4 ms·
Weren't the ME vulnerabilities remotely exploitable? If so that's not the same at all as what we're talking about here.
by zenhack 9y ago
Weren't the ME vulnerabilities remotely exploitable? If so that's not the same at all as what we're talking about here.
- pvg 9y ago'Persistent exploit' and 'Remote exploit' are surely both in some very high category of badness, it seems weird to say they are not the same at all.
- AstralStorm 9y ago"Persistent when you overwrite firmware after cracking update key" is not very persistent at all.
- consp 9y agoThe are not. Remote is far worse as it usually enables compromise (via privilege escalation most of the cases) and persistence without need for a previous break or physical presense. These reported errors, while quite severe for what i've been able to make out of the less-than-good paper, do not grant a primary mode of attack and do not provide a way of getting privileges. Just a way of keeping it forever and ever and ever and ever ... Should be fixed and done properly, just get the fucking CVEs already and publish it ... It is highly likely that it's in some way applicable to other secure elements on other cpu's as well so a proper response is needed.
- pvg 9y ago"The are not." The basis of this is mostly you just saying it emphatically, as far as I can tell. Most real-world exploits rely on a combination of vulnerabilities. What's a sensible ranking of 'remote' over 'persistent'? just get the fucking CVEs already What does this really have to do with anything? It's hard to imagine anyone dealing with a real deployed system saying 'Well, since there is no CVE, this does not affect us at all".
- blattimwind 9y agoRemote means you're already compromised. Persistent means you can't easily recover from a compromise.
- pvg 9y agoNo.
- tptacek 9y agoCVEs are something that people who don't do vulnerability research seem to care about a lot more than people who do. What difference do you suggest it makes whether CTS-Labs gets them allocated or AMD does?