![]() ![]() On many Intel chips, the Management Engine is shipped with the AMT module installed. Unless that happens, we are concerned that it may not be appropriate to use Intel CPUs in many kinds of critical infrastructure systems. EFF believes that Intel needs to provide a minimum level of transparency and user control of the Management Engines inside our computers, in order to prevent this cybersecurity disaster from recurring. This post will describe the nature of the vulnerabilities (thanks to Matthew Garrett for documenting them well), and the potential for similar bugs in the future. ![]() While AMT can be disabled, there is presently no way to disable or limit the Management Engine in general. ![]() Last week, vulnerabilities in the Active Management (AMT) module in some Management Engines have caused lots of machines with Intel CPUs to be disastrously vulnerable to remote and local attackers. All of the code inside the ME is secret, signed, and tightly controlled by Intel. The ME is a largely undocumented master controller for your CPU: it works with system firmware during boot and has direct access to system memory, the screen, keyboard, and network. Since 2008, most of Intel’s chipsets have contained a tiny homunculus computer called the “Management Engine” (ME). ![]()
0 Comments
Leave a Reply. |
AuthorWrite something about yourself. No need to be fancy, just an overview. ArchivesCategories |