Name Email
https://www.extremetech.com/computing/262031-researchers-found-another-major-security-flaw-intel-cpus

>Tl;DR: AMT is remotely vulnerable via default passwords

Tech was right again!

Sorry I keep posting ET; they're just my favorite site

No.851879

Intel is fucking dumb. I'm buying a used PPC Mac on ebay and throwing my Intel shit in the bin. Fuck this.

No.851880

Is it at all possible to remove an Intel CPU from a thinkpad and replace it with something made by AMD? Is there anything made by AMD that's compatible? Or should I just figure out how to get Linux running on my GameCube (PowerPC + ATI graphics)?

No.851889

>>851880

Well you can try PlayStation as well, it's AMD CPU and GPU, and fairly decent performance for modern age.

No.851890

>>851880

The second choice is your best bet, but based on the sheer and utter retardation of your first question you probably won't be able to pull it off.

No.851904

>no text dump

>not even an archive

>Tech

I'm sick of doing work for shitty OPs.

>Security researchers have pinpointed another major security hole in Intel processors, in addition to the security holes in the Intel Management Engine and the Meltdown flaw that hits Intel CPUs uniquely hard. This time, it’s an issue with Intel’s Active Management Technology (AMT), a feature typically reserved for systems that support Intel vPro or workstation platforms with certain Xeon CPUs.

The Intel AMT is designed to allow administrators to access and update PCs, even if those PCs are turned off. All they need is an internet connection and a wall socket and they can be updated. That’s a useful tool for large multinational firms with far-flung employees, but it’s also a potential security risk. F-Secure has published information highlighting how easily an attacker with even brief local access can gain full access to an entire machine. Here’s how they describe the problem:

>A BIOS password normally prevents an unauthorized user from making low-level changes to a device. However, the essence of this issue is that even when a BIOS password has been set, an attacker does not need it to configure AMT. Not only that, due to insecure defaults in the BIOS and AMT’s BIOS extension (MEBx) configuration, an attacker with physical access can eﬀectively backdoor a machine by provisioning AMT using the default password. The attacker can then access the device remotely, by connecting to the same wireless or wired network as the user. In certain cases, the assailant can also program AMT to connect to their own server, which negates the necessity of being in the same network segment as the victim.

>In short, setting a BIOS password won’t help and once someone has access, you can’t kick them out. The researchers note that no other security measures, including local firewalls, BIOS passwords, anti-malware software, or use of a VPN can prevent a compromised system from leaking data, because it’s been compromised outside of the Windows environment, in a separate OS that’s completely shielded from any attempt to inspect or control the data flowing out of or into it.

>From here, the possibilities are endless. Even firmware-based malware can be easily uploaded to the system with no chance of detection. And while local access might seem a tough barrier to crack, it’s not as hard as it seems. The changes can be made in under a minute, according to F-Secure. It may not be the kind of attack that gets deployed across thousands of systems on a corporate local network — at least not without additional steps — but it’s exactly the kind of targeted attack a government agency might use. And more to the point, it illustrates that Intel CPUs are once again vulnerable to set of management capabilities that Intel decided to sandbox entirely from the primary operating system.

>Once this is done, the attacker can connect to the system if he’s on the same local area network or program AMT to enable Client Initiated Remote Access (CIRA), which will connect to the attackers’ servers and avoid any need for local access at all.

>Not a great look on a company that’s already being hammered by other security flaws. Intel’s entire rationale for keeping so much of its security infrastructure locked away looks less and less like the principled decision of a company keeping us safe and more like a desperate attempt to cover just how badly it treats security. Because folks, look, this is not a sophisticated attack. This is not some crazy idea. In fact, it’s one of the first things I would expect an attacker to try, if said person had even a basic concept of what functions like AMT and the Intel Management Engine can be configured to do.

https://archive.fo/qRWSz

No.851909

>>851890

>The second choice is your best bet

Neat. I need to go find the GameCube's broadband modem on eBay, then.

>but based on the sheer and utter retardation of your first question you probably won't be able to pull it off.

I'll refrain from asking such stupid questions in the future.

No.851911

>>851904

It's worth emphasizing that this is a local-only exploit (at least initially) and it can be mitigated by accessing the AMT and changing the password. Chances are nobody here will be directly affected by it, and it continues the merciless nightmare for Intel and especially their management engine, so cheers all around for /tech/.

