4 ms·
What can an ordinary person do? Plugging out the network cable? What about laptops? Can this vulnerability hack into Wi-Fi and allow itself to the internet? But
by MichailP 9y ago
What can an ordinary person do? Plugging out the network cable? What about laptops? Can this vulnerability hack into Wi-Fi and allow itself to the internet? But then again the moment you plug internet back in you're done.
- zanny 9y agoThe me-cleaner is getting more and more bugfixes over time. For the average person simply sanitizing a firmware image to disable the ME will be enough. The question is more at what point are you confident you won't brick the system doing it. I have not done any research recently in the success rate of ME cleaner, but it isn't that low, it usually works to the best of my knowledge, and once we have good documented statistics saying "this works most of the time" it becomes more feasible for those not directly involved in its development to start using it more proactively to get rid of this vulnerability.
- userbinator 9y agoThe irony is that AFAIK the ME cleaner itself depends on exploiting some vulnerability in ME in order to disable it... so it may get more difficult in the long term.
- CapacitorSet 9y agoAs far as I know it's not exploiting vulnerabilities, just the fact that it won't mind if most modules are not present.
- zanny 9y agoThe good news on that front is most board manufacturers abandon updates after a year or two. My ASUS mobo right now was released in 2013 and saw its last firmware update in late 2014. With the exception of the most modern boards, you can generally assume there will be no more updates for your hardware after a year or so.
- kogepathic 9y ago> What can an ordinary person do? Use non-x86 platforms such as an ARM based Chromebook, or potentially an x86 with the ME partially disabled (coreboot or similar, but it's not a 100% guarantee). > Plugging out the network cable? It depends on the vulnerability scope. If it's over HECI (virtual PCI device between host OS and ME) then removing the network cable won't save you from local malware owning the ME via HECI. > But then again the moment you plug internet back in you're done. Well considering how few people ever update the firmware of their devices, it's unlikely a majority of computers would ever be patched against an ME vulnerability anyway. Starting with ME12 Intel is going to start checking the ME firmware version number in the ME's silicon (read-only) boot ROM to prevent firmware downgrade attacks. [1] This version number is stored in single use eFuses which can only be incremented, and are during an ME update. But it depends on your threat model. As stated in the PDF, there are only 3 known exploits against the ME, and only one results in unsigned code execution. Until someone weaponizes such an exploit, which at the moment it seems physical access is needed, then Intel x86 owners are safe. If your adversary is a three letter agency or nation state attacker, then you've got bigger concerns than someone hacking your ME (starting with, say, your OS). [1] https://github.com/corna/me_cleaner/issues/111#issuecomment-350480591 https://github.com/corna/me_cleaner/issues/111#issuecomment-...
- userbinator 9y agoan x86 with the ME partially disabled (coreboot or similar, but it's not a 100% guarantee) Or even x86 before it had ME at all, which means anything before ~Core 2 or so. AFAIK the Thinkpad x60 is one of those.
- MisterTea 9y ago> Use non-x86 platforms such as an ARM based Chromebook Careful there. Microsoft has been slipping PC bits into their Windows Arm systems because Windows is so hopelessly tied to the PC platform that they had to PCify their Arm with EFI, ACPI and other PC legacy junk. Just be sure your Arm does not have any of this anti-consumer crap and you should be good to go.
- johncolanduoni 9y ago
- criddell 9y agoAn ordinary person can buy a PC with it disabled. Dell has started offering to disable the management engine for $30. Choose "Intel vPro - ME Inoperable, Custom Order" when ordering.
- ploggingdev 9y agoIt's not possible to disable ME completely. See : https://twitter.com/rootkovska/status/939058475933544448 https://twitter.com/rootkovska/status/939058475933544448
- criddell 9y agoI think people are mostly worried about the persistent, highly privileged processes that it starts (especially the remote-access features when they don't need them). The initialization stuff (in the BUP module) are necessary and AFAIK, nobody is suggesting that be removed.
- jacek 9y agoI removed Intel ME from my Thinkpad x230 last weekend. I highly recommend this machine. Still quite powerful, very serviceable, upgradeable, Linux friendly and cheap (you can get one in good condition for ~$150 USD in USA). I used the following guide (very easy to follow): https://steemit.com/tutorial/@joeyd/run-don-t-walk-from-the-blob https://steemit.com/tutorial/@joeyd/run-don-t-walk-from-the-... EDIT: You can also get a laptop with Intel ME disabled. As far as I know you can get a modern laptop without ME from System76, Purism. For a while Dell offered such machines, but that might no longer be the case.