4 ms·
Has Intel ever commented about this issue of removing ME? Surely, at least 1 Intel staffer reads HN and they must have discussed this internally. Unless they
by phantom_oracle 10y ago
Has Intel ever commented about this issue of removing ME?
Surely, at least 1 Intel staffer reads HN and they must have discussed this internally.
Unless they just brush this off as negligible (a couple thousand paranoid/"extremist" users) ?
- wmf 10y agoTheir discussion may have consisted of "too bad these extremists don't realize that the ME is harmless if you don't have an Intel NIC".
- devereaux 10y agoThere is a device visible on the PCI bus. How hard is it to imagine that userland programs could somehow pass requests to that device, and have the ME do bad things to the CPU or the RAM? How hard is it to imagine some special string in RAM could trigger the ME in a similar way? (so many CPU instructions - I would be surprised if there wasn't one to talk to the ME) Exploits and vulnerability are mitigated by proper analysis and ecological diversity. Here we have an attack channel present of every single Intel based computer, regardless of the CPU. Call me an extremist if you want, but this is far from harmless.
- tedunangst 10y agoIf userland processes are passing unauthorized commands to PCI devices, you have bigger problems.
- ackalker 10y agoThey're called proprietary video drivers, and yes, they pass unknown commands, without user authorization (think DRM) to PCI(e) devices (video cards) all the time.
- lallysingh 10y agoIf you're running highly privileged binary blob drivers, is ME really the attack vector you should be worried about?
- jtl999 10y agoHow does a userland process communicate with a PCI device? Asking for a project.
- kuschku 10y agoSo that’s why my Intel NIC never really worked well, and two devices showed up in my router as connected?
- tonylemesmer 10y agoDoes that mean if you have a secondary network card the risk goes away? (genuine question).
- wmf 10y agoIt depends how paranoid you are. AMT/vPro requires an Intel NIC but in theory NSA firmware could talk to any device.
- userbinator 10y agoI have a feeling Intel is more likely going to consider this a "vulnerability" and try to close it off in the next revision... Anyone who works there, has access to the required information, and is unhappy at the situation surrounding ME and other freedom-hostile directions your company is taking, you know what to do!