6 ms·
Is there a better source for this than SemiAccurate? The article doesn't really have much beyond self-aggrandizement and "we can't tell you any details, but yo
by tomku 9y ago
Is there a better source for this than SemiAccurate? The article doesn't really have much beyond self-aggrandizement and "we can't tell you any details, but you're screwed". For something that could be anything from "Charlie Demerjian heard a rumor about a ME patch and wanted some pageviews" to the actual security apocalypse, I'd like credible sources.
- na85 9y agoCredibility issues of the author/website aside, I actually hope this is true, and I hope it's catastrophic for Intel. Maybe then we'll finally see hardware companies taking security seriously.
- finnn 9y agoI'm worried that it's true and it's not catastrophic for Intel. Aka show to the world that you can get away with BS like this.
- freehunter 9y agoThe fact that people can stay behind platforms, companies, and technologies that are proven to be so inherently insecure that they can never be trusted just boggles my mind. Adobe Flash has a new zero-day every week, but we were saddled with it for years past when it should have been retired because some people didn't want HTML5 to have feature-parity with Flash. Java has a new zero-day every week but we're stuck with it because enterprises are afraid of trying something new. Windows was wide open to attacks for years, but they got away with it by saying "yeah but Apple is so expensive" and people still parrot that. They said "yeah but Linux is stolen technology/doesn't work right" and people still parrot that. Android has a new malware/exploit warning every week, the majority of the phones never see security updates, and are running outdated software the minute they're shipped to stores but people say "yeah but Apple is so expensive/locked down" or "Windows Phone doesn't have any apps". I have friends who lost their credit card numbers at Home Depot but refuse to shop at Lowes because they don't like the NASCAR driver that Lowes sponsors. People get so caught up in brand loyalty that they're willing to defend "their" company like it's a family member. Even among the tech community, security means nothing. We still use Android phones to get root access, we still use Windows to save some money on our laptops, we still program in PHP because it pays the bills. Nothing will ever be catastrophic enough. Anyone can get away with it just by creating an "us vs them" mentality with their customers.
- tormeh 9y ago>Java has a new zero-day every week but we're stuck with it Well, Java applets did die. What more do you want? The Java sandbox is only used by extremely legacy software at this point, so it doesn't matter if it has holes in it. Actually, the more holes the better, so we can get rid of the last holdouts.
- umanwizard 9y agoJava is the most widely-used programming language in the world. Applets are an insignificantly tiny drop in the bucket of what Java is used for.
- deleted 9y ago[deleted]
- alasdair_ 9y agoJava is consistently listed in the top three (and often #1) languages in current use.
- mike_hearn 9y agoJava has a new zero-day every week No it doesn't. The last one was in 2015. Before that I think there was a two year gap to the prior one. Zero days in Java are actually very rare these days. That doesn't mean bugs are rare - like any large piece of software Java gets regular security patches, but those are flaws found by the developers themselves rather than attackers, so they aren't zero days.
- freehunter 9y agoI think it's implied that "a new X every week" is always going to be hyperbole. I'm intentionally overstating the point so someone just like you could hop in and prove it better than I ever could. Remember in 2012 when Apple stopped shipping Java with their browser because it was so insecure?
- thraway2016 9y agoIME is likely not a case of Intel "not taking security seriously". It's almost certainly a case of doing what FiveEyes demanded of them.
- na85 9y agoYou're probably right. I still hope it's true, and that it's catastrophic for Intel. No change can happen otherwise. If Intel aren't fighting against 5eyes then they aren't taking security seriously.
- nyolfen 9y agothis was my first thought as well, but surely there would have been some hint of it in snowden docs or the recent wikileaks cia malware docs?
- mediocrejoker 9y agoI'm not familiar with the author. Can you elaborate on the credibility issues?
- wmf 9y agoCharlie Demerjian is a massive hater. That doesn't mean he's wrong, but everything he writes about Intel or Nvidia has a negative slant.
- Natanael_L 9y agoThere's eventually going to be one when it is officially published by Intel, but that seems to be months away right now.
- tomku 9y agoNo, that's not how sources work. You don't get to use your assumption that the article is accurate to assert that it will eventually be proven accurate by other sources. That's circular reasoning.
