8 ms·
Potential impact of the Intel ME vulnerability
- tomc1985 9y agoThe $10000000 question... generally speaking, am I safe from a potential drive-by infection if my PC is behind NAT? (Assuming, of course, the router is not infected or vulnerable and my computer is not DMZ) Or is there some new attack vector that can pierce those machines reliably?
- Stefan-H 9y agoDrive by downloads are very much an issue regardless of NATing. Taking advantage of browser exploits or bugs to download and execute arbitrary code/executables. note: this is common in compromised or malicious ad networks, so just safe browsing habits are not necessarily enough.
- tomc1985 9y agoI was thinking more in-terms of attacks requiring zero user interaction. But you are right that NAT has no interaction with unwitting-user-type drive-by downloads
- feikname 9y agoI am no security expert, but if a machine in the local network gets infected and tries to access your ME, then NAT can't prevent the attack. That's the only other vector I can think of.
- jsmthrowaway 9y agoIt’s safest to never consider NAT and security in the same thought, for a few reasons. Two come to mind right away: IPv6 is pushing us toward less NAT, and laptops go other places and interact with other networks than your own.
- wiml 9y agoAlso (as feikname points out in another comment) because if you're relying on your NAT for security, your security boundary becomes your network, not your machine. If you read post-mortems of security breaches, it's really common for the initial intrusion to be a printer, or webcam, or an intern's/secretary's/nonprivileged user's device, which then pivots using the internal network to gain more access.
- zaarn 9y agoIPv6 is also pushing towards a more firewall-heavy network rather than a firewall-less network, usually a NAT implies the presence of a firewall though.
- icebraining 9y agoThere's the danger of automated updates, if they are not signed or if the key is compromised. The NotPetya malware infected a large number of machines by being injected into the update server of a company which developed a tax preparation program. When the program fetched the new "update", the machine got infected.
- Erlich_Bachman 9y agoJudging from other replies here, answer to your question is "being behind NAT is most probably safe in terms of random remote ME exploitation". But since there are other attack vectors, and since NAT can technically be circumvented (due to bugs in router, etc., which are NOT uncommon) - you should definitely disable ME if you can (and now there are tools to do that).
- pdkl95 9y ago> being behind NAT is most probably safe Any protection at the router level is from the firewall, not NAT, which only rewrites addresses. NAT does not provide any security benefits on it's own. (see [1] for a longer explanation) [1] https://news.ycombinator.com/item?id=14282568 https://news.ycombinator.com/item?id=14282568
- Erlich_Bachman 9y agoI think the idea here is being that if NAT is used, in the most common meaning, that usually means that the machine behind the router is not Internet-routable. There is no address which can be reached from the internet, that will go to the machine directly. (Which has actual security benefits.) Of course the abbreviation "NAT" really has a broader meaning, and one can of course set up certain network configurations where the machine would still be Internet-routable, even though NAT is used for something, or the other way around, etc. Is this what you meant? Judging by the link it seems so. A clarification could be important, so do you suggest perhaps that the question should have been more like "If my machine does not have a direct Internet address, due to NAT configuration, am I safe from ME exploits"?
- pdkl95 9y ago> There is no address which can be reached from the internet Maybe read my previous [1] again? If you are behind a NAT only - which would be highly unusual - you probably can send packets to it from the internet. The router will simply forward packets that have an internal (RFC 1918) DST address. That only thing NAT does is rewrite address fields. The reason you usually cannot receive packets directly from the internet is due to the stateful firewall. > "If my machine does not have a direct Internet address, due to NAT configuration, am I safe from ME exploits"? s/NAT/firewall/
- upofadown 9y ago>The most common usage of TPMs is to protect disk encryption keys - Microsoft Bitlocker defaults to storing its encryption key in the TPM, automatically unlocking the drive if the boot process is unmodified. I had to go look this up. Apparently there is mode of full disk encryption that automatically decrypts the disk every time you boot up if some stuff has not been modified. That strikes me as quite pointless. * https://en.wikipedia.org/wiki/BitLocker#Encryption_modes https://en.wikipedia.org/wiki/BitLocker#Encryption_modes
- elehack 9y agoIf the machine (1) has soldered-on RAM (preventing cold boot attacks) and (2) the portions of the OS that run prior to user authentication are sufficiently secure, then it really doesn't seem to be a problem. Last I knew, Windows does not like to let you enable this mode in a machine with removable RAM that don't have compensating security features.