No.851916

>>851880

Unfortunately there are no Ryzen Thinkpads yet. Soon.

No.851923

>>851911

Please /tech/ does nothing but post shit about the work other people do.

No.851956

>>851909

>go find the GameCube's broadband modem on eBay, then.

<muh etherent > wifi

You can just use a usb etherenet adapter which you should be able to find fairly cheap.

No.851966

AHAHAHAHA

No.851972

>>851880

>Is it at all possible to remove an Intel CPU from a thinkpad and replace it with something made by AMD?

If it's newer it probably has a soldered-in CPU, if it's older then you'd need to replace the main board in your device. Basically you'd be better off buying an AMD laptop of your choosing.

>Or should I just figure out how to get Linux running on my GameCube (PowerPC + ATI graphics)?

PowerPC after late 2005 is vulnerable to Spectre, so having a Gamecube as a desktop would be no better than having an AMD box; in fact since IBM has had problems patching their POWER chips, it might be worse since that seems to be going smoother for Team Red. However, certain G3 and G4 Apple devices are practically immune to these security flaws due to peculiarities in their design, but they are a decade old so be aware of performance tradeoffs going into a transition to those devices. See >>851512

No.851974

>>851880

>>851972

Also, as an addendum, while Gamecube is older than the G3's and G4's linked above, it's a 400-500MHz processor and would be difficult to use for daily tasks, if you can even get anything running on it. I was thinking more along the lines of the Wii, which IS modern enough to support a desktop system with some success but would have the post G5 PPC Spectre vulnerability. Either way, PPC consoles are unlikely to have any patches issued for Spectre.

No.851979

>>851889

The PS4 CPU is weak as fuck and its PCI bus is bridged behind an ARM chip. Don't buy one for casual jailbreaking or you're in for a world of pain.

No.852010

>>851866

Again, nobody tells if it "works" on macbooks and other apple hardware. WTF is it too hard?

No.852012

>>851904

>The Intel AMT is designed to allow administrators to access and update PCs, even if those PCs are turned off. All they need is an internet connection and a wall socket and they can be updated. That’s a useful tool for large multinational firms with far-flung employees, but it’s also a potential security risk.

"Potential security risk." Let's call it what it is: a fucking backdoor.

Why is this garbage even sold to home users who don't need or want it? Is it because NSA are the admins now?

Y'all niggers better start boycotting. Don't worry about Intel going out of business though, they still make CPUs for the military. This is just about letting them know you don't like being assraped, speaking to them in the only language they understand: money. BOYCOTT INTEL.

No.852015

>Somehow this is Intels fault

/tech/ -LARPNiggers

No.852016

>>851866

>AMT exploit

This is in addition to the one found last May?

https://www.intel.com/content/www/us/en/architecture-and-technology/intel-amt-vulnerability-announcement.html

>On May 1, Intel published a security advisory regarding a critical firmware vulnerability in certain systems that utilize Intel® Active Management Technology (AMT), Intel® Standard Manageability (ISM) or Intel® Small Business Technology (SBT). The vulnerability could enable a network attacker to remotely gain access to business PCs or devices that use these technologies. Consumer PCs with consumer firmware and data center servers using Intel® Server Platform Services are not affected by this vulnerability.

I think not since the article you cite links to the following:

>On May 1, Intel published a security advisory regarding a critical firmware vulnerability in certain systems that utilize Intel® Active Management Technology (AMT), Intel® Standard Manageability (ISM) or Intel® Small Business Technology (SBT). The vulnerability could enable a network attacker to remotely gain access to business PCs or devices that use these technologies. Consumer PCs with consumer firmware and data center servers using Intel® Server Platform Services are not affected by this vulnerability.

No.852017

>>852015

>switch off Remote Management or change password makes you safe.

BIOS password and settings are irrelevant to an exploit of AMT.

No.852019

>>852012

>ge even sold to home users who don't need or want it? Is it because NSA are the admins now?

Yes.

>Y'all niggers better start boycotting.

This.

No.852026

>>851974

>Wii, which IS modern enough to support a desktop system with some success but would have the post G5 PPC Spectre vulnerability

Are you sure about that? The CPU is based on the G3 architecture.