- walterbell 9y agoIf the article's claims are true, all sources (e.g. OEMs with access to a fix) should be under NDA, https://twitter.com/cdemerjian/status/859096565033693185 https://twitter.com/cdemerjian/status/859096565033693185
- tomku 9y ago...and if the article's claims aren't true, there wouldn't be any sources to confirm the claims at all. The evidence we've been presented with so far (no sources) is consistent with both possibilities. When you make a claim as big as SemiAccurate did, it's on you to provide sources to back it up. If you can't present any kind of proof, you don't have a story, you have a rumor.
- walterbell 9y agoThe article claimed: > That is the end of June for non-Intelspeak people, they will officially issue this guidance then along with OEM disclosures. We'll know in two months whether the above claim is true or false.
- tomku 9y agoMy prediction: At the end of June, Intel announces a fix for a minor non-RCE bug in the LAN code of Intel ME. SemiAccurate proudly and inaccurately announces that it confirms their previous reporting and adds it to the list of things to mention every time they write an article about Intel. There is no follow-up Hacker News thread with 100+ comments, so most of the people who posted here continue thinking that there was a major RCE in Intel ME that we just haven't heard about because it was covered up. Edit: Already proven wrong! We're headed for interesting times.
- davidgerard 9y agoIs there a better source for this comment than "I don't like Charlie Demerjian"?
- codedokode 9y agoIf Intel released a firmware update, then anyone can compare this update to a previous version and see what has changed.
- tomku 9y agoThat's harder in practice than you make it sound. Firmware updates for Intel ME are handled through OEMs, it's not a file that Intel publishes that an interested person can go to their website and download. The article claims that such a patch has been released to OEMs but is being kept under wraps, which might make it hard to determine when it actually ships in a downstream update. Even if you have a file that you know contains the binary blob of updated firmware, reverse-engineering it to determine what it does differently compared to the previous version is very much non-trivial.
- Zuider 9y agoCPU firmware patches have also been released through Microsoft update, and Windows computers may well be patched on the fly in this way. I suppose it would be possible to download the update individually and examine its contents, but, as you point out, it would be extremely difficult to work out what it was doing.
- Jan_jw 9y agoYes. There is A better source: http://invisiblethingslab.com/resources/bh09dc/Attacking%20Intel%20TXT%20-%20paper.pdf http://invisiblethingslab.com/resources/bh09dc/Attacking%20I...
- milcron 9y agoWhat is the publication date of this?
- ripdog 9y ago>The details of our new SMM attacks will be made available once Intel patches its firmware, most likely we will present them at the Black Hat USA conference in summer 2009. We will also make the code of our TXT exploit available.
- Natanael_L 9y agoInitial confirmation below, I haven't read it through in full yet. I believe technical details are being delayed; https://security-center.intel.com/advisory.aspx?intelid=INTEL-SA-00075&languageid=en-fr https://security-center.intel.com/advisory.aspx?intelid=INTE...
- tomku 9y agoThat is not a source that confirms SemiAccurate's claims, it's a nearly decade-old paper (~2008-2009) describing an attack against a completely different security feature. The "System Management Mode" described and attacked in the paper is unrelated to Intel ME.
- milcron 9y agoHow about The Register? https://www.theregister.co.uk/2017/05/01/intel_amt_me_vulnerability/ https://www.theregister.co.uk/2017/05/01/intel_amt_me_vulner... There's also an Intel advisory https://security-center.intel.com/advisory.aspx?intelid=INTEL-SA-00075&languageid=en-fr https://security-center.intel.com/advisory.aspx?intelid=INTE...
- tomku 9y agoI'm glad that credible sources are now available. It's unfortunate that it took so long to confirm, but congrats to SemiAccurate on a massive scoop. Edit: On the previously-mentioned scale, this sounds like a solid 8 or 9 out of 10.
- mirimir 9y agoFrom the Intel advisory: > There is an escalation of privilege vulnerability in Intel® Active Management Technology (AMT), Intel® Standard Manageability (ISM), and Intel® Small Business Technology versions firmware versions 6.x, 7.x, 8.x 9.x, 10.x, 11.0, 11.5, and 11.6 that can allow an unprivileged attacker to gain control of the manageability features provided by these products. This vulnerability does not exist on Intel-based consumer PCs. If in doubt, you can check your CPUs here: https://ark.intel.com/#@Processors https://ark.intel.com/#@Processors
- deleted 9y ago[deleted]