Intel ME's Undocumented Manufacturing Mode Suggests CPU Hacking Risks

Karadjgne

Titan
Ambassador
Intel is the Big Dog on the block, has been for a while. Even had claims of 90% of the internet being run by Intel processors at one point not so long ago. Of course it's the target for such specific hacks trying to find back doors. And everyone has them, even Apple did. They are there. But Ryzen is still pretty new and is not yet fully established in business applications, won't be for a while, until ppl upgrade. That leaves Intel. Most ppl running amd are still using FX processors and haven't updated yet, and really, it's a pretty sad waste of time trying to hack an FX user. It's the same as Microsoft. Most ppl run a version of Windows, so guess who gets hacked. You can hack Linux just as easy, but what's the point, not enough users to make any real splash in the headlines.

Amd only looks better because either hackers aren't bothering, or those that are just haven't found the security lapses yet.
 
Its a shame that intel did this, but one has to also consider AMD. Although there hasn't been specific research published or public about AMD's equivalent to ME, fact of the matter is that it exists, and thus, the similar possibilities for exploits on AMD's platforms as well. That said, it might be better executed or less vulnerable than Intel's.
 
Oct 4, 2018
1
0
10
AMD's PSP is quite different (and simpler) from Intel's ME which controls everything, networking included. And it's very simplistic to assume that vulnerabilities are not being found because "hackers aren't bothering".
 

Christopher1

Distinguished
Aug 29, 2006
666
3
19,015
I will be totally blunt: This should not be enabled in the damned first place on customer systems. As soon as all testing is done, a special daisy version that it is known that this functionality is disabled should be pushed out for customers.
This is a failure in the extreme by Intel, by Microsoft, and by the computer manufacturers.

Congress, if you are reading this? Do a hearing on this subject and lambaste those three levels of companies for this stuff.