No.852032

>>852026

Not him, but I posted here before that you can easily run Debian (Whiite Linux) on a Homebrew'd Wii with IceWM and even Dillon as the main web browser fairly well as long as you had ample SWAP space, which I just had dedicated to a USB flash drive

Would still never use it as a daily driver though. But it was a nice little novelty nonetheless.

No.852035

>>852032

that flash drive isn't going to live long

No.852039

>>851866

X86 is such a steaming pile of botnet shit it needs to die.

No.852041

>>852039

Its really pathetic that you spam this shit in multiple threads. Begone LARP Goblin

No.852050

>>851879

I'm right behind you anon.

https://youtu.be/Qp8yxJHvxuo

No.852099

>maxed out stats for atleast muh maximum performance

>just werks

<now on suicide watch because old CPUs are said to be slowed down the most

Do I just keep deferring all updates from now on? I don't want 50% performance drops. I'm on Core2Duo at the moment...

No.852101

>>852039

Why do you care? Is somebody forcing you to use x86?

No.852106

>>852101

My boss. A lot of big orgs use proprietary software that only x86.

Sucks a massive dick, but there's not really a convenient way around it.

So, on another note, are there any CPU architectures that aren't a steaming file of shit?

No.852107

>>852106

So why do you care about that? You don't own those computers do you? What your employers decide to do with their business ought to have zero effect upon your personal life.

No.852109

>>852107

Actually, it is my personal computer. I won't get into why - it's a long story.

But, regardless, we also FORCE clients to use some of this software in order to communicate with us. I've also had to deal with clients where they've forced me to use software that is OSX only.

The fact of the matter is that in the real working world, compromise is necessary. It's hard to escape this. Not only are we in debt to (((them))) by way of usury and fractional reserve banking practises, but they've placed their brackets all around Silicon Valley too.

No.852110

>>852109

() parentheses

[] brackets

{} braces

Learn the difference, it might save you face

No.852111

No.852112

>>852111

>implying programmers gives one hot fuck damn about what English majors with too much time on their hands define a bracket to be

No.852114

>>852112

>implying that non-programmers refer to brackets as parentheses

Regardless, you completely dodged the rest of my post.

No.852117

>>852110

This post is correct. Only my fair lady tier bongs call them all brackets.

No.852126

>>852114

>you completely dodged the rest of my pos

I'm not the same person you were replying to. Why the fuck doesn't /tech/ use poster id's anyways?

No.852132

YEAR OF THE RISC-V DESKTOP CPU FUCKING WHEN

No.852135

File: 3c04f4f4494c1fe⋯.jpg (52.72 KB, 500x375, 4:3, burn it all.jpg)

>>852132

The general purpose desktop as we know it needs to die. Say good bye to Windows and Linux both. We're going to have to start using the video game console model, everything compartmentalized and specialized and locked down to a strict set of supported hardware so that it can be optimized as much as is humanly possible with absolutely no room for "a complete standalone OS embedded into the CPU for the purpose of remote code execution and spying".

No.852138

>>852135

>absolutely no room for "a complete standalone OS embedded into the CPU for the purpose of remote code execution and spying".

o i am laffin

No.852139

>>852112

>implying normal people gives one hot fuck damn about what programmers with too much time on their hands define anything to be

No.852140

>>852135

What's better than one big botnet?

EVEN MORE BOTNETS!

Drawn yourself.

No.852141

>>852140

And if they're specialized and compartmentalized you can just remove them, you double nigger.

No.852145

>>852141

And after that you can finally drawn yourself, because you have exactly 0 hardware and 0 software to work with that isn't botnetted you fucking idiot.

No.852146

>>852145

>he gets mad at other people for not using botnetted hardware and software

No.852163

>>852135

*SPIES ON YOU*

Oh Jesus Christ in heaven!

No.852164

>>852163

Where do faggots like you even come from anyways?

No.852165

>852163

>reddit spacing

No.852170

>>852012

It's gonna keep happening if you still a class collaborationist.
Stop being a retard

Stop being a retard

No.852180

>>852146

It's okay lainon. One day they will see the light.

No.852187

>>852135

>implying nu-consoles don't have their own super sekrit mario management engine embedded inside the audio codec/USB controller/GPU etc.

No thanks, I'd rather a no-frills libre motherboard standard every piece of consumer desktop HW is strictly required to follow.

No.852200

>>852012

>several low functioning autists on /tech/ boycott Intel

>Intel lose a couple of thousand in potential sales

>military, government and large corps still buy Intel

The dent in their profits is going to be undetectable. Indistinguishable from noise.

trannyboardownersuckingdick.mp4

x86 has always been shit.

By 2020 the plan is to have BIOS removed. So you couldn't even write a self-booting disk/usb stick if you wanted.

The worst home computer architecture won the battle in the 80s. Now it's fully infiltrated and controlled.

It turns out open source software was a red herring. Linux was a distraction. No degree of security or autonomy over a Win10 user. The hardware was fully backdoored long ago. The compilers, including gcc are now nearly fully backdoored. If you're still using x86 for anything but jerking it and checking the weather you're a fool.

No.852329

>>852327

>No degree of security or autonomy over a Win10 user

Wrong.

>If you're still using x86 for anything but jerking it

One of the most intimate and publicly embarrassing, sometimes incriminating information there is. What else am I going to keep secret? My Stallman folder?

No.852333

>>852327

>By 2020 the plan is to have BIOS removed.

The BIOS has a lot of legacy bloat. It should be removed and replaced with something more lightweight.

No.852335

>>852333

s/The BIOS/x86/

No.852349

>>852170

FROGGED

No.852358

>>852327

Well at least SPARC is alive again.

https://www.theregister.co.uk/2017/09/19/oracle_sparc_m8_solaris/

Maybe someday RAPTOR will actually ship their POWER9 workstations also.

No.852364

>>852358

they'll ship around the same time star citizen does. atleast if you give them 10 grand you get a cool jpeg and an interactive model

No.852372

>>852358

i couldn't even afford a stick of ram for that

No.852378

>>852358

>>852358

>8 32 core 4 ghz procs with 8 TB RAM

No.852499

>>852237

Fucking hell.

No.852711

>>852327

>The compilers, including gcc are now nearly fully backdoored.

Everybody go and read Reflections On Trusting Trust again. This anon has, obviously.

No.852732

>>852327

>It turns out open source software was a red herring. Linux was a distraction.

Linuxes were good until 2010 then suddenly went to shit due to systemd, Grub2, touchscreen DE's and other things. KDE and Gnome also went to shit.

>No degree of security or autonomy over a Win10 user.

Be serious. Admittedly Windows can be hardened better than Linux. At least Windows firewall lets you block specific programs and not just ports for one thing. The 1980s called, they want their Gufw back.

>The hardware was fully backdoored long ago.

True, proof is Intel ME and similar crap we know of.

>The compilers, including gcc are now nearly fully backdoored.

For this claim do you have proof? "Nearly fully backdoored", as in "nearly full of shit"? Proof (file, line of code, refusal to patch, disassembled compiler) or it's opinion. I remember that VS2015 has some stupid telemetry crap that it adds to what you build, but that's been found out, fixed in VS2017 and GCC doesn't have that.

No.852734

>>852732

>Linuxes were good until 2010 then suddenly went to shit due to systemd, Grub2, touchscreen DE's and other things. KDE and Gnome also went to shit.

Linux is what, 8 million lines of code not including the user-space?

OpenBSD is 4 million, but that includes the user space and X.

TempleOS is 100000 lines of code.

Forth can be 1000 lines or less, with the ANSI standard dictionary.

No.852735

>>852732

>I remember that VS2015 has some stupid telemetry crap that it adds to what you build, but that's been found out, fixed in VS2017.

Not surprised that an openplacebotard would be so gullible.

No.852736

>>852735

>you're gullible

Insult attempt != argument. Proof please? No proof?

No.852737

>>852735

Not so fast, in current year Pajeets at MS are personally asking you why you Googled a specific framework and used it in your program instead of using MS's do-alike. There was a thread on this a while back.

No.852740

>>852737

Paranoia and rumor cheapens this thread.

Keep it tight with proof and shiet... so you're saying VS2017 still has telemetry added to user projects or what?

No.852741

>>852740

>Paranoia and rumor cheapens this thread.

