4 ms·
The vulnerability where no authentication was required and could be exploited wirelessly while the machine was off is directly relevant to the security model of
by user6723 3y ago
The vulnerability where no authentication was required and could be exploited wirelessly while the machine was off is directly relevant to the security model of anyone with a laptop with an Intel CPU.
I have been responsible for keeping small fleets of laptops patched and I actually read the relevant CVEs Intel puts out, which if you bothered to do you would find that yes over the years there has been an endless stream of fatal 0days
- charcircuit 3y ago>is directly relevant to the security model of anyone with a laptop with an Intel CPU. I assume you are talking about INTEL-SA-00075. To quote "This vulnerability does not exist on Intel-based consumer PCs with consumer firmware." This vulnerability was responsibly disclosed to Intel and there was a security update made that patched it along with mitigation instructions in case your motherboard manufacturer did not create an update. Security bugs and security updates are just a matter of reality. Anyone managing a fleet of computers needs to make sure that the whole fleet is getting security updates for any software that is running on it. This isn't a problem exclusive to the Intel ME. If this was instead was implemented as an OS driver it would still be a critical vulnerability that would need to be patched. >over the years there has been an endless stream of fatal 0days I believe INTEL-SA-00075 is the only ME related vulnerability that was rated as critical. I am not seeing all of these fatal 0 days that you are talking about.
- user6723 3y ago>> "This vulnerability does not exist on Intel-based consumer PCs with consumer firmware." Yet it did exist on computers used by senators, lawyers, executives, everyone I mentioned. Consumers are not the high value targets. >> This vulnerability was responsibly disclosed to Intel The vulnerability was uncovered and well known of by very many private espionage teams for a very long time. If this wasn't already obvious to you then your view of the world is too sheepish and naive to meaningfully participate in discussion about this kind of topic. >> I am not seeing all of these fatal 0 days that you are talking about. Those of us in the offensive security space see vulnerabilities that could be exploited "locally", anywhere where bad code could get running on the ME as critical too. Getting SYSTEM or root (the former being easier because of that OS' particular culture) is generally easier than it should be. Intel ME makes it a much bigger problem than it otherwise would have to be. While you most likely are not, you come across as a shill.