You patched the Intel AMT vulnerability. Right? RIGHT?????

You patched the Intel AMT vulnerability. Right? RIGHT?????

Other urls found in this thread:

downloadcenter.intel.com/download/26755/INTEL-SA-00075-Detection-and-Mitigation-Tool?product=23549
libreboot.org/faq.html#amd
downloadcenter.intel.com/download/26799/INTEL-SA-00075-Linux-Detection-and-Mitigation-Tools?product=23549
arstechnica.com/gadgets/2016/02/intel-to-shut-down-renegade-skylake-overclocking-with-microcode-update/
theregister.co.uk/2017/05/01/intel_amt_me_vulnerability/
twitter.com/NSFWRedditVideo

downloadcenter.intel.com/download/26755/INTEL-SA-00075-Detection-and-Mitigation-Tool?product=23549

If you have a Thinkpad, you're vulnerable.

not having problem with my ryzen 1700 :^)

I "patched" it from the patch given by Lenovo, but that's all that it's worth. It's like putting a bandaid on an open wound - just superficial.
I really should bite the bullet and go with coreboot and wipe ME, but three things so far are holding me back: the hardware required, the fact that there appears to be an existing issue with wiping ME that causes slow boot, and the fact Coreboot doesn't support the USB 3.0 chipset (I have an i7 X220).

AMD has the equivalent of Intel's ME, called AMD PSP. All modern x86 platforms contain hardware-level rootkits - enjoy!
>libreboot.org/faq.html#amd

Nope fampai

No, don't want to flash a new bios and have no possibility of installing a nonshit wifi card

The T60p does not have the vulnerability. Best laptop wins again.

¯\_(ツ)_/¯

...

>using a botnet cpu

BOTNET

It's also piss-poor slow. I can barely decode high-bitrate 1080p on my X220 with medium mpv config. Don't even want to imagine this.

>windows

720p 10bit usually works. 1080p does not

"Normal" 720p/1080p files are no problem

>Using a cpu with NSA backdoors

Linux version

downloadcenter.intel.com/download/26799/INTEL-SA-00075-Linux-Detection-and-Mitigation-Tools?product=23549

seems ok

So what now?

>MEI
are you fucking retarded using this?

>T60p does not have the vulnerability
idiot..

no because I don't believe in vulnerabilities. nothing was vulnerable but the people who patched were fooled and downloaded a backdoor.

hahaha
u mad?

This.

>You patched the Intel AMT vulnerability. Right? RIGHT?????
Didn't need to. Server motherboard master race.

Risk Assessment
Based on the analysis performed by this tool, the tool was unable to detect ME or SMBIOS information to assess vulnerability.

Explanation:
The tool did not receive a valid response when requesting hardware inventory data from your computer. Please contact your system manufacturer for assistance in determining the vulnerability of this system.

>installing microcode from intel
enjoy
arstechnica.com/gadgets/2016/02/intel-to-shut-down-renegade-skylake-overclocking-with-microcode-update/

I never did, but apparently I'm safe.

delet

The first Thinkpad with AMT was the T61

AMT firmware is separate from the BIOS

$ sudo ./INTEL-SA-00075-Discovery-Tool

INTEL-SA-00075-Discovery-Tool -- Release 0.8
Copyright (C) 2003-2012, 2017 Intel Corporation. All rights reserved

Error: No such file or directory (null)
Cannot establish a handle to the Intel(R) MEI driver. Refer to Tool User Guide for more information.

What is this and why should I be concerned?

Linux is also vulnerable

How do you install the updated firmware from Lenovo on Linux?

Why would Lenovo support a toy operating system?

Why would lenovo patch a backdoor on NSA/Windows? It's like taking a glass of water out of the ocean.

lenovo doesn't support linux
you literally have to bend over backwards to install BIOS updates because they assume everyone has windows and if you "happen" to not have windows, better hope you have an optical drive, because their updates are PC-DOS era bootloader monstrocities that simulate a disk drive image and require specialized extraction tools and a grub boot entry just to run on your machine.

what isn't a botnet these days?

Am I vulnerable? My intel mobo is from 2006.

Turion is the epitome of "ayyyymd house fire".

no, because i wasn't retarded enough to buy a botnet cpu to begin with

Correction:
Everything is vulnerable

It's almost as if having an indipendant cpu that works as a backdoor is a bad idea

exactly

No because I'm CyrixInstead

you have other problems like defecating in public areas

I use a Mac so I don't have to worry about viruses.

...

