8 ms·
Wow all 6th, 7th and 8th gen are all vulnerable along with a bunch of Xeon processors. Even the laptop I am typing this on is vulnerable, this is going to be me
by aeleos 9y ago
Wow all 6th, 7th and 8th gen are all vulnerable along with a bunch of Xeon processors. Even the laptop I am typing this on is vulnerable, this is going to be messy. Plus all the fun vulnerabilities like arbitrary code execution, unauthorized access to privileged content. These must be related to the blackhat talk coming up in December about hacking a turned-off computer and running unsigned code on ME [0]. Yep and the two researches doing the talk are the two people credited in this announcement, Mark Ermolov and Maxim Goryachy. Great work by them finding these vulnerabilities and disclosing them, these are the kind of vulnerabilities that the NSA would salivate over.
I wonder if this will at all dissuade either Intel or AMD into continuing to make these super privileged processors whose functions are completely hidden. The cynic in me thinks that this will change absolutely nothing.
There is a great website called The Bad Thing [1] that has compiled the known information about Intel ME.
I just ran the detection tool on my laptop and I am running a vulnerable version of Intel ME, but I can't even do anything about it until my system manufacturer provides a patch for it. I feel like this is going to be one of those situations that ends up leaving millions of devices unpatched and vulnerable a few years down the road.
[0]: https://www.blackhat.com/eu-17/briefings/schedule/#how-to-hack-a-turned-off-computer-or-running-unsigned-code-in-intel-management-engine-8668 https://www.blackhat.com/eu-17/briefings/schedule/#how-to-ha...
[1]: https://www.cs.cmu.edu/~davide/bad_thing.html https://www.cs.cmu.edu/~davide/bad_thing.html
- toyg 9y ago> I wonder if this will at all dissuade either Intel or AMD into continuing to make these super privileged processors They clearly invested some serious money into this sort of thing and see it as a differentiator (or AMD wouldn't have followed suit). Chances that they'll throw it all away because of a few vulnerabilities are very, very thin.
- chocolatebunny 9y agoThrowing it away is unlikely but the fact that this affects Xeon processors means that pretty much every single data center across the world could be affected. And that means that a lot of companies with a lot of money will complain.
- jlgaddis 9y ago> "...a lot of companies with a lot of money will complain." Maybe, but they'll only complain for about five minutes. Then, they'll patch everything and move on and forget about it. Until the next time. Rinse and repeat.
- aeleos 9y agoAMD has had their own version of this for quite some time. Its called the Platform Security Processor (PSP), it has been in anything AMD since around 2013 [0]. I am not sure if Ryzen / Threadripper has it, but I would be surprised if it didn't. [0] https://libreboot.org/faq.html#amd-platform-security-processor-psp https://libreboot.org/faq.html#amd-platform-security-process...
- wolfgke 9y ago> AMD has had their own version of this for quite some time. Its called the Platform Security Processor (PSP), According to the small footnote at http://www.amd.com/en-gb/innovations/software-technologies/security http://www.amd.com/en-gb/innovations/software-technologies/s... AMD does not use the name "Platform Security Processor (PSP)" anymore, but calls it "AMD Secure Processor" instead.
- zaarn 9y agoIf I'm not mistaken, PSP is not at all like ME, it runs code if you supply it with such but on it's own it doesn't listen to network traffic or run it's own OS, atleast, last I checked. I'd still consider AMD the better player in the game.
- my123 9y agoMobile Atoms are affected it seems despite using TXE (SPARC CPU) instead of ME.
- Avery3R 9y agoblackhat =/= defcon
- deleted 9y ago[deleted]
- aeleos 9y agosorry, fixed
- white-flame 9y ago> I wonder if this will at all dissuade either Intel or AMD into continuing to make these super privileged processors whose functions are completely hidden. I think many discussions miss the nuance here. The problem is that the functionality is hidden, not necessarily that the function is there. In corporate use, these tools can be incredibly useful. If they were more transparent, then they could be used by normal users for remote administration as well. But it needs to be secure, and it needs to exist without secrecy. If this portion were free for the user to configure, or if they allowed complete disabling via motherboard jumper, or simply open sourced it, that would be a better step. However, the NSA's activities have destroyed all trust in these sorts of features coming from an American company, so even if it were completely open sourced, there's no guarantee that there isn't other hardcoded ROM also executing in tandem with the open source components.
