Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Intel ME is frequently featured here on HN, but the general population is completely clueless.

This is quite possibly the worst and most widespread computing vulnerability that has ever existed, and it's likely that Intel will just maintain the status quo until there's some sort of black swan event.



Worst vulnerability ever? AMT has to be enabled, attacker has to know AMT password, BIOS password and BIOS has to be misconfigured. I understand clickbait hyperbole and appeal to emotions are good for getting eyeballs but lets keep some perspective. Remember heartbleed, conflicker or blaster?


ME is running regardless of those things.


But not vulnerable. This is like saying a local root exploit is the Worst Vulnerability Ever in a system that was correctly firewalled from its earliest implementations.

"Worst" implies harm, not just potential. It doesn't get to be The Worst until something happens, no matter how much it offends your personal design sensibilities or confirms your conspiracy priors.


Sorry, but "running but not vulnerable" is not nearly good enough nowadays. This means that a real exploit (e.g., via yet another insert-your-favorite-spooky-agency tool leak) can be quickly scaled to a large fraction of computers worldwide.

If you are saying that when assessing the vulnerabilities, potential harm is not important, only actual is, would you feel that putting remotely activated bombs on all planes is not a major vulnerability as long as no one has a password?


You're talking past me. It's an important flaw. It should be fixed where possible. It should be mitigated where not possible.

It's not remotely The Worst Vulnerability Ever and any attempt to hyperbolize in that direction is hurting the efforts of the people actually trying to protect you.


I think you're right it's not remotely The Worst Vulnerability Ever. Personally I'm a bit worried that we're just one exploit away from it being that in the future though. :/

I usually like to include a metaphor to explain the equivalence as I see it, but I'm struggling to come up with any other thing where we've built in a problem like this that's waiting for a single event that could effect nearly everyone. The closest I can come up with is Snow Crash, and having to reach that far into science fiction leads me to think we likely have a poor grasp on how to assess this risk (since we as a species are fairly bad at assessing and mitigating risk for events we haven't encountered before). Hopefully it's just an extreme failure of imagination on my part.


The backdoor code that a user, who bought the hardware, cannot shut down is a major flaw. It is, IMO, far from The Worst Vulnerability Ever, but it is a flaw that the manufacturer is not inclined to address; in fact, it is seeing this as a feature.

Thus advocacy, including overstating its impact, is likely the only option for those who want it changed.

> any attempt to hyperbolize in that direction is hurting the efforts of the people actually trying to protect you

Can you clarify this -- who are those trying to protect us and why do they want this mis-feature to stay? Are you talking about spooks who use this as a backdoor in their own cyber attacks? If so, this IMO only adds urgency to the need to close this backdoor -- such tools often leak and backfire.


>Sorry, but "running but not vulnerable" is not nearly good enough nowadays.

What does that mean practically? What you said applies to every networked device and tech. All routers, all computers, all OSs, all voip phones, etc, etc are 'one vulnerability away'. from total compromise.


Normally you only run things if you think they are useful, and you are cognizant of the risk.

It's very hard to avoid running ME even if you believe it's actively harmful.


That is a good point. I suppose you could mitigate that if you were building new systems and used AMD products.


AMD has its own equivalent of ME also.


How do you know that AMD does not run its own version of ME?

The only viable solution I see is open hardware.


Mitigation does not necessarily mean to entirely protect. Having less of a homogeneous ecosystem mitigates the risk of any one vulnerability, as it's unlikely to affect as many systems. It's not a solution, but it may help.


What does viable mean? Where can I go out and purchase it? Yes, hypothetically, anything is possible.


viable == introspectable


1. You have no idea if it's vulnerable or not. For starters, you don't have the source code and nobody you trust has seen it. You would have to take Intel's word that "disabling" it actually works, and hope that there is no other vulnerability Intel doesn't know about.

2. It doesn't have to be "vulnerable" to be used in an attack; it's essentially designed to be an attack. So any government agency or leaked Intel info may be sufficient to abuse.

3. You can't reliably check/audit if it is being exploited or not since it runs at a higher privilege than any diagnostics you might try to run on your own computer.

Disclaimer: I am not an expert in computer security.


"This is quite possibly the worst and most widespread computing vulnerability that has ever existed."

The problem is to make that true, you have to carefully phrase the situation as "this has the potential to give rise to the worst, bad .... etc".

And that's the thing. Ignoring this ranks along attitudes like "that cement pool of mining tails right above town is quite sturdy", "we just need a little time to reduce our carbon emissions..." and "we shouldn't kill the IoT with too much regulation..." etc

If X isn't a problem right now!, then it seems like X is going to get about zero attention from a world swimming in things that are a problem right now.

And that too is going to give rise to further problems down the road, to say the least.


> Intel will just maintain the status quo until there's some sort of black swan event.

I absolutely hate Intel and AMD for sabotaging their customers like that. Please people, get to that black swan event ASAP.


If we're unlucky, the 'black swan event' will be something along the likes of Pluto's Kiss. Imagine a Morris worm equivalent, but which bricks the computers it infects after destroying the filesystem.

Even if everyone has backups of everything, offline, it'll be years before all the destroyed computers can actually be replaced. This isn't a scenario I want to happen for real.


On the plus side, you can probably guarantee it would only ever happen once.


Haha, no, you can't. Since when do humans learn from their mistakes?


Not infrequently, but it's in vogue to hold the belief that they don't.


You could do some much more interesting things with a hack than wiping and bricking a bunch of computers, even if the bricking part is doable.


As a note, the latest AGESA for Ryzen seems to have the ability to turn off the PSP, it is showing up in some of the latest beta bios releases.

No official statement yet, but some info can be had here: https://www.phoronix.com/scan.php?page=news_item&px=AMD-PSP-...


"BIOS PSP Support disabled" is the only statement we have, in the form of a new option in the BIOS Setup.

That sounds like the equivalent of "HECI Disabled" for Intel BIOSes, which has been around for years.

It doesn't do anything to shut down the hidden CPU (PSP). It just sends a command to disable the bridge over to the main CPU. All the other ways of talking to the PSP remain open.


ASRock support says it disables CPU <-> PSP communication. https://www.reddit.com/r/Amd/comments/7j2i8f/asrock_replies_...


I also hate Intel and AMD for that, but I think they'd prefer we didn't hate them. I conclude that there are big reasons to still do what we hate them for. I'm afraid even a black swan event wouldn't make those reasons go away.

What I think needs to happen is for other countries to realize this issue is a matter of national security, and to fund development of alternatives.


They don't care at all if we hate them, because we're still buying their chips en masse.


Well, I will not buy an Intel CPU anymore. I also try to avoid Intel in all other chip classes like networking chips where Intel is suspiciously active. Sometimes I wonder if their name is giveaway that people just don't realize. Soon I intend to move to an Intel-free single board computer for my day-to-day computer usage. Now, for other people I can't speak.


Yes, but I don't think it's a black swan if you're waiting for it.


True, but I meant for all of those who aren't prepared for or aware of this issue.


> Intel ME is frequently featured here on HN, but the general population is completely clueless.

That's what they want: a backdoor advertised as a feature.


What is harmed most directly by publicizing Intel ME vulnerabilities?

Is it in the interest of this entity to restrict the publication of Intel ME vulnerabilities to the general public?

How does the general public obtain information on a day to day basis?

Who runs the mass media?

Is the mass media affected by this entity?

Is the mass media narrative influenced by this particular entity?




Consider applying for YC's Fall 2026 batch! Applications are open till July 27.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: