6 ms·
Intel decided they have the right to put a whole secret computer inside your computer that only they can access. God knows what it does when no one is watching.
by bobsam 9y ago
Intel decided they have the right to put a whole secret computer inside your computer that only they can access. God knows what it does when no one is watching.
That's the problem you should discuss, not this particular exploit.
- nullc 9y agoSo has AMD.
- djsumdog 9y ago..and HP servers/sans (iLO)
- Godel_unicode 9y agoThat's a separate system which lives on a daughter board. It's essentially a kvm+usb cdrom+power switch. No disk access, no dma. Not the same thing at all. Edit: and trivially removable if you don't want it.
- mjg59 9y ago> No disk access AMT doesn't provide raw disk access either > no dma It's connected to PCI. What makes you so sure that it has no DMA access? > Not the same thing at all Indeed - iLo is pretty good, but the implementations provided by other vendors have an even worse track record than AMT does.
- yuhong 9y agoI think they even excluded iLO when they locked down firmware updates to paid customers just after https://lkml.org/lkml/2013/11/11/653 https://lkml.org/lkml/2013/11/11/653 (they are the one who ported UEFI to RISC-V too!)
- dom0 9y agoWell if you want to walk to the DC every time a server throws a tantrum, be my guest.
- bobsam 9y agoHave you seen their reddit AMA regarding this?
- xgen 9y agoNot the person you were replying to but I would really want to read this, do you have a link? edit I think i may have found it, is it this https://www.reddit.com/r/Amd/comments/5x4hxu/we_are_amd_creators_of_athlon_radeon_and_other/ https://www.reddit.com/r/Amd/comments/5x4hxu/we_are_amd_crea...
- yuhong 9y agoThere still seems to be much confusion about the relationship between PSP and DASH (AMD's version of AMT).
- AnimalMuppet 9y agoWell, even if you completely trust Intel to never be nefarious, never act against your best interest, never do anything shady whatsoever with that power, you can't trust them to keep that power only for their own use. This vulnerability is proof of that. So you don't have to claim that Intel could have bad faith. You can claim, with proof, that Intel has less than perfect success at security, and that less than perfect security is reason enough why this "secret computer inside" is a horrible idea.
- madez 9y agoAll in the name of DRM.
- Animats 9y agoHaving a "management engine" with direct access to the network and to memory is questionable in itself. Its code being secret indicates there's probably something bad going in. If it only does what Intel says it does, it doesn't need to be secret.
- justinclift 9y agoIPMI falls into similar waters, and also has known design flaws around authentication. :(
- dom0 9y agoIPMI normally has a dedicated NIC (well, on some crappy boards it doesn't), which tends not to be connected to public networks.
- justinclift 9y agoIn theory, definitely. :D Unfortunately though, too many of them still seem to make the connection. eg looking through Shodan quickly just now still shows potentially 1k+ examples. Ugh. :( But you're right that it's a lot less than is likely present for this AMT problem.
- pcwalton 9y agoIntel ME has a DRM app called "Protected Audio-Video Path" [1], which obviously has to be secret. As to whether anything actually uses the PAVP functionality, I have no idea. I wouldn't be surprised if it was something Intel included to try to push Atom-based set top boxes or whatever. [1]: https://www.slideshare.net/mobile/codeblue_jp/igor-skochinsky-enpub https://www.slideshare.net/mobile/codeblue_jp/igor-skochinsk...
- angersock 9y ago> Intel ME has a DRM app called "Protected Audio-Video Path" [1], which obviously has to be secret. Does it, does it really? I'm pretty sure security through obscurity is some bullshit.
- Spooky23 9y agoIt does very little. As usual with AMT, there's a lot of noise, but these vulnerabilities to date have only been exploitable with activated AMT. With activation you can patch, etc. And as I always point out in these stories, if Intel AMT freaks you out, Google "absolute software embedded bios".
- mr_overalls 9y agoBlack Hat Briefings 2009 - researchers show that the implementation of the Computrace/LoJack agent embedded in the BIOS has vulnerabilities and that this "available control of the anti-theft agent allows a highly dangerous form of BIOS-enhanced rootkit that can bypass all chipset or installation restrictions and reutilize many existing features offered in this kind of software." Black Hat 2014 - Kaspersky demonstrates local and remote exploitation of first-stage CompuTrace agent (small agent, it is used only to install full version of rootkit after activation of LoJack or after reinstallation of Windows) https://www.blackhat.com/docs/us-14/materials/us-14-Kamlyuk-Kamluk-Computrace-Backdoor-Revisited.pdf https://www.blackhat.com/docs/us-14/materials/us-14-Kamlyuk-... Holy hell.
- yuhong 9y agoAh, the laptop anti-theft arms race.