3 ms·
Surely, this is more an opinion piece than a didactic article. Here you have a more detailed write-up on the issue, including a known vulnerability and how othe
by aylons 9y ago
Surely, this is more an opinion piece than a didactic article. Here you have a more detailed write-up on the issue, including a known vulnerability and how others could be lingering: https://www.eff.org/deeplinks/2017/05/intels-management-engine-security-hazard-and-users-need-way-disable-it https://www.eff.org/deeplinks/2017/05/intels-management-engi...
- ngneer 9y agoThanks. The citation describes the existence of vulnerabilities and laments the lack of transparency. While the latter is indeed lamentable, and is known to be a contributing factor in increasing risk, vulnerabilities do exist in any system, including transparent ones (e.g., OpenSSL). Still am not seeing any evidence of malice by this vendor, as "providing a full set of entrenched vulnerabilities, user espionage tools and privacy-evading mechanisms" would perhaps imply. Vendors have a hard time with security. Chip vendors are no different, only the stakes are higher.
- zAy0LfpBZLC8mAC 9y agoThe important point is that in the case of OpenSSL, anyone who wanted to know could know, and plenty of people knew. Not the specific vulnerabilities, but the horrible quality of the code base was not just something that you could discover by looking at the source, it is something that plenty of people did discover. Also, obviously, anyone could in principle fix vulnerabilities they find in OpenSSL, without any need to wait for the OpenSSL project or anyone else to do anything.