- cryptonector 9y agoAnd also no Thunderbolt/Firewire, and/or has an IOMMU and the OS uses it.
- rootsudo 9y agoI'm sorry, what? Windows 100% allows you to use TPM + bitlocker and secure the keys on AD on any sort of computer, regardless of removable ram or not.
- xmodem 9y agoin what sense is it pointless? If the attacker can’t log into the system, and can’t modify the boot process without invalidating the TPM, then so long as the TPM is reasonably tamper proof it’s perfectly sufficient for the 99% use case for full disk encryption - a stolen laptop
- lemoncucumber 9y agoThere are basically three options for how to do disk encryption unlocking: * The way that e.g. macOS FileVault works, where you enter your password in EFI, before the machine boots and before the OS is loaded. * The way that e.g. iOS works, where there is an unencrypted partition containing the OS (mounted read-only), and an encrypted partition containing the data. The OS boots off the unencrypted partition, then you have to enter your password to unlock the data partition. * The mode you're describing, where the unlocking happens automatically if and only if nothing has been tampered with (the encrypted hard drive hasn't been swapped into another machine, etc). With this mode you're relying on the fact that when the OS boots it won't let you do anything without entering a password, even though the disk is already unlocked. Assuming there are no bugs in the login screen, no way to physically read the contents of RAM (where the encryption keys are), and no way to access the contents of the TPM, this approach is just as secure.
- rsync 9y ago"While AMT gives an authenticated user a great deal of power, it's also designed with some degree of privacy protection in mind - for instance, when the remote console is enabled, an animated warning border is drawn on the user's screen to alert them." Can someone point me to a picture, or screenshot, of this ?
- Cyphase 9y agoIf the ME is drawing this directly to the GPU, it wouldn't show up on a screenshot. A picture would work of course. Also, I would guess that it only works if you're using the integrated Intel GPU. Non-xkcd reference: http://www.bash.org/?291262 http://www.bash.org/?291262
- rsync 9y agoI am looking forward to seeing some ME demos from the art scene ...
- tedunangst 9y agoThere's a screenshot somewhere in https://www.youtube.com/watch?v=aiMNbjzYMXo https://www.youtube.com/watch?v=aiMNbjzYMXo
- acidburnNSA 9y agoI think I see it at 27:57 https://www.youtube.com/watch?v=aiMNbjzYMXo&t=27m57s https://www.youtube.com/watch?v=aiMNbjzYMXo&t=27m57s
- mrsteveman1 9y agoRebooted one of my AMT machines so I could take a video of what you see on the physical screen during boot while the remote console is active: https://youtu.be/GDD8os3ZeCI https://youtu.be/GDD8os3ZeCI
- sspiff 9y agorEFInd is the greatest little EFI bootloader!
- krylon 9y ago> The big problem at the moment is that we have no idea what the actual process of compromise is. Intel's behavior through this while story has struck me as rather peculiar. The impression I get (which might be totally wrong - I sure hope that is the case!) is that Intel hardly admits to anything more than is already public knowledge. I really hope I am just misinformed / judging on incomplete information. But based on what I do know, I find the implications of Intel's behavior rather disturbing. Even more disturbing than the specific security issues people have found with the ME.
- vog 9y agoIt is quite a common theme on HN that actual infrastructure people speak up against Intel ME. (for example: https://news.ycombinator.com/item?id=15796392 https://news.ycombinator.com/item?id=15796392) The tone is always along the lines: The advantages of ME for server monitoring are negligible, but the risks are huge, so they wish they could get all their hardware without ME. I wonder if there is any way for you to unite? Maybe to change Intel's mind. Or to change your manager's mind, to be able to vote with your company's wallet against ME. Would that be feasible?
- Asiasweatworker 9y agoThis petition like a "responsible encryption". A feasible and easier way is just buy a consumer laptop or shipped with non-AMT ME and make ME boot into the recovery mode.