Live data from Hacker News

Intel platforms from 2008 onwards have a remotely exploitable security hole

semiaccurate.com

71–80 of 190 posts

Re: Intel platforms from 2008 onwards have a remotely exploitable security hole

#71

The short version is that every Intel platform with AMT, ISM, and SBT from Nehalem in 2008 to Kaby Lake in 2017 has a remotely exploitable security hole in the ME (Management Engine) not CPU firmware. We knew this would happen. We knew that the Management Engine was a backdoor, and we knew it was only a matter of time before someone would figure out how to exploit it. This is exactly the reason why Libreboot exists (…

Let's hope one of the other CPU manufacturers (e.g. AMD) starts supporting LibreBoot and allows to officially disable the ME-equivalent hardware feature, so that Intel get's forced by market-pressur to follow.

Intel needs more competition - thanks to AMD latest new 8-core CPU Intel got forced to release a new CPU the had in their basement for years - suddently it's possible for them to release i7 notebook CPUs with more then two cores!! Even back in 2010 it would have been viable to produce 4 core notebook CPUs - but the went away because the had no competition.

Re: Intel platforms from 2008 onwards have a remotely exploitable security hole

#72
post #9

Is there a better source for this than SemiAccurate? The article doesn't really have much beyond self-aggrandizement and "we can't tell you any details, but you're screwed". For something that could be anything from "Charlie Demerjian heard a rumor about a ME patch and wanted some pageviews" to the actual security apocalypse, I'd like credible sources.

Is there a better source for this comment than "I don't like Charlie Demerjian"?

Re: Intel platforms from 2008 onwards have a remotely exploitable security hole

#73
post #48

> For obvious reasons we couldn’t publish what we found It's not obvious to me why anyone not under an NSL or NDA would sit on this vulnerability for 5 years and wait until it's actively being exploited in the wild before public disclosure. It's extremely negligent to global security for SemiAccurate to not immediately publicly disclose the vulnerability 5 years ago after Intel refused to fix it. Of course this is ig…

That seems strange. Since it's a security hole you can exploit on your very own Intel computer, there's no issue about "hacking" into someone else's system. Researching this is legally safe. There should have been a Defcon talk and a CERT advisory years ago.

Re: Intel platforms from 2008 onwards have a remotely exploitable security hole

#74
post #2

>>every Intel platform with AMT, ISM, and SBT from Nehalem in 2008 to Kaby Lake in 2017 has a remotely exploitable security hole in the ME (Management Engine) not CPU firmware. >>there is literally no Intel box made in the last 9+ years that isn’t at risk >>SemiAccurate has been begging Intel to fix this issue for literally years Am I the only one who is so cynical to think it must have been deliberate? Intel draggin…

Believe incompetence before malice, and I'd stick economic incentives somewhere in the middle.

The discussion probably went something like:

Person 1: "Should we issue a recall and disable a feature which bought us a several billion dollar customer?"

Person 2: ...

Re: Intel platforms from 2008 onwards have a remotely exploitable security hole

#75
post #34

Earlier quoted context omitted.

I'm worried that it's true and it's not catastrophic for Intel. Aka show to the world that you can get away with BS like this.

The fact that people can stay behind platforms, companies, and technologies that are proven to be so inherently insecure that they can never be trusted just boggles my mind. Adobe Flash has a new zero-day every week, but we were saddled with it for years past when it should have been retired because some people didn't want HTML5 to have feature-parity with Flash. Java has a new zero-day every week but we're stuck wit…

Java has a new zero-day every week

No it doesn't. The last one was in 2015. Before that I think there was a two year gap to the prior one. Zero days in Java are actually very rare these days.

That doesn't mean bugs are rare - like any large piece of software Java gets regular security patches, but those are flaws found by the developers themselves rather than attackers, so they aren't zero days.

Re: Intel platforms from 2008 onwards have a remotely exploitable security hole

#76

I've always wondering why nobody seems to notice the fact that this site is literally called "Semi Accurate". I mean sure, everyone makes mistake and even the most credible news sources are not entirely accurate all the time. But what am I to think when your organization is literally named after being only half truthful?

It's a semiconductor news site.

Re: Intel platforms from 2008 onwards have a remotely exploitable security hole

#77
post #9

Is there a better source for this than SemiAccurate? The article doesn't really have much beyond self-aggrandizement and "we can't tell you any details, but you're screwed". For something that could be anything from "Charlie Demerjian heard a rumor about a ME patch and wanted some pageviews" to the actual security apocalypse, I'd like credible sources.

If Intel released a firmware update, then anyone can compare this update to a previous version and see what has changed.

Re: Intel platforms from 2008 onwards have a remotely exploitable security hole

#78
post #34

Earlier quoted context omitted.

I'm worried that it's true and it's not catastrophic for Intel. Aka show to the world that you can get away with BS like this.

The fact that people can stay behind platforms, companies, and technologies that are proven to be so inherently insecure that they can never be trusted just boggles my mind. Adobe Flash has a new zero-day every week, but we were saddled with it for years past when it should have been retired because some people didn't want HTML5 to have feature-parity with Flash. Java has a new zero-day every week but we're stuck wit…

>> People get so caught up in brand loyalty that they're willing to defend "their" company like it's a family member.

Long ago I read something about that. The psych came down to the (false) idea that changing brand would confirm that you were wrong. The example was that even if Ford made better cars back in the day so you're a diehard Ford owner, if they quality demonstrably falls behind and Chevy is demonstrably awesome today you still won't change! And that's a case where your prior decision was actually right. So people have these weird internal notions that 1) companies value doesn't change over time, 2) their value doesn't change in light of new evidence, and 3) My own value is somehow tied to making a "correct" decision in spite of cognitive errors #1 and #2.

People are stubborn, and that's being kind about it.

Re: Intel platforms from 2008 onwards have a remotely exploitable security hole

#79
post #32
post #9

Is there a better source for this than SemiAccurate? The article doesn't really have much beyond self-aggrandizement and "we can't tell you any details, but you're screwed". For something that could be anything from "Charlie Demerjian heard a rumor about a ME patch and wanted some pageviews" to the actual security apocalypse, I'd like credible sources.

Credibility issues of the author/website aside, I actually hope this is true, and I hope it's catastrophic for Intel. Maybe then we'll finally see hardware companies taking security seriously.

I'm not familiar with the author. Can you elaborate on the credibility issues?

Re: Intel platforms from 2008 onwards have a remotely exploitable security hole

#80
post #71

The short version is that every Intel platform with AMT, ISM, and SBT from Nehalem in 2008 to Kaby Lake in 2017 has a remotely exploitable security hole in the ME (Management Engine) not CPU firmware. We knew this would happen. We knew that the Management Engine was a backdoor, and we knew it was only a matter of time before someone would figure out how to exploit it. This is exactly the reason why Libreboot exists (…

Let's hope one of the other CPU manufacturers (e.g. AMD) starts supporting LibreBoot and allows to officially disable the ME-equivalent hardware feature, so that Intel get's forced by market-pressur to follow. Intel needs more competition - thanks to AMD latest new 8-core CPU Intel got forced to release a new CPU the had in their basement for years - suddently it's possible for them to release i7 notebook CPUs with m…

> suddently it's possible for them to release i7 notebook CPUs with more then two cores

I'm not sure what you mean by this. My Dell XPS 15 has a i7-6700HQ which is quad core, and it's not like I just bought the thing.

Post reply on HN