

I'm shocked to say that the Thinkpad x260 does not have AMT at all. Shocked not because I think it's a huge conspiracy to control your computer but because I honestly do believe AMT was made with the best intentions of providing a level of theft mitigation for devices. Just like "Find my Mac" from Apple that seems to get very little flack. I'd be surprised if this meant that my pretty expensive Lenovo Thinkpad X-seri…

When you first set up your Mac, you are asked explicitly whether you want Find My Mac turned on and the Preference to turn it off is then in plain sight in the iCloud preferences. In what way are the two comparable?

i don't think anyone has found a machine yet where AMT is enabled out of the box either

Re: Intel AMT Checker for Linux

#62

I'm shocked to say that the Thinkpad x260 does not have AMT at all. Shocked not because I think it's a huge conspiracy to control your computer but because I honestly do believe AMT was made with the best intentions of providing a level of theft mitigation for devices. Just like "Find my Mac" from Apple that seems to get very little flack. I'd be surprised if this meant that my pretty expensive Lenovo Thinkpad X-seri…

Lenovo lists the X260 as vulnerable to CVE-2017-5689 [0], implying it supports AMT. My X240 definitely has AMT, it would be a bit odd for them to remove it in later generations.

[0] https://support.lenovo.com/us/en/product_security/LEN-14963

Re: Intel AMT Checker for Linux

#63

Earlier quoted context omitted.

When you first set up your Mac, you are asked explicitly whether you want Find My Mac turned on and the Preference to turn it off is then in plain sight in the iCloud preferences. In what way are the two comparable?

i don't think anyone has found a machine yet where AMT is enabled out of the box either

AMT is enabled by default (but not provisioned) on an X220, for example.

Re: Intel AMT Checker for Linux

#64
post #20
post #13

Earlier quoted context omitted.

The issues page has a report of the same error (as does my i5-6600) and the author says: >Ok, I'm /inclined/ to believe that this indicates that the system doesn't implement AMT at all, but I'll try to do some more research.

I got this message on a system which has a Core i7-4510 CPU; this is not on the list of systems with "vPro" technology. I've seen referenced as another name for the vulnerable component --- but given the marketing-spawned confusion around Intel CPU nomenclature, I can easily imagine someone (perhaps me!) getting confused on the point. Search for "vPro" systems here: https://ark.intel.com/Search/FeatureFilter?productT…

This isn't that helpful because you need a vPro-capable CPU and the proper chipset and AMT firmware to be vulnerable.

Re: Intel AMT Checker for Linux

#65
post #63

Earlier quoted context omitted.

i don't think anyone has found a machine yet where AMT is enabled out of the box either

AMT is enabled by default (but not provisioned) on an X220, for example.

sorry, I meant provisioned.

As far as I know (could be wrong) it doesn't even listen to any network ports until its provisioned

Re: Intel AMT Checker for Linux

#66
post #42

Earlier quoted context omitted.

The machine is self-assembled, and the motherboard manufacturer doesn’t provide updates. I don’t run windows, though. > Well, firstly, don't connect your machine to networks you don't trust the members of :) I’ve already had issues with the intel card, so I’m running on a RealTek ethernet card for now anyway. But that’s no long term solution.

Now I’m curious how a self-assembled computer got into the provisioned state.

That’s an interesting question, isn’t it? Even more, how AMT was enabled in the first place, if the UEFI has no option for it.

And I’ve had massive issues with AMT before – for some reason, on Linux, the ME would force a reset of the network connection every 90 seconds (which is why I use an ancient realtek network card currently).

Possible explanations include bad defaults in the UEFI, a store sending me a used part instead of a new part, etc. If we go into conspiracy territory, NSA TAO interception would also be on the table. Very unlikely, though.

Re: Intel AMT Checker for Linux

#68
post #63

Earlier quoted context omitted.

AMT is enabled by default (but not provisioned) on an X220, for example.

sorry, I meant provisioned. As far as I know (could be wrong) it doesn't even listen to any network ports until its provisioned

Ah, then yes, it seems, and you should be right (at least in principle - I'm not sure, either) with regards to network ports. (I've done some light scanning out of curiosity, but that's only anecdotal...)

Re: Intel AMT Checker for Linux

#69
post #62

I'm shocked to say that the Thinkpad x260 does not have AMT at all. Shocked not because I think it's a huge conspiracy to control your computer but because I honestly do believe AMT was made with the best intentions of providing a level of theft mitigation for devices. Just like "Find my Mac" from Apple that seems to get very little flack. I'd be surprised if this meant that my pretty expensive Lenovo Thinkpad X-seri…

Lenovo lists the X260 as vulnerable to CVE-2017-5689 [0], implying it supports AMT. My X240 definitely has AMT, it would be a bit odd for them to remove it in later generations. [0] https://support.lenovo.com/us/en/product_security/LEN-14963

[deleted]

Re: Intel AMT Checker for Linux

#70
post #56

Why would Intel insist on being so secretive about their management engine? Is it some kind of competitive advantage for them? Supposedly, it's useful for management tasks in enterprise environments, but if I were CIO, I think I would ban VPro chips. Who wants ring -3 processes running on their network for which they have no information about?

The ME isn't much more secret than, say, the memory controller.

The memory controller isn't running a web server that is accessible to anybody on the LAN.
Post reply on HN