Earlier quoted context omitted.
I'm running Windows and I just disabled the service. There are a couple of them, one is Local Management Service and the other is User Notification Service.
ME is a separate chip running alongside main CPU. You can't disable it via Windows services :) I recommend Platform Embedded Security Technology Revealed book [0] from designers and creators of ME for further information. [0]: https://link.springer.com/book/10.1007/978-1-4302-6572-6
Intel platforms from 2008 onwards have a remotely exploitable security hole
91–100 of 190 posts
Re: Intel platforms from 2008 onwards have a remotely exploitable security hole
#92Re: Intel platforms from 2008 onwards have a remotely exploitable security hole
#93Zero details and zero cross references, zero mentions on Google and zero mentions in any security list I'm on. Charlie blowing nonsensical steam yet again?
The article implies that they have been privately trying to get Intel to fix it, so there is no reason it would have been mentioned publicly anywhere. Now a patch is coming out but Intel is still trying to keep it quiet, so he's trying to warn people disable AMT and be ready to apply patches ASAP. Presumably he didn't even want to disclose the existence of the vulnerability publicly until there was some sort of fix,…
I'd guess this would be a lot of interest for "hacker" news; i want to sign my own damn firmware.
Re: Intel platforms from 2008 onwards have a remotely exploitable security hole
#94Is there a better source for this than SemiAccurate? The article doesn't really have much beyond self-aggrandizement and "we can't tell you any details, but you're screwed". For something that could be anything from "Charlie Demerjian heard a rumor about a ME patch and wanted some pageviews" to the actual security apocalypse, I'd like credible sources.
Re: Intel platforms from 2008 onwards have a remotely exploitable security hole
#95Earlier quoted context omitted.
There's eventually going to be one when it is officially published by Intel, but that seems to be months away right now.
No, that's not how sources work. You don't get to use your assumption that the article is accurate to assert that it will eventually be proven accurate by other sources. That's circular reasoning.
Re: Intel platforms from 2008 onwards have a remotely exploitable security hole
#96Earlier quoted context omitted.
The functionality ME attempts to provide is lights out a.k.a. out-of-band management (like IPMI) to the desktop. If, for example, an admin needed to add a dual-boot-to-Ubuntu option to every PC on a floor, he could, through ME, remotely reboot (force power reset if necessary) or power on every machine, have the machines boot to a (remote) OS install disk, run the install, and reboot. ME allows one to do almost anythi…
Can't all that be done from the main OS? Repartition, modify the boot stuff, reboot from an image in a new partition, etc... Why did they need to add another processor with closed source and all the potential security issues?
Re: Intel platforms from 2008 onwards have a remotely exploitable security hole
#97Is there a better source for this than SemiAccurate? The article doesn't really have much beyond self-aggrandizement and "we can't tell you any details, but you're screwed". For something that could be anything from "Charlie Demerjian heard a rumor about a ME patch and wanted some pageviews" to the actual security apocalypse, I'd like credible sources.
Yes. There is A better source: http://invisiblethingslab.com/resources/bh09dc/Attacking%20I...
Re: Intel platforms from 2008 onwards have a remotely exploitable security hole
#98What is the motivation behind Management Engine? From the perspective of an everyday user these things came out of nowhere to evolve into this para-computer running along side me that I cannot see and have no control of. It is on literally ALL hardware Why is it that any attempts to disable it knock your whole computer out? And this is the world of technology that we want? I'm so sick of technology companies appearin…
I think the problem is not that this technology exists but rather that the operation of this engine is not transparent, the user cannot examine or disable the software in this engine, cannot write his own software.
I really don't understand why the would just shove it into every chipset out there. I understand it needs to get its claws all over the system, but the core should be external and optional.