Live data from Hacker News

An in-depth security review of the Intel Management Engine

security-center.intel.com

71–80 of 192 posts

Re: An in-depth security review of the Intel Management Engine

#71
post #50

Does "attacker with local access to the system" mean "physical access to the system"?? Initially I thought it meant "attacker able to run an unprivileged process on the system" but then I see other wording that seems to imply that case, so does "local access" mean physical access? (e.g. connect a USB drive, boot the box off their own media?)

The examples I've heard about are plugging a usb drive in and that's the ballgame. The big one, that I have not heard of, would be accessing the ME and privilege elevation over network.

It would be a little more interesting if a "virtual USB drive" (similar to a virtual floppy/CD-ROM drive) in remote consoles (BMC/iDRAC/ILO/IPMI/etc.) could be used to exploit it.

Re: An in-depth security review of the Intel Management Engine

#72
post #43
post #8

Wow all 6th, 7th and 8th gen are all vulnerable along with a bunch of Xeon processors. Even the laptop I am typing this on is vulnerable, this is going to be messy. Plus all the fun vulnerabilities like arbitrary code execution, unauthorized access to privileged content. These must be related to the blackhat talk coming up in December about hacking a turned-off computer and running unsigned code on ME [0]. Yep and th…

blackhat =/= defcon

sorry, fixed

Re: An in-depth security review of the Intel Management Engine

#73
post #36

Earlier quoted context omitted.

It is nice to know lenovo already has the updates, but sadly I'm gonna have to install windows for that :(

Go for the "bootable CD" option, if it's available. You don't need Windows for that. My ThinkPads all run Linux and I have no problems updating them.

Thanks, I'm gonna look into that!

Re: An in-depth security review of the Intel Management Engine

#74

Earlier quoted context omitted.

> I wonder if this will at all dissuade either Intel or AMD into continuing to make these super privileged processors whose functions are completely hidden. I think many discussions miss the nuance here. The problem is that the functionality is hidden, not necessarily that the function is there. In corporate use, these tools can be incredibly useful. If they were more transparent, then they could be used by normal us…

I agree with your overall conclusions, but I am having a hard time imagining the 'normal users' who would use remote administration... though perhaps if that were normal-for-HN users...

I guess I'm "Normal-for-HN". IPMI is so useful that I wouldn't buy a server without it, even one I'm going to use in the same building.

Re: An in-depth security review of the Intel Management Engine

#75
post #36

Earlier quoted context omitted.

It is nice to know lenovo already has the updates, but sadly I'm gonna have to install windows for that :(

Go for the "bootable CD" option, if it's available. You don't need Windows for that. My ThinkPads all run Linux and I have no problems updating them.

Unfortunately I couldn't find the bootable cd version for the intel management engine firmware and software updates. Mine is a thinkpad t460s.

Re: An in-depth security review of the Intel Management Engine

#76

Unreal. Kept scrolling and the vulnerabilities kept coming. Most annoying thing is that there isn’t even a real alternative. If I understand it right then AMD chips have pretty much the same thing?

My alternative is a Librem:

https://puri.sm/posts/purism-librem-laptops-completely-disab...

Re: An in-depth security review of the Intel Management Engine

#77
post #36

I prefer the wording in Lenovo's security advisory [0]: > "Potential Impact: An attacker could load and execute arbitrary code outside the visibility of the user, operating system, and hypervisor/virtualization platform; resulting in exfiltration of secrets, subtle manipulation of system operation, or denial of service." [0]: https://support.lenovo.com/us/en/product_security/len-17297

It is nice to know lenovo already has the updates, but sadly I'm gonna have to install windows for that :(

Seriously. After they pulled that from the last ME vulnerability they lost me as a customer.

Re: An in-depth security review of the Intel Management Engine

#78
post #36

Earlier quoted context omitted.

It is nice to know lenovo already has the updates, but sadly I'm gonna have to install windows for that :(

Go for the "bootable CD" option, if it's available. You don't need Windows for that. My ThinkPads all run Linux and I have no problems updating them.

I think that's only for BIOS updates, not ME. ME uses an Intel provided flash EXE. It would probably run on PE or definitely Windows to Go though.

Re: An in-depth security review of the Intel Management Engine

#79
post #32
post #18

Earlier quoted context omitted.

Yep. "Let's put a chip in it" IoT nightmare now applies recursively to chips. Everything is insecure by design. I am really looking forward for either ARM to displace x64 or even better RISC-V. With ARM you have many more vendors so more chance for options, and RISC-V is the ultimate in openness.

Good luck getting a modern ARM SoC which doesn't depend on binary blobs.

i.MX6 is modern-ish and is bootable without blobs.

Re: An in-depth security review of the Intel Management Engine

#80

Earlier quoted context omitted.

> I wonder if this will at all dissuade either Intel or AMD into continuing to make these super privileged processors whose functions are completely hidden. I think many discussions miss the nuance here. The problem is that the functionality is hidden, not necessarily that the function is there. In corporate use, these tools can be incredibly useful. If they were more transparent, then they could be used by normal us…

I agree with your overall conclusions, but I am having a hard time imagining the 'normal users' who would use remote administration... though perhaps if that were normal-for-HN users...

If you have a hard time imagining normal users who would use this, then I suggest you grow your imagination and teach users what possibilities there are.
Post reply on HN