4 ms·
Isn’t this vulnerability based on AMT, which is based on ME but disabled by default? Even then, every setup I’ve seen have AMT (a separate Ethernet interface) b
by yzmtf2008 8y ago
Isn’t this vulnerability based on AMT, which is based on ME but disabled by default? Even then, every setup I’ve seen have AMT (a separate Ethernet interface) behind a firewall and is only accessible via local network. The outrage is hardly justified.
- rainbowmverse 8y agoOne day it's "[thing] shouldn't be exploitable because [mitigation]", the next it's "welp, [mitigation] has a bug in it and they've exploited [thing]."
- yzmtf2008 8y agoRight, and the network security is always part of the attack surface of an enterprise. What I’m saying, though, is that the component that’s vulnerable is 1) disabled by default and 2) near impossible for a consumer to enable.
- achillean 8y agoThere are close to 5,000 devices exposing their Intel AMT to the Internet: https://www.shodan.io/report/j3cFHOzs https://www.shodan.io/report/j3cFHOzs
- yzmtf2008 8y agoThere are X thousand redis servers exposed to the Internet too. This is hardly intel’s fault (having the ports exposed, not the vulnerability). And again, this is not the main point I’m arguing. What I’m saying is that supposedly “this is something that’s enabled by default on consumer devices” is verifiably wrong.
- achillean 8y agoIf you run Redis on a public interface without authentication then it will spit out a bunch of warnings and make you aware of the security implications. The changes antirez has made to Redis both in terms of secure defaults and notifying users of insecure settings has directly lead to a huge reduction in Internet-exposed Redis instances. And I was trying to address this point: > Even then, every setup I’ve seen have AMT (a separate Ethernet interface) behind a firewall and is only accessible via local network. In the past, manufacturers used that defense when a security researcher approached them about a problem and they justified the lack of patching by saying things like "nobody would put this on the Internet". There are simple things a manufacturer can do to encourage good security by the end-user (ex. showing a warning). I don't believe that blaming the end-user is a viable path to fixing the problem. This issue isn't specific to Intel but I would prefer it if the vendor implemented more security safeguards to prevent users from inadvertently increasing their attack surface.
- yread 8y agoHow many honeypots are there?