Free Republic
Browse · Search
General/Chat
Topics · Post Article

Skip to comments.

New Security Flaw Hits Intel, Laptops this time
Guru3d.com ^ | 01/12/2018 06:01 PM | Hilbert Hagedoorn

Posted on 01/12/2018 10:50:57 AM PST by Ernest_at_the_Beach

F-Secure has reported another serious flaw in Intel hardware, which could enable hackers to access corporate laptops. Standard password of Intels Management Engine BIOS Extension are rarely changed and can invoke business laptops vulnerable to unauthorized remote access, claims F-Secure. 

Intels Management Engine BIOS Extension, or MEBx, contains the standard log-in combination 'admin', 'admin' and because many users simply do not change it, according to F-Secure this opens the door to an easy to set-up attack. Attackers can open the BIOS Extension during startup with Ctrl + P, even if the user has set a bios password. Then they can manage settings of the Management Engine, reports dw.com.

"The issue potentially affects millions of laptops globally," said F-Secure consultant Harry Sintonen, who discovered the flaw. "It's of an almost shocking simplicity, but its destructive potential is unbelievable."


TOPICS: Computers/Internet
KEYWORDS: corporatelaptops; intel; interprocessors; security
Some links at the website for more info
1 posted on 01/12/2018 10:50:57 AM PST by Ernest_at_the_Beach
[ Post Reply | Private Reply | View Replies]

To: Ernest_at_the_Beach; Swordmaker

Ping!...................


2 posted on 01/12/2018 11:01:56 AM PST by Red Badger (Road Rage lasts 5 minutes. Road Rash lasts 5 months!.....................)
[ Post Reply | Private Reply | To 1 | View Replies]

To: Ernest_at_the_Beach

admin /admin. Seems legit.


3 posted on 01/12/2018 11:04:16 AM PST by Noumenon (Irony: Those who tell us we don't need a border wall whIle living in gated communities.)
[ Post Reply | Private Reply | To 1 | View Replies]

To: Ernest_at_the_Beach
None of these things are "flaws", they're all subtle backdoors that companies were told they'd include in their products way back when Algore was pumping the Clipper Chip. Clinton made it clear that any company not willing to play ball with the government wouldn't get one cent of government business and would be under constant close surveilance by the IRS and every other arm of the government that could be brought to bear.

All the big players agreed so the Clinton admin backed down on their drive for the Clipper Chip.

4 posted on 01/12/2018 11:06:30 AM PST by Rashputin (Jesus Christ doesn't evacuate His troops, He leads them to victory !!)
[ Post Reply | Private Reply | To 1 | View Replies]

To: Ernest_at_the_Beach

Yes, that is exposure, but unless someone has physical access to the machine, not really a big deal. This won’t be an issue just from grabbing some malware.

And of course, those who are concerned can change the password. I understand that some important people use p@ssword.


5 posted on 01/12/2018 11:07:51 AM PST by Dr. Sivana (There is no salvation in politics.)
[ Post Reply | Private Reply | To 1 | View Replies]

To: Red Badger

“once an attacker had the chance to reconfigure AMT (for which he would initially need physical access to the device in question)”

Pro tip: Don’t give you PCs or other devices to cyber criminals to monkey with.


6 posted on 01/12/2018 11:08:24 AM PST by LouieFisk
[ Post Reply | Private Reply | To 2 | View Replies]

To: Dr. Sivana

“I understand that some important people use p@ssword.”

“asdf” and “12345” works for me!


7 posted on 01/12/2018 11:09:26 AM PST by LouieFisk
[ Post Reply | Private Reply | To 5 | View Replies]

To: Noumenon

Change the BIOS password at your peril if you change it and lose or forget it and have to get into the BIOS you are screwed but good.


8 posted on 01/12/2018 11:10:54 AM PST by gibsonguy
[ Post Reply | Private Reply | To 3 | View Replies]

To: Dr. Sivana

[[I understand that some important people use p@ssword]]

I’m smart- I use p@zzword

Oh darn it- forget i just said that


9 posted on 01/12/2018 11:11:56 AM PST by Bob434
[ Post Reply | Private Reply | To 5 | View Replies]

To: LouieFisk

And be careful where you drop it off for service.


10 posted on 01/12/2018 11:14:29 AM PST by Ernest_at_the_Beach
[ Post Reply | Private Reply | To 6 | View Replies]

To: gibsonguy

I don’t mess with that for good reason.


11 posted on 01/12/2018 11:24:10 AM PST by rdl6989
[ Post Reply | Private Reply | To 8 | View Replies]

To: LouieFisk
“asdf” and “12345” works for me!

"1-2-3-4-5"?!

That sounds like the password an IDIOT would have on his luggage!

(note to self: change password)

12 posted on 01/12/2018 11:48:01 AM PST by thulldud ("What makes it news is its dissemination, not its concrete reality." -- Ellul)
[ Post Reply | Private Reply | To 7 | View Replies]

To: Ernest_at_the_Beach

ah, so was that the huge update I had today?


13 posted on 01/12/2018 12:50:04 PM PST by huldah1776 ( Vote Pro-life! Allow God to bless America before He avenges the death of the innocent.)
[ Post Reply | Private Reply | To 1 | View Replies]

To: Rashputin

Backdoor with a Democrap in the White House: Good

Backdoor with a Republican in the White House: Bad

I see how it works.


14 posted on 01/12/2018 12:53:52 PM PST by Buckeye McFrog
[ Post Reply | Private Reply | To 4 | View Replies]

To: Dr. Sivana

Government does not have a problem getting to anyone’s machines if they want to.


15 posted on 01/12/2018 1:09:42 PM PST by Secret Agent Man ( Gone Galt; Not averse to Going Bronson.)
[ Post Reply | Private Reply | To 5 | View Replies]

To: Buckeye McFrog

You got it. Give yourself a little gold star.


16 posted on 01/12/2018 2:25:55 PM PST by Rashputin (Jesus Christ doesn't evacuate His troops, He leads them to victory !!)
[ Post Reply | Private Reply | To 14 | View Replies]

Disclaimer: Opinions posted on Free Republic are those of the individual posters and do not necessarily represent the opinion of Free Republic or its management. All materials posted herein are protected by copyright law and the exemption for fair use of copyrighted works.

Free Republic
Browse · Search
General/Chat
Topics · Post Article

FreeRepublic, LLC, PO BOX 9771, FRESNO, CA 93794
FreeRepublic.com is powered by software copyright 2000-2008 John Robinson