>If you have a Thinkpad, you're vulnerable.
haahahahah, lelnopevovo cucks on suicide watch
Elitebooks win once again

retarded/10

pedo/10

How do I patch this?

I have an x220t on Ubuntu 16.04. It says I'm vulnerable. Wat do

Is this a problem if I disabled ME in my bios years ago?

Lol dumb windows pleb

>Basically, if you're using a machine with vPro and AMT features enabled, you are at risk. Modern Apple Macs, although they use Intel chips, do not ship with the AMT software, and are thus in the clear.

theregister.co.uk/2017/05/01/intel_amt_me_vulnerability/

No. That doesn't fix this issue.

No, the hardware is vulnerable, it's OS-independent. But Windows is a vulnerability in and of itself.

JUST

I used Windows PE. Followed the Arch wiki, except made a writable image instead of an ISO. From there, you need to boot up PE, load hardware-appropriate HECI driver provided by Lenovo, and finally install the patch.

Thanks. You just reminded me I have a Win 10 partition that I haven't used in half a year. Guess I finally have a reason to boot into it

>Why would Lenovo support a toy operating system?
Sadly because Windows is still necessary for some people.

how much ram do u have on that x220

lenovo fags on suicide watch

Shit like this is why I use mac

Not him but I'm having performance issues on my x220t and am looking to upgrade some of the components that might be bottlenecking it. What are good RAM and SSD choices for this aging machine? Are there any decent replacement batteries? Anything else I could potentially upgrade to speed this thing up that I haven't thought of? Oh, and it needs a new keyboard. Where should I buy one of those?

there's already a patch out
if you don't have a small windows partition still you're an idiot who deserves it

only reason I asked him was because I upgraded my x220 from 4gb of ram to 16gb and it made all the difference in the world

no more hangups, no more typing lag, its just fast, doesn't even need an SSD

I would recommend getting at least 8gb.

I have my AMD trusted computing disabled, that's as far as I can go

or just know how to maintain your computer instead of just throwing more resources at the problem

>if you don't have a small windows partition still you're an idiot who deserves it
Why would I care about having an Intel backdoor on my computer when I have a massive microsoft backdoor on my computer?

If lenovo is shit, what brands are good?
I've been looking around and everything looks pretty bad. System76 would be good if their keyboards weren't complete ass and they supported libreboot.

4GB isn't enough for a browser with a ton of tabs, IDE, web server, modern DE, etc., and when you couple it with a 5400rpm HD its even worse

>browser with a ton of tabs
I've never had a problem with 20 tabs. I don't see why I'd ever have more than that
>IDE
vim does not take up much ram. If you need anything else, you should not be programming
>modern DE
KDE takes around 400MiB or RAM

>------------------Vulnerability Status--------------------
>System is not Vulnerable, no further action needed.

I'm good.

>using AMT
Lol

I'm not American.

you're an idiot you know that?

kys

That's a crock. Even with all of that I never get close to full ram usage.
You don't know how to remove bloat, get over it.

>proving him right
PAJEET

What the fuck. I downloaded the thing from and when I go to run it, nothing visible happens. There's an exe running that I can end, but that's about it. On the second attempt, I noticed it says it's from an unknown publisher. Have I been duped? How do I get to the screen like OP's?

>switch to windows and install firmware
>neither detection tool changes its output
>both just assume based on the version since they can't seem to check well enough
fucking intel

I'm not running anything I'm not using

pic related. installed fine. gui just isn't visible

it's only a vulnerability when you boot into it. compatibility and so on outweighs the risk if you barely use it.

I couldn't care less

If you're not using a ryzen-powered system, you're doing it wrong.

If you boot to it, how do you know it's not writing a backdoor into your bootloader?

>AMD
libreboot.org/faq.html#amd

Downside is some systems simply won't ever get patched to this vulnerability, like my Latitude E6420 with a Core i7-2640m since the tool points out that it's vulnerable.

Oh well, shit happens, life moves on.

Open psp code is open sourced, all your worries will vanish

get fucked lmao

Wrong, it's just not open source

>Open psp code
iwouldliketoknowmore.face is this recognized by fsf?

and here. It eventually came up. Took a while and didn't appear to be doing anything in that time. I'd honestly forgotten I ran it without ending the task.

Apparently the only way to install the patch is as a BIOS update.

Um, I have a ryzen sweetie

>not a threadripper

It's too big for me

Bless

I installed the MSI. Didn't do anything else though. Was that all I needed to do?

Plebs. I use a libreboot thinkpad x60 with a core 2 duo that has neither the AMT or the ME.

not having this problem with my fx8350