Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Will this do?

"Additional major security flaws in the ME affecting a very large number of computers incorporating ME, Trusted Execution Engine (TXE), and Server Platform Services (SPS) firmware, from Skylake in 2015 to Coffee Lake in 2017, were confirmed by Intel on 20 November 2017 (SA-00086).[39] Unlike SA-00075, this bug is even present if AMT is absent, not provisioned or if the ME was ‘disabled’ by any of the known unofficial methods.[40] In July 2018 another set of vulnerabilitites were disclosed (SA-00112).[41] In September 2018, yet another vulnerability was published (SA-00125).[42]"

https://njnewnjnew.medium.com/management-engine-interface-dr...

https://www.theregister.com/2017/12/06/intel_management_engi...

It does make me wonder what else has been missed.

We have such elaborate means to deceive one another. Perhaps, one day, we will be good enough that it is no longer necessary. But that is not today.



> Will this do?

Sorry to be a stickler, but not really.

The citation indexed [40] (that is, the relevant portion) in your quote points to the Register article you also linked, just as the Wikipedia entry does in support of the statement:

"Unlike SA-00075, this bug is even present if AMT is absent, not provisioned or if the ME was "disabled" by any of the known unofficial methods."

That being the case I would expect the Register article to contain something that bolsters the quote above but if it does, it is so subtle as to escape my repeated rereading.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: