Re: [qubes-users] Intel ME exploitable
On Mon, 1 May 2017, 'Lolint' via qubes-users wrote: > Confirmation by Shintel: > https://downloadmirror.intel.com/26754/eng/INTEL-SA-00075%20Mitigation%20Gu > ide%20-%20Rev%201.1.pdf So it requires either network connection to an ME aware NIC or, unsuprisingly, access to some local HW interface of ME (that is used by LMS that is a Windows thing). It's somewhat doubtful that such HW interface would be available for other than dom0 under Qubes. Thus it doesn't sound too bad, except for laptops with any kind of wireless wired to ME (wired NICs need not to be connected - ever, use USB device for providing ethernet instead if you want to avoid this kind of issues). -- i. -- You received this message because you are subscribed to the Google Groups "qubes-users" group. To unsubscribe from this group and stop receiving emails from it, send an email to qubes-users+unsubscr...@googlegroups.com. To post to this group, send email to qubes-users@googlegroups.com. To view this discussion on the web visit https://groups.google.com/d/msgid/qubes-users/alpine.DEB.2.20.1705020031160.18054%40melkinpaasi.cs.helsinki.fi. For more options, visit https://groups.google.com/d/optout.
Re: [qubes-users] Intel ME exploitable
Confirmation by Shintel: https://downloadmirror.intel.com/26754/eng/INTEL-SA-00075%20Mitigation%20Guide%20-%20Rev%201.1.pdfhttps://downloadmirror.intel.com/26754/eng/INTEL-SA-00075%20Mitigation%20Guide%20-%20Rev%201.1.pdf -- You received this message because you are subscribed to the Google Groups "qubes-users" group. To unsubscribe from this group and stop receiving emails from it, send an email to qubes-users+unsubscr...@googlegroups.com. To post to this group, send email to qubes-users@googlegroups.com. To view this discussion on the web visit https://groups.google.com/d/msgid/qubes-users/tSXLoJvyyEDdBtL6zdZ4leYPp6Ar5jEpbkx4pO2jFfQlzozE5zfWdPjQ6-aCESh9zDb0pq_C9lBV5LIf_gwds80eRVcRcs2Jvu_AfNjXnG0%3D%40protonmail.com. For more options, visit https://groups.google.com/d/optout.
Re: [qubes-users] Intel ME exploitable
On 05/01/2017 12:38 PM, Jean-Philippe Ouellet wrote: I want my RISC-V laptop already! I would agree, but these things are still quite slow... correct? I think they are lacking in out-of-order execution and SIMD, for example. A good benchmark for performance might be something like the last of the PowerPC CPUs (G5) which is a different RISC-type architecture. -- Chris Laprise, tas...@openmailbox.org https://twitter.com/ttaskett PGP: BEE2 20C5 356E 764A 73EB 4AB3 1DC4 D106 F07F 1886 -- You received this message because you are subscribed to the Google Groups "qubes-users" group. To unsubscribe from this group and stop receiving emails from it, send an email to qubes-users+unsubscr...@googlegroups.com. To post to this group, send email to qubes-users@googlegroups.com. To view this discussion on the web visit https://groups.google.com/d/msgid/qubes-users/22ec6e8c-eba6-943d-2531-2ea6f7cc27ec%40openmailbox.org. For more options, visit https://groups.google.com/d/optout.
[qubes-users] Intel ME exploitable
*Sigh*... Yep. We were right to be concerned (of course). And now we have something other than our tin foil hats to point at too: https://semiaccurate.com/2017/05/01/remote-security-exploit-2008-intel-platforms/ I want my RISC-V laptop already! -- You received this message because you are subscribed to the Google Groups "qubes-users" group. To unsubscribe from this group and stop receiving emails from it, send an email to qubes-users+unsubscr...@googlegroups.com. To post to this group, send email to qubes-users@googlegroups.com. To view this discussion on the web visit https://groups.google.com/d/msgid/qubes-users/CABQWM_AtFXSAE3r03x5nDugT5JYTaX9kh2MXGE11bZan95Aa2g%40mail.gmail.com. For more options, visit https://groups.google.com/d/optout.