4 ms·
The last Intel security bugs made them lose a lot of the reputation they had, at least amongst system adminstrators though. Now is a crucial time for AMD to st
by Iv 7y ago
The last Intel security bugs made them lose a lot of the reputation they had, at least amongst system adminstrators though.
Now is a crucial time for AMD to strike back.
- mcv 7y agoThis and their Minix backdoor are the reasons why I wanted an AMD for my laptop, but I was sad I couldn't find a high-end Thinkpad with AMD processor. I hope that will change next year.
- snvzz 7y agoWhy call it minix backdoor? It puts some blame on minix, yet minix is blameless here. Minix is an excellent FOSS microkernel multiserver OS with a focus on reliability and fault tolerance. The way Intel is using it just isn't nice.
- mcv 7y agoI'm not blaming it on Minix, but it does make use of Minix. I'm mentioning it to identify what I'm talking about. I believe the official name is Intel Management Engine. Or maybe that's just part of it.
- snvzz 7y agoIntel ME is the name I usually see, and also the name that the tools to remove/disable when possible do reference.
- soulnothing 7y agoT495 Zen+ A485 Zen X395 Zen+ The 5 at the end denotes an AMD product. I'd hold out for after CES though. That's when Zen2 is coming to laptops. With thinkpad lag I'd say August of next year.
- tgsovlerkhgsel 7y agoIf you're talking about the Management Engine, doesn't AMD have basically the same thing just called PSP?
- mcv 7y agoPossibly. The Intel version is better publicised. I have no idea what PSP can do, but Intel's IME makes it possible to remotely completely override anything about a PC, which can be convenient for sysadmins for large organisations, but hasn't been disabled for consumer products. I have no idea whether the same is true for PSP.
- lima 7y agoThe remote management features in Intel ME require a vPro capable chipset.
- labawi 7y agoTo be useful to you, usually yes. To be a convenient security hole, AFAIK no. Any quotes on ME being safe on non-vPro?
- lima 7y agoIt's still a security risk – code is running in the ME that can be exploited locally. Without vPro or with remote management and the network stack turned off there's a much smaller (probably close to zero) remote attack surface. With a vPro-capable chipset that has remote management enabled, the ME has its own IP address, plenty of potentially unsafe services, an insecure-by-default provisioning mechanism and much more.
- solarkraft 7y agoThe extensive research on the ME I actually conside a pro for Intel, since I know more about what it does and how to disable it. The PSP is still more of a black box.
- 7y ago
- xodice 7y agoAMD has the same "Secure Enclave". AMD PSP; "AMD Platform Security Processor". :(
- Tsarbomb 7y agoNot with the Directors of those system administrators though. Nobody got fired for buying Intel is a thing. I had to fight to get our recent server purchases to be AMD.
- Newtonip 7y agoWhat were the arguments you were getting against buying AMD?