10 ms·
You can disable the remote management and the entire embedded network stack though.
by eeZi 10y ago
You can disable the remote management and the entire embedded network stack though.
- ZenoArrow 10y agoThat's not so easy to do. To get a sense of what's required... https://software.intel.com/en-us/forums/intel-business-client-software-development/topic/563988 https://software.intel.com/en-us/forums/intel-business-clien... Plus, even you disable it there's still room for exploits, previous versions of Intel AMT have had exploits. Check out the 'Known vulnerabilities and exploits' section of the Intel AMT Wikipedia page: https://en.m.wikipedia.org/wiki/Intel_Active_Management_Technology https://en.m.wikipedia.org/wiki/Intel_Active_Management_Tech...
- luma 10y agoEnabling it isn't generally easier either, and it can be secured with certificates on both side. Every time this topic is brought up I'm surprised by the number of people who think remote access is bad and cannot possibly be secured, while not actually digging into what it would take to compromise such a machine. Maybe it's the server admin in me, but OOB BIOS-level remote access and management for my systems is a godsend and my biggest issue with it is that they tend not to include those features in their "enthusiast" chipsets.
- ZenoArrow 10y agoThe features are included in all modern Intel CPUs AFAIK, if you found one where it wasn't included please let me know as its absence would be a feature for me. As for the number of people who think remote access is bad, nobody seems to be denying it can be useful, but by baking it into hardware you're basically hoping that it doesn't get hacked. If it was an optional dongle nobody would care.
- deleted 10y ago[deleted]
- stakent 10y agoExactly. Optional, hardware mediated remote access is good.
- luma 10y agoThe remote access part is called AMT[1] and is part of the Intel vPro[2] feature set. It most certainly is not enabled in all modern Intel processors. Further, it requires a compatible processor, chipset, and BIOS for it to be enabled. There is a common misunderstanding in these discussions that the ME features of the Intel processor (included in nearly all modern procs) allows for hardware level remote access, which isn't true. [1] https://en.wikipedia.org/wiki/Intel_Active_Management_Technology https://en.wikipedia.org/wiki/Intel_Active_Management_Techno... [2] https://en.wikipedia.org/wiki/Intel_vPro https://en.wikipedia.org/wiki/Intel_vPro
- dlmetcalf 10y agoYeah, right. I suppose we're just supposed to take their word for that. There's an enormous difference between the concepts of trusted and trustworthy. You're extremely naive or clearly never read anything Snowden released if you think 'trust us' is enough.
- luma 10y agoAre you suggesting Intel has implemented hidden backdoors into all of their systems?
- livus 10y agoNot OP but it could be very much possible and that's what OP is trying to say. Just taking it on Intel's word that they haven't done it is not the correct way to go. For the truly privacy minded, it's better to err on the side of caution.
- luma 10y agoErr on the side of caution in this sense would mean fabricating your own proc. Are you going to do that?
- colejohnson66 10y ago
- scrupulusalbion 10y agoTL;DR: Build yourself a desktop with a non-vPro CPU and a non-Intel NIC. Check [0] for a list of such CPUs. The usual recommendation is to either get a pre-2009 AMD machine (which is what my present desktop is) or get a Sparc machine. My boss won't buy me a desktop with an UltraSparc CPU, so I won't bother with that. AMD has substantially less documentation than Intel, AFAICT, so Intel products deserve investigation for their relative starkness. An albeit outdate list of systems to avoid, see [1]. I will assume that you are trying to build a desktop from off-the-shelf parts. For sure, get a CPU without vPro, since that downgrades the type of AMT/IME feature set to Standard Manageability: "Please note that NON -vPro™ Intel® desktop procesors will make Intel® ME FW to switch its features set from full Intel® Active Management Technology to Intel® Standard Manageability that do not suport Intel® AMT KVM Redirection feature (it is disabled internally in the Intel® ME FW)." [2] When the CPU doesn't support AMT, then Standard Manageability is what is running in the background. This says 2 things: (1) non-vPro desktop CPUs downgrade AMT to Standard Manageability and (2) IME is active regardless of the CPU's feature set. What is Intel Standard Manageability? "Q8: What is Intel® Standard Manageability and can it run on a non-Intel® vPro™ technology-based CPU? A8: Some basic management capabilities are available on non-Intel® vPro™ technology-eligible Intel® Core™2 processors as well as Intel® Pentium® dual-core and Intel® Celeron® processor-based CPUs. Intel® Standard Manageability is available only on desktop systems right now (not notebook), and only includes basic capabilities such as hardware and software inventory and remote diagnostics." [3] I can't tell if Standard Manageability is a lite version of AMT. Intel's documentation on it [4] isn't a whole lot of help. Intel mentions that Atom and i3 platforms generally do not support AMT. [5] At the bottom of this [6] page lists those Intel chipsets with IME. I'd consider that to be a list of chipsets to avoid, but those cover almost all modern chipsets, AFAIK. For sure, don't use any Intel NICs: "Adding another NIC will not nullify Intel® vPro™ technology verification, but Intel® Active Management Technology communicates only through the onboard network interface of Intel vPro technology, and it is strongly recommended that an additional wired NIC is not added to the platform as this might cause some of the features of Intel AMT to not operate as expected." [7] [0] = http://ark.intel.com/search/advanced?s=t&VProTechnology=false http://ark.intel.com/search/advanced?s=t&VProTechnology=fals... [1] = https://communities.intel.com/docs/DOC-2033 https://communities.intel.com/docs/DOC-2033 [2] = https://communities.intel.com/thread/65350 https://communities.intel.com/thread/65350 [3] = https://software.intel.com/en-us/articles/intel-vpro-technology-faq https://software.intel.com/en-us/articles/intel-vpro-technol... [4] = https://software.intel.com/en-us/blogs/2009/03/27/what-is-standard-manageability https://software.intel.com/en-us/blogs/2009/03/27/what-is-st... [5] = http://www.intel.com/content/dam/www/public/us/en/include/retail-client-manager-help/Technical_Notes/Remote_control/tech-remote.html http://www.intel.com/content/dam/www/public/us/en/include/re... [6] = https://www.kernel.org/doc/Documentation/misc-devices/mei/mei.txt https://www.kernel.org/doc/Documentation/misc-devices/mei/me... [7] = https://software.intel.com/en-us/articles/intel-vpro-technology-faq https://software.intel.com/en-us/articles/intel-vpro-technol...
- stakent 10y agoCan you enumerate "enthusiast" chipsets? I'd like to know what chipset to choose in the future. Thanks.
- Tiksi 10y agoYeah, I find it difficult to understand the hoopla around IME. It's not much different from the BMC that's on pretty much all server hardware.
- dlmetcalf 10y agoLet me make this totally clear. The top OEM hardware manufacturers couldn't give a CRAP about your security. https://duo.com/blog/out-of-box-exploitation-a-security-analysis-of-oem-updaters https://duo.com/blog/out-of-box-exploitation-a-security-anal... e.g. http://teletext.zaibatsutel.net/post/145370716258/deadupdate-or-how-i-learned-to-stop-worrying-and http://teletext.zaibatsutel.net/post/145370716258/deadupdate... But you're totally fine that THESE are the people with unfetted power to fill your system with backdoors? (Not to mention NSA etc who'd almost certainly have access). What's wrong with you having zero care about the world's data security?
- Tiksi 10y agoIt's not so much that I don't care, more that it's nothing new. I just don't understand why people are suddenly railing against IME instead of Dell, SuperMicro, HP, etc when there is far more hardware out there with far, far less secure BMCs and it's been that way for ages. IME is probably closer to the best of the bunch as far as security goes.
- dlmetcalf 10y agoIME is horrible and we should be railing against all horrible implementations. I can assure you I let my OEM know full well how I felt about insecure automatic update software (even though I wipe the system as soon as I get it, something I can't do with ME). I'll be taking my next purchase elsewhere. Unless people speak up, it's guaranteed to only gets worse.
- Tiksi 10y agoI think we're talking about two different things. BMCs run separately from the rest of the system and are active even when the machine is halted. They provide remote mouse/keyboard/monitor, power control, remote device mounting, bios settings, hardware sensors and monitoring, etc. These have been in servers for ages, do the same thing as IME, and are way less secure. None of it has any relevance to software updaters or software at all really since a lot of these boxes are shipped without an OS or even hard drives.
- Vendan 10y agoThe security expert in me is terrified at the concept of remote access that, far too often, isn't actually managed very well. I've been to far too many places that have management interfaces like this and either don't know it, or don't apply updates. It's not that remote access is bad, it's that all the remote access I've seen has been horrible. Hash disclosure is just seen as "meh, that's the way it is", and being able to login without a password is standard unless the IT has taken the time to update something they often don't even know about.