Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Interesting that the ME region can be even partially overwritten and will still let the system boot, albeit with an error (guessing a checksum mismatch)...


Ah ... reading further down the thread its explained and is even more interesting: https://www.coreboot.org/pipermail/coreboot/2016-September/0...


> along with the fact that the ME will sync it's internal clock with NTP servers across the internet once every 30 days

Wow. This is part of the processor?


The Management Engine, think of it as running at Ring -1. It can access hardware below the level of the processor. Injecting malware into it would be the holy grail for attackers, it would be impossible for anything running on the CPU to detect it and the malware would have access to all of the low level hardware. It can even intercept or create packets on the network interfaces.

Luckily the implementation is obscure so it has perfect security, right? There's no way such a complex piece of software that has had very little oversight could have exploitable bugs that would completely destroy any security foundations you have on your machine.


> It can even intercept or create packets on the network interfaces.

And appears to be built to do so out of the box by default with no "specialized code". I'm guessing with both wired and wireless interfaces... crazy!


My next question is (and it's probably mentioned further in the thread or manual somewhere): how does the ME chipset route traffic to the Internet in the first place? Piggyback off the OS? Does this mean it's directly coupled with the networking devices on the system somehow? Presumably it will work with any OS....


AMT requires Intel NICs for that reason.


So could you neutralize its communication functions (to a degree) by using a non-Intel NIC? Would a non-chipset Intel NIC accomplish the same thing?


but it still needs and IP address right? Does ME does its own DHCP/BOOTP configuration or does it rely on some other protocol specific to Intel NICs/Intel infrastructure?


The AMT component must be specifically configured with network information. It is usually kept on a different interface from that used by the OS for security reasons.


"chipset" I think.


What are the odds that NSA already has the source of ME and can infect it like they can infect HDD ROM?


What are the odds that it was put there at their request, or partially specified by them? After all, the clipper chip never went anywhere, but neither did the desire.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: