13 ms·
I don't want a patch. I don't use that thing for anything. I want them to disable that thing by default! Leaving those backdoors open in older products should
by std_throwaway 8y ago
I don't want a patch. I don't use that thing for anything. I want them to disable that thing by default!
Leaving those backdoors open in older products should lead to a recall because the flaw was there all along.
- rectang 8y agoCertainly if the lifespan of Intel chips turns out to be much shorter than the marketplace expected (because Intel is unable to provide security updates), that affects the value of Intel products and ought to inform future buying decisions. Whether it is the unfortunate materialization of Spectre-style bugs or the deliberately insecure-by-design ME, Intel's inability to support its products is dismaying.
- brudgers 8y agoThe ordinary life cycle of an Intel CPU is the five t̶h̶r̶e̶e̶ year depreciation schedule in the US tax system. The life cycle for Intel's most important customers is less and is based on operating cost in large data centers and these are driven by density, throughput, and energy utilization. Traditionally this has been two years or less as reflected in Intel's tick-tock iteration strategy. The critical life cycle for Intel is not consumer/SMB sales which don't generate sales frequencies and volumes of leading edge products.
- ec109685 8y agoDo you have any citations that companies are replacing their intel processors every 2 years? That is not inline with what I have seen.
- ams6110 8y agoMore like 5 years, or even longer, where I work. We have some 7 year old Dell servers that are still chugging along, performing their duties as well as ever.
- brudgers 8y agoCurious if they are managed with ME.
- close04 8y agoThey have the ME and Server Platform Services (SPS) on top of that but I doubt anyone uses that to manage when Dells have DRAC/iDRAC.
- close04 8y agoUsually the amortization of such systems is ~ 4 years. But many smaller companies choose to stay with the old systems a little longer, 5, or even 6 years lately. Simply because there is no push performance wise. The main motivation for upgrade is software support (usually for the OS, driven by Microsoft), or failure rates for the older systems. And that's for the desktop side. For servers they tend to be taken out of commission when the service they provide is migrated to a whole new platform and the legacy one goes to a better place along with the metal. Servers are more reliable than your regular desktops, they get better support, and most companies don't upgrade running systems. P.S. I don't know of any enterprise environment where ME is used for managing servers. It's usually ILO, ILOM, DRAC, IMM, RMM. I think ME is mostly for desktops or SOHO, Intel has RMM for servers.
- oneplane 8y agoAlso, on servers, Intel has (requires?) SPS: server platform services. It's like an ME, but worse, and without a way to neuter it. Edit: a quick search yields a common core or division at Intel behind the ME and SPS, so that makes a bit of sense. There has been at least 1 exploit in the wild for that SPS, it also lists TXT and ME, so I guess it's a shared (MINIX?) kernel that had the bug.
- forapurpose 8y ago> For servers they tend to be taken out of commission when the service they provide is migrated to a whole new platform Or when the service contract expires or is too expensive to extend. You can't run a server of any importance without a service contract; it can be the difference between all the server's users and services being down for hours or a more than a week, and between IT management keeping their job for hours or longer.
- samstave 8y agoextrapolate as you will... https://aws.amazon.com/blogs/aws/ec2-instance-history/ https://aws.amazon.com/blogs/aws/ec2-instance-history/ I didn’t have one, but it seemed like a worthwhile thing to have and so I spent a few minutes putting the following list together (these are all announcement dates): August 2006 – m1.small. October 2007 – m1.large, m1.xlarge. May 2008 – c1.medium, c1.xlarge. October 2009 – m2.2xlarge, m2.4xlarge. February 2010 – m2.xlarge. July 2010 – cc1.4xlarge. September 2010 – t1.micro. November 2010 – cg1.4xlarge. November 2011 – cc2.8xlarge. March 2012 – m1.medium. July 2012 – hi1.4xlarge. October 2012 – m3.xlarge, m3.2xlarge. December 2012 – hs1.8xlarge. January 2013 – cr1.8xlarge. November 2013 – c3.large, c3.xlarge, c3.2xlarge, c3.4xlarge, c3.8xlarge. November 2013 – g2.2xlarge. December 2013 – i2.xlarge, i2.2xlarge, i2.4xlarge, i2.8xlarge. January 2014 – m3.medium, m3.large. April 