5 ms·
If I ran a hosting company and all of my servers were compromised by ring -3 malware exploiting the Intel AMT vulnerability, the first thing I'd do is privately
by stevenh 9y ago
If I ran a hosting company and all of my servers were compromised by ring -3 malware exploiting the Intel AMT vulnerability, the first thing I'd do is privately inform Intel that I intend to go public with the story and sue for damages, after which Intel would perhaps offer a very generous bribe for my silence and a week-long window to replace all of the server processors for free, on the one condition that I bury the truth by fabricating a story about an imaginary ex-employee who improbably was both smart enough to gain an administrative position in a large company while also being stupid enough to risk decades in prison for petty revenge over workplace drama.
- forgottenacc57 9y agoWeird. That's exactly what happened to the data centers at Area 51 too.
- ronilan 9y agoAlso similar to when Gillette paid a very generous bribe to bury Occam's and Hanlon's razors. /s
- sethrin 9y agoI'm sad both that I can't upvote this more than once and that I can't think of any way I'd ever get to steal this line.
- qb45 9y agoNo, these were stolen by aliens but CIA covered it up by pretending to be covering up AMT malware ;) Seriously though, would Verelox still be running unpatched AMT many weeks after the disclosure of this authentication bug? Or does GP think there are more bugs which Intel hopes to sweep under the rug forever by individually covering each incident? They would spend quite a money on these bribes while AMT bugs can simply be fixed with BIOS updates. This Intel conspiracy doesn't make sense. It's aliens, folks, I know it.
- midnitewarrior 9y agoWhat kind of hosting company is going to have any kind of reputation after admitting their security allowed an ex-admin to ransack everything? Rephrase the question -- what idiot customer is going to do business with such a place that allows such a lapse in security to happen? Intel would basically have to buy the company.
- atmosx 9y ago> What kind of hosting company is going to have any kind of reputation after admitting their security allowed an ex-admin to ransack everything? The kind of people that: - Use Gmail, iCloud, etc. post Snowden - Buys SSL certificates from Comodo, etc. - [put other companies here] So, pretty much everybody, me included. Your idea that mis-management can damage a company's reputation permanently, has been proved wrong. The complexity of moving an infrastructure in and out of a service provider is apparently bigger, os as you say, we're all stupid - we manage to survive somehow though.
- chris_wot 9y agoEither way, their reputation would be trashed. Intel knew about potential issues in their products for many, many years. I'd shed no tears if lots of people do this to them now.
- hoodoof 9y ago>>admitting their security allowed an ex-admin to ransack everything What, exactly can be done to secure a company against a malicious systems admin? These are the guys typically with not only the keys to everything but also the knowledge of how it all works. You say that the company cannot be trusted for "allowing" this to happen. I know quite alot about this stuff, and for MOST companies, they simply have to trust that the people with the keys to the castle with behave responsibly. There are ways to design infrastructure such that it is protected from its builders and keepers, but this is very very hard and complex and expensive. Presumably you work for a company that has taken steps to ensure this will never happen, what are they?
- kelnos 9y ago
- ryanlol 9y agoHow Intel would most likely respond to you: "HahaHAHAHahAHAHAHahahAHAHahAHA, fuck off"
- draw_down 9y agoWhat's the opposite of Occam's razor?