Hacker News new | past | comments | ask | show | jobs | submit login

If you're talking about the Management Engine, doesn't AMD have basically the same thing just called PSP?



Possibly. The Intel version is better publicised. I have no idea what PSP can do, but Intel's IME makes it possible to remotely completely override anything about a PC, which can be convenient for sysadmins for large organisations, but hasn't been disabled for consumer products.

I have no idea whether the same is true for PSP.


AMD supports KVM redirection, too, via a standard called DASH. You can see examples at https://community.amd.com/community/devgurus/dmtf-dash/blog. From the standard body's description: "DASH provides support for the redirection of KVM (Keyboard, Video and Mouse) and text consoles, as well as USB and media, and supports the management of software updates, BIOS (Basic Input Output System), batteries, NIC (Network Interface Card), MAC and IP addresses, as well as DNS and DHCP configuration. DASH specifications also address operating system status, opaque data management, and more." https://www.dmtf.org/standards/dash

Intel's AMT is also an implementation of DASH.


The extensive research on the ME I actually conside a pro for Intel, since I know more about what it does and how to disable it. The PSP is still more of a black box.


The remote management features in Intel ME require a vPro capable chipset.


To be useful to you, usually yes.

To be a convenient security hole, AFAIK no.

Any quotes on ME being safe on non-vPro?


It's still a security risk – code is running in the ME that can be exploited locally.

Without vPro or with remote management and the network stack turned off there's a much smaller (probably close to zero) remote attack surface. With a vPro-capable chipset that has remote management enabled, the ME has its own IP address, plenty of potentially unsafe services, an insecure-by-default provisioning mechanism and much more.




Consider applying for YC's Spring batch! Applications are open till Feb 11.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: