7 ms·
Disabling Intel AMT on Windows
- justinclift 9y agoSeems Windows specific? It'd be nice to have something that actually disables these additional Intel "management" chipsets, across all platforms.
- gaia 9y agoYes, windows only for now. The Linux guide is upcoming: https://twitter.com/IntelSupport/status/859437569368567811 https://twitter.com/IntelSupport/status/859437569368567811
- hd4 9y agoIs that because the exploit only affects Windows? I somehow doubt that but just wanted to be sure.
- gaia 9y agoYes, the exploit is only for Intel ME on Windows, AFAIK.
- throwaway2048 9y agoThis is not accurate
- beagle3 9y agoI'd be surprised if this actually disables all aspects of ME and AMT. Those things listen when the computer is off, and cause a CPU shutdown when deactivated unless you are work hard to subdue them (recent CCC had a presentation on what's needed).
- LinuxFreedom 9y agoPlease add some substance to your post. Thank you!
- zer0tonin 9y agohttps://blog.invisiblethings.org/papers/2015/x86_harmful.pdf https://blog.invisiblethings.org/papers/2015/x86_harmful.pdf
- gaia 9y agoYou can run netstat and see it is no longer listening. Now, how you would verify this when the computer is off is beyond me (assuming it is the case - I have not yet been able to go thru the PDF below)
- algesten 9y agoYou can use something like nmap to scan open ports from another machine. Nmap can both do host discovery (find IP addresses) as well as port scans. https://nmap.org https://nmap.org
- derefr 9y agoThe thing that was listening is just AMT. The ME consists of a much wider suite of behaviors. For example: there's an embedded-profile JVM for running Java Card smart-card software, allowing enterprises to deploy crypto auth firmware written for smart-cards directly to the device. This avoids the need to flash, deploy, and manage hardware smart cards, while also preventing the OS from being able to introspect said software's operation. (This particular feature almost sounds like a good thing, doesn't it? It's a programmable TPM!)
- lima 9y agoIn fact, AMT isn't listening in the operating system either but directly on the ME. What OP removed is probably some sort of OS-level agent that collects information about the system (installed software, patches, ...).
- deleted 9y ago[deleted]
- amluto 9y agoHmm, a programmable TPM / secure element running as a program on an undocumented OS that also runs a web server and is probably not hardened (and might not even have privilege separation or even an MMU for all I know) but nonetheless has superpowers over the main CPU. I'll stick with a hardware TPM, thank you very much. (Qualcomm's TrustZone kernel runs on a similarly limited but much better documented platform, does not run a web server, and has had a good share of vulnerabilities over the years. I see no reason to expect Intel's ME software stack to be any better.)
- derefr 9y agoI don't know; presumably organizations like the US military need some way of "hardening" Intel's chips after they receive them. This SCS tool could be how such organizations accomplish that.
- sambull 9y agoYea they say cut the AMT fuse.
- semi-extrinsic 9y agoSeeing as we know Amazon can get Intel to make custom Xeon chips specifically adapted for EC2 usage, I'm 100% certain Intel also makes custom chips for military/etc applications that have whatever functionality the customer does (doesn't) want enabled (disabled).
- Hydraulix989 9y agoThe closest thing I found that could work for Linux is flashing the BIOS manually: https://hackaday.com/2016/11/28/neutralizing-intels-management-engine/ https://hackaday.com/2016/11/28/neutralizing-intels-manageme... In the case of my Thinkpad, I had to open it up and flash the chip using the Raspberry Pi hardware over SPI bus. Then I found out that removing the Intel Management Engine breaks Hackintosh so I ended up having to put it back. Another alternative is flashing Coreboot/Libreboot, but this also breaks Hackintosh.
- lima 9y agoYou'll be happy to hear that this no longer works with newer devices thanks to Intel Boot Guard, which prevents firmware modifications altogether.
- orblivion 9y agoI have a Lenovo T440s. My BIOS has an "activate/deactivate/permanently deactivate" setting for AMT. I set it to "deactivate" for now. Any idea what this buys me? Their last BIOS update was March 14. I'm hoping their next one has the new firmware.
- gaia 9y agoDeactivation merely resets the AMT settings. You can only turn it off by following these instructions.
- orblivion 9y agoSo that means it's still exploitable over the network? (I thought it would cut it down to local-only). Lenovo is lying to me when it says "disable AMT"? Then again, maybe it's not actually enabled, since I didn't use the software to do so.
- gaia 9y agoThat is a good question. Lenovo's advisory (https://pcsupport.lenovo.com/us/en/product_security/ps500104 https://pcsupport.lenovo.com/us/en/product_security/ps500104) does not explicitly states which AMT status make it vulnerable, but given that Intel ME runs no matter what, I'd go for the disable guide.
- lima 9y agoThis only disables the Windows driver. The actual ME co-processor is still running.
- gaia 9y agoAnd how would you test for that?
- lima 9y agoUnless you modified your BIOS with a SPI flasher after disassembling your device, you know it's still running :-) It would disappear from the PCI bus. Your commands un-provision AMT (Active Management Technology), the ME feature that apparently has a security issue. Unless you've explicitly enabled AMT, it's not provisioned anyway so this doesn't do anything.
- weinzierl 9y ago> Your commands un-provision AMT (Active Management Technology), the ME feature that apparently has a security issue. It disables the optional OS-side of AMT. How do we know that the vulnerability is in the OS-side? Has this been established yet?
- agumonkey 9y agoMay be worth reading the coreboot wiki, I remember reading about the different subsystems of AMT, and it seems plausible that you can set it into a state where control functions are disabled. But my memories are very blurry. Still coreboot guys are quite experts on the matter.
- lima 9y agoUnprovisioning disables both the OS side and the hardware AMT. It doesn't change anything if you never enabled AMT.
