Intel ME's Undocumented Manufacturing Mode Suggests CPU Hacking Risks

Positive Technologies (PT), a Russian security company that has discovered multiple bugs in Intel’s Management Engine (ME) over the last couple of years, this week revealed more details about Intel’s “Manufacturing Mode” for ME, saying it can expose users to remote hacking. This is the second undocumented mode in Intel ME that PT has found in recent years.

Contributor

Lucian Armasu is a Contributing Writer for Tom's Hardware US. He covers software news and the issues surrounding privacy and security.

  • PellehDin
    AMD is looking better and better for my next build.
    Reply
  • acme64
    amd has trustzone
    Reply
  • Karadjgne
    Intel is the Big Dog on the block, has been for a while. Even had claims of 90% of the internet being run by Intel processors at one point not so long ago. Of course it's the target for such specific hacks trying to find back doors. And everyone has them, even Apple did. They are there. But Ryzen is still pretty new and is not yet fully established in business applications, won't be for a while, until ppl upgrade. That leaves Intel. Most ppl running amd are still using FX processors and haven't updated yet, and really, it's a pretty sad waste of time trying to hack an FX user. It's the same as Microsoft. Most ppl run a version of Windows, so guess who gets hacked. You can hack Linux just as easy, but what's the point, not enough users to make any real splash in the headlines.

    Amd only looks better because either hackers aren't bothering, or those that are just haven't found the security lapses yet.
    Reply
  • TCA_ChinChin
    Its a shame that intel did this, but one has to also consider AMD. Although there hasn't been specific research published or public about AMD's equivalent to ME, fact of the matter is that it exists, and thus, the similar possibilities for exploits on AMD's platforms as well. That said, it might be better executed or less vulnerable than Intel's.
    Reply
  • derekullo
    Intel ME reminds me of Windows ME.

    Automatically making it sound bad.
    Reply
  • rantoc
    So where to forcefully disable ME, its just adding headaches. No wonder why clever companies like Google is working towards that end!
    Reply
  • ein4rth
    AMD's PSP is quite different (and simpler) from Intel's ME which controls everything, networking included. And it's very simplistic to assume that vulnerabilities are not being found because "hackers aren't bothering".
    Reply
  • Christopher1
    I will be totally blunt: This should not be enabled in the damned first place on customer systems. As soon as all testing is done, a special daisy version that it is known that this functionality is disabled should be pushed out for customers.
    This is a failure in the extreme by Intel, by Microsoft, and by the computer manufacturers.

    Congress, if you are reading this? Do a hearing on this subject and lambaste those three levels of companies for this stuff.
    Reply