2014 – r3.large, r3.xlarge, r3.2xlarge, r3.4xlarge, r3.8xlarge. July 2014 – t2.micro, t2.small, t2.medium. January 2015 – c4.large, c4.xlarge, c4.2xlarge, c4.4xlarge, c4.8xlarge. March 2015 – d2.xlarge, d2.2xlarge, d2.4xlarge, d2.8xlarge. April 2015 – g2.8xlarge. June 2015 – t2.large. June 2015 – m4.large, m4.xlarge, m4.2xlarge, m4.4xlarge, m4.10xlarge. December 2015 – t2.nano. May 2016 – x1.32xlarge. September 2016 – m4.16xlarge. September 2016 – p2.xlarge, p2.8xlarge, p2.16xlarge. October 2016 – x1.16xlarge. November 2016 – f1.2xlarge, f1.16xlarge. November 2016 – r4.large, r4.xlarge, r4.2xlarge, r4.4xlarge, r4.8xlarge, r4.16xlarge. November 2016 – t2.xlarge, t2.2xlarge. November 2016 – i3.large, i3.xlarge, i3.2xlarge, i3.4xlarge, i3.8xlarge, i3.16xlarge. November 2016 – c5.large, c5.xlarge, c5.2xlarge, c5.4xlarge, c5.8xlarge, c5.16xlarge. July 2017 – g3.4xlarge, g3.8xlarge, g3.16xlarge. September 2017 – x1e.32xlarge. October 2017 – p3.2xlarge, p3.8xlarge, p3.16xlarge. November 2017 – x1e.xlarge, x1e.2xlarge, x1e.4xlarge, x1e.8xlarge, x1e.16xlarge. November 2017 – m5.large, m5.xlarge, m5.2xlarge, m5.4xlarge, m5.12xlarge, m5.24xlarge. November 2017 – h1.2xlarge, h1.4xlarge, h1.8xlarge, h1.16xlarge. November 2017 – i3.metal. June 2018 – m5d.large, m5d.xlarge, m5d.2xlarge, m5d.4xlarge, m5d.12xlarge, m5d.24xlarge. July 2018 – z1d.large, z1d.xlarge, z1d.2xlarge, z1d.3xlarge, z1d.6xlarge, z1d.12xlarge, z1d.metal, r5.large, r5.xlarge, r5.2xlarge, r5.4xlarge, r5.12xlarge, r5.metal, r5.24xlarge, r5d.large, r5d.xlarge, r5d.2xlarge, r5d.4xlarge, r5d.12xlarge, r5d.24xlarge, r5d.metal.
- mmt 8y agoUnfortunately, announcement dates only give one endpoint of the timeline. The other endpoint, retirement date (from even previous-generation availability), is crucial to any anlysis.
- dantillberg 8y agoThe US IRS depreciation schedule for computer equipment is five years, not three years: https://en.wikipedia.org/wiki/MACRS#MACRS_GDS_property_classes_table https://en.wikipedia.org/wiki/MACRS#MACRS_GDS_property_class....
- woolvalley 8y agoIf something is considered broken before the full 5 years and you throw it away, you can deduct the rest of the cost right away correct?
- ebikelaw 8y agoThis is not in accordance with my experience. The life of an Intel platform in a datacenter is more like 7-10 years.
- TomMarius 8y agoWhat insurance comapny insures that? What company offers SLAs like that? I want in on that deal!
- ebikelaw 8y agoI have no idea since I'm not in the finance department. Start up an AWS m1.small instance and see what kind of CPU you're using. You may be surprised. Even AWS's current mainstream "M4" offering is using a CPU from 4 years ago.
- TomMarius 8y agoYeah I guess that AWS gets these deals, maybe even supports it themselves. We others don't/can't (no, AWS is not an option). :-(
- CamperBob2 8y agoWhy is this an insurance issue? Do you expect the servers to catch on fire?
- TomMarius 8y agoWell the distributors stamp the top of the server with a sticker that says it's safely operable for 2 years, so no one is going to insure it for more, of course. Might be European thing, though; good think for enthusiasts is that it's common to contact a company and join their next 2 years buyout and acquire cheap hardware.
- close04 8y agoI've never seen this 2 year thing in Europe. There are plenty of companies that stick to their servers for over 5 years. Some servers stay there even for more than a decade because they deliver a service using software that is no longer developed or supported, and there's no replacement for it in the company. So they keep them there, chugging along. But with x86 being basically commodity and virtualization being used everywhere this is less of an issue in most cases. It means your VMs can mostly run on whatever metal you throw under them and that x86 metal can just be propped up to keep working for many, many years.
- lowbloodsugar 8y agoDepreciation determines the minimum age not the maximum. I've seen XP boxes still in use.
- close04 8y agoYes but it's also used as a reference point for when you can upgrade. It's not the trigger but way back when YoY performance improvements were substantial companies waited for the amortization cycle to complete and jumped on the next gen. Not anymore, no point. But the XP example you gave kind of undermines the point. Nobody should be using XP. Not even on air-gapped networks, totally cut off, with a special support contract from MS, etc. If anyone is still using it they clearly have nothing but disregard for any kind of rules (like all the XP ATMS still out there).
