Because the fallout will cost billions over the next years. Intel as a company due to class-action lawsuits, recalls, rebates, and the shareholders because the drop in stock value after the announcement will cost them quite a chunk of money.
In addition, more long-term, I sincerely hope that the cloud vendors (and maybe even Apple!) recognize that their total dependence on Intel (and NVIDIA in deep learning...) is bad and they need to diversify their base.
It gets even worse when you consider the incentives of private/academic/third party researchers to search for bugs, since there is a lot less prestige in catching a bug in a smaller/less well known product. e.g. I'm pretty sure no white-hat security researcher has checked for security problems in the cheap wifi light switches I bought on Amazon.
But there's a much smaller attack surface and the incentives for attackers are significantly changed. Homogeneity is always more vulnerable to disaster, whether we're talking about food supply or chips.
At least having the option of another vendor as a fallback (e.g. in case there's a severe RCE vulnerability in ME/PSP) is a better alternative than having to shutter your entire business.
I would not be surprised if these management engines have a backdoor that can be invoked from a guest VM... and then an all-Intel (or all-AMD) shop has a massive problem.
This is the core question: is this isolation absolutely perfect, or can it be pierced in any way? Something on a severity level like Spectre/Meltdown - people would have laughed you off the stage half a year ago when you told 'em you could read kernel memory from Javascript without exploiting both the browser and the kernel - is IMHO certain to be present in either of the "management" solution, and I'd like to be prepared when the bomb explodes.
No isolation is perfect but and that is an important but for virtualization you have much higher control over what instruction you allow through so an attach which is specific to ME isn’t likely.
That said you can have a side channel attack that allows you to compromise the hypervisor and from it you can jump to the ME but this is a different story.
But isn't this also applicable to the other side? As in, black hats have less incentives to research vulnerabilities in less popular products (security through minority). I'm not certain how this balances out.
The aerospace industry has realized this a long time, and for some things they will have 3 different devices from 3 different vendors doing the same job
That being said, even though I don't think it's the case here, greed has been known to make people do some very stupid things.
If one wants to be truly cynical, you could say he has been expecting something like this all the time and cashing out to ensure his money isn't tied to Intel. I am inclined to being slightly less cynical - I'd say he has been just cashing out regardless of the the company's performance.
0: https://www.bloomberg.com/view/articles/2018-01-05/citi-forg...
Doubtful. Intel has a near monopoly in data centers in 2017. They will have a near monopoly in data centers in 2018 and 2019 I predict as well.
Really very few things they can do to lose their business at this point.