Live data from Hacker News

Intel AMT Checker for Linux

github.com

71–80 of 93 posts

Re: Intel AMT Checker for Linux

#71
I want to be able to bios disable Intel AMT and AMDs variant of it. This is another bad attack vector. Further i want a simpler boot loader UEFI is bloatware and bad for security as its easy to hide things in those huge prorietary binary blobs.

Re: Intel AMT Checker for Linux

#72

Why would Intel insist on being so secretive about their management engine? Is it some kind of competitive advantage for them? Supposedly, it's useful for management tasks in enterprise environments, but if I were CIO, I think I would ban VPro chips. Who wants ring -3 processes running on their network for which they have no information about?

> Why would Intel insist on being so secretive about their management engine? It includes DRM (Protected Audio/Video Path), for one.

Documenting it shouldn't alter its effectiveness. I can tell you how AES works and that doesn't compromise anything.

Re: Intel AMT Checker for Linux

#73

Earlier quoted context omitted.

> Why would Intel insist on being so secretive about their management engine? It includes DRM (Protected Audio/Video Path), for one.

Documenting it shouldn't alter its effectiveness. I can tell you how AES works and that doesn't compromise anything.

I agree with you. But Intel would have to convince skeptical Hollywood executives of that, who are more inclined to just not let PCs have new content at all, since relatively few people consume TV and movies on PCs to begin with.

Personally, I think the right solution is to not have DRM for music, TV, and movies on PCs, purely for business reasons. What's happening today is that Intel is effectively shipping everyone who buys an x86 CPU a content decryption module, burning goodwill among free software advocates even though fewer than 1% of consumers will ever use the functionality (actually, does anyone use it?) It makes more business sense for consumers to just buy set-top boxes to consume content. It's not like anyone who buys a $450 Core i7 is going to balk at paying $35 for a Chromecast.

Re: Intel AMT Checker for Linux

#76
post #62

I'm shocked to say that the Thinkpad x260 does not have AMT at all. Shocked not because I think it's a huge conspiracy to control your computer but because I honestly do believe AMT was made with the best intentions of providing a level of theft mitigation for devices. Just like "Find my Mac" from Apple that seems to get very little flack. I'd be surprised if this meant that my pretty expensive Lenovo Thinkpad X-seri…

Lenovo lists the X260 as vulnerable to CVE-2017-5689 [0], implying it supports AMT. My X240 definitely has AMT, it would be a bit odd for them to remove it in later generations. [0] https://support.lenovo.com/us/en/product_security/LEN-14963

My X230 does as well.

Re: Intel AMT Checker for Linux

#77
post #8

Earlier quoted context omitted.

Thanks! Missed this part. Also, do you think it's a good idea to keep it in this state as opposed to updating in case Intel's new patches lock AMT down even further? This is the pattern I saw with Sony once - groups of users not updating their consoles because via exploiting it they could get more control over it.

You should be able to disable it in the BIOS. If you're not going to use it, I'd suggest disabling it. You could always reenable it later, should you find a need for it.

I disabled it in bios on my Lenovo T450s back when this was first reported and the tool reports...

Intel AMT is present AMT is unprovisioned

So disabling it puts it in the same state.

Re: Intel AMT Checker for Linux

#78

Earlier quoted context omitted.

> Why would Intel insist on being so secretive about their management engine? It includes DRM (Protected Audio/Video Path), for one.

Documenting it shouldn't alter its effectiveness. I can tell you how AES works and that doesn't compromise anything.

If you tell me how AES works and also give me the key you're using, then you're compromised. DRM relies on giving consumers the decryption key but making it hard for them to figure out how the system works (and sometimes making it hard to isolate the decryption key you've delivered to them).

Re: Intel AMT Checker for Linux

#79

Earlier quoted context omitted.

> Why would Intel insist on being so secretive about their management engine? It includes DRM (Protected Audio/Video Path), for one.

Documenting it shouldn't alter its effectiveness. I can tell you how AES works and that doesn't compromise anything.

That's because encryption is based on sound mathematical principles.

DRM is based on "physical access is not complete access", which is different.

Re: Intel AMT Checker for Linux

#80
post #26

God #$%@ing damn it, this is why we can't have nice things. You can do only so much to not get pwned software wise, now you need to be paranoid about the hardware too?! Going through all Xeon servers is going to be fun tomorrow.

I am tempted to go back to dialup style connectivity. Meaning i disconnect the router from the net unless i absolutely need something online.

You absolutely need security updates, or your system will be out of date and extra-vulnerable as soon as you plug it in.
Post reply on HN