How to Hack a Turned-Off Computer, or Running Unsigned Code in Intel ME
blog.ptsecurity.com
blog.ptsecurity.com
[dupe] https://news.ycombinator.com/item?id=16015539 (543 points, 107 comments)
HN user saulrh mentioned that the list of requirements "does not seem incredibly unusual" for enterprise setups with AMT on.
Pre-Meltdown/Spectre this was 2017's "big deal" re:Intel; nearly all of the varying degrees of paranoia in the previous discusson seem a lot more reasonable with the benefit of hindsight. (If any more AMT info has become available thanks to Meltdown/Spectre-enhanced reverse engineering I would appreciate a heads-up; example vs SGX: https://github.com/lsds/spectre-attack-sgx)
Intel needs get their act together or remove this features entirely. Clean it up.
Yikes. That’s the first I’ve heard of this. It’s terrifying that even exists as an option, given how much of a strategic military benefit it provides to whoever can pull Intel’s strings.
call me a conspiracy theorist if you like but i'll bet you dollars to donuts wireless powerless remote management exploits exist in the wild for these intel chips.
and by wild i include state-owned in there
edit: if you have one of these chips you can disable the feature in bios
From what I understand (I'm not well-informed though), those security flaws stem mainly from carelessness by Intel. So this would assume AMD acts equally careless, which may or may not be true.
In engineering terms, the bugs are "errors and omissions" not carelessness or negligence. Errors and omissions arise because humans are fallible and engineering is a human process.
One of the features of Intel (and AMD) products is that their primary customers are data centers and that's where the core CPU design parameters come from (not consumers or developers). The consumer/developer SKU's are little more than repackaging and feature tweaking of the chips that Intel/AMD sells datacenters in high volume on 1-3 year cycles. That's what drives the roadmap five+ years out.
I don't believe it's been explicitly denied either, but I also don't find software that leverages deployments using PSP (or, Secure Processor, as it's now known) unlike what I find for Intels ME/AMT.
All indicators point to them focusing on it as a Trusted Execution Environment, similar to secure enclave.