6 ms·
How to Hack a Turned-Off Computer, or Running Unsigned Code in Intel ME
- j_s 9y agoThis PDF might be news to many; click 'past' to see previous submissions -- last month's got traction: [dupe] https://news.ycombinator.com/item?id=16015539 https://news.ycombinator.com/item?id=16015539 (543 points, 107 comments) HN user saulrh mentioned that the list of requirements "does not seem incredibly unusual" for enterprise setups with AMT on. Pre-Meltdown/Spectre this was 2017's "big deal" re:Intel; nearly all of the varying degrees of paranoia in the previous discusson seem a lot more reasonable with the benefit of hindsight. (If any more AMT info has become available thanks to Meltdown/Spectre-enhanced reverse engineering I would appreciate a heads-up; example vs SGX: https://github.com/lsds/spectre-attack-sgx https://github.com/lsds/spectre-attack-sgx)
- godelmachine 9y agoI thought it's not possible to paste the same link twice in HN, yet this appears for the 3rd time, as far as my memory permits.
- z_open 9y agoDoes AMD's PSP have the same security vulnerability?
- freeone3000 9y agoLikely not the same, due to independent implementation, but it'd be foolish to think it didn't have security flaws equally as severe.
- blauditore 9y agoCan you elaborate? From what I understand (I'm not well-informed though), those security flaws stem mainly from carelessness by Intel. So this would assume AMD acts equally careless, which may or may not be true.
- gh02t 9y agoI think the argument is that AMD's implementation is similar in complexity and any sufficiently complex implementation will likely have vulnerabilities, sloppy or not.
- brudgers 9y agoThe assumption that the flaws arise from the complexity of contemporary CPU's rather than incompetence within the engineering teams at the world's leading CPU company is probably more useful. When problems come to light, those problems are latent bugs. The engineering was equally competent before and after the latent bugs became known bugs. Bugs with decades long latency are most likely to be non-obvious. In engineering terms, the bugs are "errors and omissions" not carelessness or negligence. Errors and omissions arise because humans are fallible and engineering is a human process. One of the features of Intel (and AMD) products is that their primary customers are data centers and that's where the core CPU design parameters come from (not consumers or developers). The consumer/developer SKU's are little more than repackaging and feature tweaking of the chips that Intel/AMD sells datacenters in high volume on 1-3 year cycles. That's what drives the roadmap five+ years out.
- dijit 9y agoLast I heard about PSP is that it's a supplier of things like TPM but does not have network functionality akin to AMT/vPro. If true then it really limits the attack surface.
- garmaine 9y agoThis is incorrect. PSP is explicitly a match to vPro in terms of features, including offline network asset management.
- dijit 9y agoYou're going to have to back that up. I have never found a shred of evidence to support that it has a network stack. I don't believe it's been explicitly denied either, but I also don't find software that leverages deployments using PSP (or, Secure Processor, as it's now known) unlike what I find for Intels ME/AMT. All indicators point to them focusing on it as a Trusted Execution Environment, similar to secure enclave.
- lasermike026 9y agoOK, so the computer and network switch are connected to a UPS power supply. Kill the power for both. System is now down... Intel needs get their act together or remove this features entirely. Clean it up.
- pweissbrod 9y agoI didnt see mention of this in the article but I thought accessing a powered-off machine required usage of the 3G wireless support built in to the vPro line of intel chips.
- garmaine 9y agoNo. This is a feature of the Intel vPro Ethernet network adaptors.
- ben_w 9y ago> the 3G wireless support built in to the vPro line of intel chips Yikes. That’s the first I’ve heard of this. It’s terrifying that even exists as an option, given how much of a strategic military benefit it provides to whoever can pull Intel’s strings.
- pweissbrod 9y agoscary stuff ben_w look it up 3g support has been in the vPro line for the better part of a decade. call me a conspiracy theorist if you like but i'll bet you dollars to donuts wireless powerless remote management exploits exist in the wild for these intel chips. and by wild i include state-owned in there edit: if you have one of these chips you can disable the feature in bios
- ben_w 9y agoI just did. I agree. And I cannot because I have a mac.
- roselewis470 9y agohello guys,have you ever wondered what your spouse is doing behind you?i was able to get proof that my ex husband was cheating on me through the help of a good samaritan which was referred to me by Mrs Jane.i messaged him and to my greatest suprise he's real and he got me result in less minutes,he's a great professional ,applause for him always as i told him i will let the world know him,do you have any problem spying on someone,track a cheating spouse,hack into text messages and phone calls,bank statement hacks and criminal records erased also you can boost your school grade,hack into whats' app,facebook,viber,emails,gmail and whatsoever related to hacking or your trying to get into a phone without the owner's consent,he's an expert and won't ever fail you. contact hackdigg at g mail dot com or text his number +15186284630 ,also you can text him on whats app or call him with this number on what's app +15185049376 and let him know i referred you.for sure he will help you. Email:hackdigg at gmail dot com Text num:+15186284630 what's app num:+15185049376 tell him Roseline referred you.