- blacksmith_tb 9y agoI agree with your overall conclusions, but I am having a hard time imagining the 'normal users' who would use remote administration... though perhaps if that were normal-for-HN users...
- rwmj 9y agoI guess I'm "Normal-for-HN". IPMI is so useful that I wouldn't buy a server without it, even one I'm going to use in the same building.
- subway 9y agoIPMI is fantastic, so long that the understanding is in place that access to your IPMI vlan may as well be considered root access to the node. BMCs tend to be pretty miserable when it comes to security. It's generally a good idea to have ACLs in place to ensure BMCs can only communicate with a secured management node, and importantly that BMCs cannot communicate with each other.
- nullc 9y ago
- Darthy 9y ago> these are the kind of vulnerabilities that the NSA would salivate over No need to salivate over something that you paid for and that you already used for 8 years. Post-Snowden if you believe the NSA has already broken into most things and has very often paid to facilitate this (like loss-making Skype US server routing, or inefficiently using valuable silicon space for IME), you are no longer a conspiracy theory lunatic - you are just a mere sane person applying Occam's razor.
- daxorid 9y ago> that you paid for I don't think it's necessary to pay when you can just threaten charges of treason (Melissa Mayer) or make an example out of the uncooperative (Joe Nacchio).
- gbrown 9y agoWow, who could have foreseen that this was such a risk /s
- benevol 9y ago> these are the kind of vulnerabilities that the NSA would salivate over. Are you really suggesting the IME and AMD's similar component are not the fruit of a collaboration between these market dominating companies and the NSA?
- JumpCrisscross 9y ago> I wonder if this will at all dissuade either Intel or AMD into continuing to make these super privileged processors whose functions are completely hidden Our brightest hope for reform involves (a) a breach involving ME and (b) European regulators laying fines on Intel.
- em3rgent0rdr 9y agoWhat about fully libre firmware such as libreboot? What about isolating and disabling the ME as what Purism has done? What about fully open processors based upon open instruction sets such as RISC-V?
- rdslw 9y ago> I just ran the detection tool on my laptop and I am running a vulnerable version of Intel ME, but I can't even do anything about it until my system manufacturer provides a patch for it. I would carefully analyse if patching is a good thing. Those vulnerabilities might be used in good way to disable ME and all this intel crapware completely, while if patched, this again may be impossible without doing manual chip clip and reprogramming with external device. Of course YMMV. Here, nice read of current way, using raspberry pi and clipping ME chip while motherboard is off: https://wiki.gentoo.org/wiki/Sakaki%27s_EFI_Install_Guide/Disabling_the_Intel_Management_Engine https://wiki.gentoo.org/wiki/Sakaki%27s_EFI_Install_Guide/Di...
- ChuckMcM 9y agoI was going to contribute something similar, I recall early dismissals suggesting that the 'low end' machines didn't have this capability. I recall Mike Guimarin's comment of "If transistors are free (and they are) why not cut down the internal SKUs and put this on all processors" which apparently Intel did. Of course as it becomes clear you can (and should) disable it, if you do that on a corporate laptop you might find that your IT team is both mad and proud of you at the same time. Quite the quandry.
- nullc 9y ago> Wow all 6th, 7th and 8th gen are all vulnerable along with a bunch of Xeon processors. Do we really think older systems are magically not vulnerable to any of these? It seems more likely that they're vulnerable but old enough that they're getting ignored... and so they'll never get fixes. Intel sales slump solved? :-/
- nullnix 9y agoNah. Intel are still selling new systems with SPS 3.0 on them, and those systems are still receiving updates, including security updates (I bought one in March, and it's had two firmware updates since, both with ME changes involved). I can believe that they aren't vulnerable to this one.
- omginternets 9y agoPlease let this give rise to a class-action lawsuit. It's the only way this crap will stop.
- em3rgent0rdr 9y agoWhat exactly would be the identifyable damage?
- omginternets 9y agoHopefully (sort of), the monetary damage that follows from black-hat abuse of the vulnerabilities.
- ekianjo 9y ago> this is going to be one of those situations that ends up leaving millions of devices unpatched and vulnerable a few years down the road. Intel managed to make PCs as safe as Android.
- Paianni 9y agoAMD rolled out PSP from 2013 to 2015, not 'roughly 2010'.