- gaia 9y agoYou are correct, I've updated the HN link title and post's title.
- huhtenberg 9y agoThis is taken verbatim from Intel's "SA-00075 Mitigation Guide" [1] As others have said, it doesn't disable the ME. It merely removes OS-side support for it and resets configuration to non-exploitable state. The ME itself remains up and running. [1] https://downloadmirror.intel.com/26754/eng/INTEL-SA-00075%20Mitigation%20Guide-Rev%201.1.pdf https://downloadmirror.intel.com/26754/eng/INTEL-SA-00075%20... * To clarify - the original title of this post was something like "Completely Disable Intel Management Engine (finally!)".
- gaia 9y agoThese step by step instructions were built based on the mitigation guide, which is linked in the advisory. I've updated the HN link title and post's title (see https://news.ycombinator.com/item?id=14253732 https://news.ycombinator.com/item?id=14253732)
- weinzierl 9y ago> It merely removes OS-side support for it and resets configuration to non-exploitable state. How do we know that the vulnerability is in the OS-side? Has this been established yet?
- lima 9y agoIt also un-provisions AMT, which supposedly prevent remote exploitation.
- weinzierl 9y agoAh, I understand. The Mitigation guide says: "Intel highly recommends that the first in all mitigation paths is to unprovision the Intel manageability SKU to address the network privilege escalation vulnerability". Unprovisioning AMT seems to be the essential part and I am curious if the other steps serve any real purpose. The Mitigation Guide goes on to say: "Systems that are vulnerable [...] should be unprovisioned using the tools used to initially configure them [...] As an example, the Intel AMT Configuration Utility [...]" So ACUConfig is just an example and specifically not the Intel recommended way. OP doesn't say that.
- hackuser 9y agoSome riskier but possibly more effective solutions for disabling or at least limiting ME (AMT is one application that runs on ME): https://github.com/corna/me_cleaner https://github.com/corna/me_cleaner https://hardenedlinux.github.io/firmware/2016/11/17/neutralize_ME_firmware_on_sandybridge_and_ivybridge.html https://hardenedlinux.github.io/firmware/2016/11/17/neutrali... To be 100% clear, I haven't tried either.
- gaia 9y agoSee https://news.ycombinator.com/item?id=14253704 https://news.ycombinator.com/item?id=14253704
- ajdlinux 9y agoThis is copied from the Windows-only SA00075 Mitigation Guide from Intel. Intel advised me that a Linux version of the Mitigation Guide is coming - https://twitter.com/IntelSupport/status/859437569368567811 https://twitter.com/IntelSupport/status/859437569368567811
- wfunction 9y agoDumb question: is any of this relevant for someone who only uses Wi-Fi and not ethernet?
- Qantourisc 9y agoAssume it's relative, until you can proof your BIOS is unable to communicate with the Wi-Fi adapter. If you are thinking "but it can't connect to a network", your OS will do that for you, at which time it can start communicating.
- wfunction 9y agoIsn't the entire point of AMT to allow out-of-band system management? If it relies on the OS to connect to Wi-Fi that would seem to kind of defeat the purpose. Is there any evidence AMT works on Wi-Fi for anybody? I tried pinging my laptop from another machine on the ports listed here and I didn't get any response over Wi-Fi, so I'm not sure how to interpret that.
- dboreham 9y agoGenerally these things don't work over WiFi because the special back-channel between the NIC and the management CPU isn't there for WiFi NICs. But as others have said, it is in theory possible if someone were to build the required communication path into their NICs.
- hd4 9y agoHas AMD done anything similar to this? I'm thinking of what hardware to buy in future, probably going to skip Intel-based going forwards.
- SXX 9y agoAll AMD CPUs after FX have PSP which is efficiently the same thing as Intel ME and it's also can't be removed / disabled at all since it's participate in CPU boot sequence.
- hd4 9y agoOh great. Do we have any viable choice left in avoiding these 'helpful' blackbox modules? Viable meaning something that could run a medium-load server?
- SXX 9y agoThere is chance that POWER8 and future POWER9 based hardware might work, but it's very expensive. There was already an attempt to create backdoor-free hardware, but for now it's failed: https://www.raptorengineering.com/TALOS/ https://www.raptorengineering.com/TALOS/
- hd4 9y agoDark times when even good old AMD is doing anti-consumer crap. I don't even get how this is helping their cause against Intel. They could have simply not done the stupid things Intel is doing and carved a niche. But this is just showing they want to be another Intel, not a better Intel.
- SXX 9y agoSadly I don't think there is any market for secure hardware. Simply no one care; not even enterprises and governments.
- 9y ago
- throw2016 9y agoThis is the kind of brazen backdoor which makes all other security moot. How can anyone depend on security if the cpu is backdoored and anyone can remote your machine irrespective of OS and even whether it is running? Given the sheer brazenness and scope I wonder why the security folks have been so muted, what can be more important this this? What ever the benefits of this backdoor for enterprises or any single group imposing it on all users makes it look like a fig leaf. The fact that it is done in consort with AMD and ARM can only lead to the conclusion it is some kind of a mandated NSA backdoor. There is a huge unresolved dichotomy now of 'democracies' with governments completely and singularly obsessed with their citizens' speech. Having hundreds of thousands of government employees working on monitoring citizens and doing things like backdooring CPUs is the furthest you can get from free societies. Infact it's the opposite.
- Raphmedia 9y agoOut of the loop: Why would someone want to disable Intel AMT? I gather that there was an exploit?
- gaia 9y agostart here http://www.fsf.org/blogs/licensing/intel-me-and-why-we-should-get-rid-of-me http://www.fsf.org/blogs/licensing/intel-me-and-why-we-shoul...