- dsfyu404ed 8y ago>Nobody should be using XP. Not even on air-gapped networks, totally cut off, with a special support contract from MS, etc. I think you're severely over-estimating the criticality of stuff that's still running XP. It's mostly used for antiquated industrial hardware that gets used 5x a year, maybe (old CNC mills and whatnot), often times with no network. If it gets crypotwalled via flash-drive then someone will reinstall it and carry on with life.
- close04 8y agoMore accurately, current stats put XP at around 4-6% of the world's desktops. Only Windows 7, 10, and 8.1 beat it. That's more than Linux and more than any MacOS version (more than almost all all of them put together). That would be ~5 million XP machines, give or take. So we're talking about 5 million machines with an OS designed in the late '90s (20 years ago) and that stopped receiving any meaningful updates 4 years ago. Most of them are actually ATMs in developing countries like India and they are definitely not air-gapped [1]. The POSReady XP with the bare modicum of support until April 2019 made companies take it as a green light to keep using XP in embedded systems. Other systems running XP: many of the NHS systems hit by WannaCry last year, many of the systems in UK Police stations, most electronic voting machines and gas stations in the US, most digital signage in train stations, airports, hospitals, or cinemas, parking garage payment machines, so many POSes, even passport security in some airports! Does this put the magnitude of the problem in perspective? It's a threat from so many perspectives. Your safety, your data, your money, you name it. [1] https://www.rbi.org.in/scripts/NotificationUser.aspx?Id=11311&Mode=0 https://www.rbi.org.in/scripts/NotificationUser.aspx?Id=1131...
- iknowverylittle 8y agoSo, what's AMD doing these days? I'm hesitant to switch to AMD since Intel internal graphics play nicely with Linux. However that kind of doesn't matter if my machine isn't mine.
- std_throwaway 8y agoAMD has the PSP which basically is the same thing. But we don't know for sure what either one does.
- mrsteveman1 8y agoOne thing the PSP doesn't have is AMT style remote management. AMD has their own kind of management system available on some machines (DASH, using "smart" NICs like Broadcom), but the PSP isn't even involved when DASH is available and in use, as far as I know. However, on my Intel machine with AMT, there's a network port opened by the ME itself (TCP/16992). It can use the same IP as the main OS, or a different IP entirely if desired. It uses the same ethernet port as the main OS though, splitting the packets that are directed to one of the ME ports and selectively allowing the rest to continue to the main OS (there's a low-level ME firewall[1]). On that port, there is a full remote desktop with mouse and keyboard, the ability to remotely connect small drives and/or ISO files, a remote serial console, a low level firewall configuration utility, and power/reboot controls. Even on machines where AMT is not even supposed to be available, there have been PoC demonstrated using one of the ME flaws to turn it back on[2]. [1] https://i.imgur.com/Wphopk1.jpg https://i.imgur.com/Wphopk1.jpg (slide 68) [2] https://www.blackhat.com/docs/eu-17/materials/eu-17-Goryachy-How-To-Hack-A-Turned-Off-Computer-Or-Running-Unsigned-Code-In-Intel-Management-Engine.pdf https://www.blackhat.com/docs/eu-17/materials/eu-17-Goryachy...
- iknowverylittle 8y agoYou know the shame of ME is that the concept and intended use isn't terrible and the engineering behind it is rather cool. It is however unfortunate how poorly Intel implemented it and essentially forced it onto personal systems that have no need for it to begin with.
- AndriiG2018 8y agoi think you are absolutely correct. It is faulty mostly unwanted, not properly test feature. Need to be re-called and replaced at Intel cost. Period.
- brian_herman 8y agoYeah man I forgot to post my usual website about management engines and laptops.... :( https://libreboot.org/faq.html https://libreboot.org/faq.html
- mtgx 8y agoIt's much worse than that. This "Intel patches" thing is a lie - or at least it doesn't mean that your systems are patched, which is what 99.9% of people reading such headlines believe happened. Intel only patches its own firmware, but it's normally up to manufacturers to update that firmware for devices. So most PC/laptops users really won't even see these patches. And I agree with your main point. For one of the more recent Spectre-class flaws, Intel basically said "it's third-party developers' problem to fix."
- cmurf 8y agoHow is this Intel ME CPU patch deployed and where does it actually go? Is there some tiny flash in the CPU itself where the Intel ME code resides? Or does the patch get deployed as part of a UEFI firmware update, but isn't actually part of UEFI firmware, and somehow the CPU can reach out and grab its own updates from UEFI?
- close04 8y agoUsually a separate patch, an ME firmware patch. The ME is physically located in the chipset but I'm not entirely sure where the FW resides, whether the chipset or a flash on the motherboard (sharing with the system UEFI/BIOS).
- Kliment 8y agoThe ME firmware lives on an SPI FLASH chip, on the motherboard. It can either be the same chip where the BIOS is stored or a separate one (which is often the case because two smaller chips cost less than one big one)
- close04 8y agoActually you're right. Since most of the analysis on the ME FW was done after dumping the flash from the physically removed clip on the motherboard. That might have been more difficult with a chipset embedded one.
- 8y ago
- zorkw4rg 8y agoMaybe someone could clarify some things, because I think the impression that I got from reading about this vulnerability is completely wrong. Isn't vPro just something in server hardware? At least the CPU, Mainboard and NIC all need to be certified/from Intel to support this? You could get the impression that every single computer with a Intel CPU is vulnerable to be hacked over the network. Which I really doubt. > I want them to disable that thing by default! When you say this is enabled by default, do you literally mean that they open up a HTTP server without you doing anything? I don't know much about the Intel ME but the things people are saying about it just seem totally unbelievable.
- woodson 8y ago> Isn't vPro just something in server hardware? It’s in most business notebooks (HP, Dell, Lenovo, etc.)
- bonzini 8y agovPro/AMT is the "consumer"/workstation version, the server implementation is based on IPMI, but the ME is present on all systems, even those without vPro at all.
- forapurpose 8y agovPro is branding for several related products. ME is a platform with its own CPU, memory and OS, on which applications can be run. One common application is AMT, which provides remote management services.
- tinus_hn 8y agoIt’s difficult to see the reason for including this on by default other than some conspiracy involving government agencies and a lot of money.
- westmeal 8y agoI've been thinking on this a lot as well. Could go either way as far as I'm concerned.
- majewsky 8y agoThere was a submission on the weekend which posited that ME was made mandatory because of lobbying from the content industry to implement copy protection that the OS cannot tamper with (HDCP etc.).
- deno 8y agoSo are they paying Intel to do that? How much? Why would Intel agree to that? Otherwise seems like a convenient cover for the aforementioned conspiracy theory…
- fao_ 8y agoBuy an X200, install libreboot, and you won't have an ME anymore :)
- _emacsomancer_ 8y agoAnd let Intel know that you and your business won't be buying new Intel machines until they provide a way of completely disabling/removing the ME chip.
- blitmap 8y agoAs I understand it, ME is used to remotely control the processor like in a datacenter. If a datacenter is buying hundreds of thousands of these it makes sense to have it on by default so their people don't have to go in and turn anything on. As much as I recognize it as a vulnerability (to the extreme), it doesn't make sense to have it off by default. They should certainly support a way to _permanently_ disable it. I wish there were easy tools to verify ME is "not accessible" since I don't work in a datacenter and I wouldn't know how to test that it's off. Things that come with great benefit to risk for abuse: - Intel ME - Computrace - Device Guard
- philjohn 8y agoIIRC AMD allows their PSP to be disabled via the BIOS.
- IntelMiner 8y agoSome do. Though it's unclear what that does yet
- floatboth 8y agoIt definitely prevents the OS from accessing it over PCI, but whether it prevents the PSP from accessing the OS is indeed unclear.
- emsy 8y agoTheir motivations are irrelevant. Consumers aren't datacenters.
- monocasa 8y agoYou do use it. AFAIK, the ME handles power management, legacy backwards compatibility, and all sorts of other random chipset stuff you don't necessarily want to expose to the main cores, in addition to the DRM and remote administration capabilities.
- solarkraft 8y agoBut why can't I disable the remote administration capabilities?
- monocasa 8y agoYou can. It's disabled on any non vpro system. It takes two exploits on a non vpro system to exploit the ME remotely: the first exploit running on the main cores to reenable the remote administration, and the exploits listed here for once it's enabled.
- valgaze 8y ago(2017) You might be able to: https://www.csoonline.com/article/3220476/security/researchers-say-now-you-too-can-disable-intel-me-backdoor-thanks-to-the-nsa.html https://www.csoonline.com/article/3220476/security/researche... https://github.com/ptresearch/unME11 https://github.com/ptresearch/unME11
- ta45737272742 8y agoAgreed; none of this even passes the smell test to me, it seems absurd to bundle this level of functionality and not have a big warning on the can: "You are not really in control of your machine, at all." I wouldn't have purchased my last Intel chip with better knowledge of this junk side-loaded, full-access, completely-opaque OS, made by a company incredibly thick with our mates in the 5 Eyes etc.
- ryanlol 8y agoThe vulnerable components are off by default. It's very strange that most comments here suggest otherwise.
- r00fus 8y agoME is the vulnerability. It's like a branch in your code that does an escalated execution of any input. Yes it's good to put a fence and prevent it but the better route is to excise the logic from your code base completely.
- gboudrias 8y agoI hope the bad PR from ME garbage follows them to their corporate grave. It's absolutely shameless.