>Keep it tight with proof and shiet... so you're saying VS2017 still has telemetry added to user projects or what?

LOL nice one, outing yourself so boldly.

This was covered here, the Pajeets had a log of what the programmer searched for. If you lurked you'd remember.

Lurk two years anon.

No.852742

>>852736

Gigabytes of proprietary software is impossible to audit or trust. You are a hypocrite for trusting it but denouncing free software like systemd. You just want to push people to proto-proprietary software like the BSDs or all the way to M$etc. No.852743 >>852742 >You are a hypocrite for trusting it but denouncing free software like systemd. Oh fucking please. Everybody knows systemd is pure cancer by now. It's larger than most historical OS's and subsumes much of their function. It's too big and swiftly-moving to be audited. Pretending that it's the only thing going on Linux is not going to get you anywhere here kid. No.852775 >>852112 >"this word is whatever I define it to be, and only that!" No.852863 >>852742 >implying systemd is possible to audit or trust >implying the extra freedom by MIT/BSD licenses is a Bad Thing(tm) >still no proof of VS2017 adding telemetry to user programs >>852741 >This was covered here, the Pajeets had a log of what the programmer searched for. Clarify because that's ambiguous. Searched for what, where? Searched the web page (the extension names) or his own open project (the code)? VS2017 IDE telemetry can be disabled (choose no participation in VS Experience Improvement Program from Help->Send Feedback->Settings) or at worst it can be firewall blocked. Firefox is no better off, check it. But I wasn't talking about VS2017 telemetry in the IDE however (and I'll laugh in your face when systemd adds telemetry of its own, enabled by default, in addition to leaking DNS to Google). I was talking about covertly adding telemetry stubs to user programs compiled with it, which VS2015 did but VS2017 doesn't do anymore... unless of course you have evidence to the contrary? Which I'd like to see? Pretty please? >>852743 >Everybody knows systemd is pure cancer by now. It's larger than most historical OS's and subsumes much of their function. It's too big and swiftly-moving to be audited. I have the following conspiracy theory and I'd like your opinion: what if systemd is designed as a secondary kernel and its only purpose is to increase the attack surface on all Linuxes that use it? Because it sure as hell isn't just an init system anymore. It's a high-level kernel now. If its purpose would be just to help user apps interface with Linux that would be an insult to Linux. So naturally I think its real goal is evil. No.852895 >>852863 >implying the extra freedom by MIT/BSD licenses is a Bad Thing(tm) The last MINIX convention got cancelled for lack of speakers, despite being inside every single AMT chip Intel-Aviv has sold for the past what, 15 years? This is what cuck licences do to projects. No.852896 >>852895 Minix has only been part of ME since 11.0 which I believe came out with Skylake. MIT/BSD licenses protects developers, but the GPL protects users No.852897 >>852896 >MIT/BSD licenses protects developers Ostensibly false No.852971 This is really depressing because I just built a very expensive Xeon server as a home lab :( No.853003 >an attacker with physical access to a machine can do bad things with it shoo-shoo, what a fucking surprise! breaking news everyone woo-woo No.853076 >>852896 Developers are also users, that's the whole point of the GPL. No.853085 >>853076 No, developers are not users. They are two distinct and different states. When you are developing you are not using. When you are using you are not developing. While a developer may at times be a developer and at other times be a user, he is never both at the same time. No.853095 >WE'RE UP TO FIVE MASSIVE INTEL EXPLOTS NOW And normalfags aren't aware of even a single one. Why haven't we been using this whole spectre shitfest to spread FUD? No.853098 >>853095 it was used pretty much to it's full extent. people don't care until their bank accounts are empty. No.853124 I tried pressing ctrl+p on my amt-enabled laptop (with tpm perma-disabled in bios) and nothing happened, what's missing? No.853128 File: 68d11709f6400a2⋯.jpg (252.24 KB, 1190x906, 595:453, e976f6f6bf1145ed4c87098eff….jpg) No.853131 >>853085 you are not developing allah is developing No.853196 File: e7c923836dd0d9c⋯.gif (1.75 MB, 500x283, 500:283, 1516060637702.gif) No.853306 >>851979 Didn't you hear him? He said PLAYSTATION. No.853439 File: 7f8c8e391d5837f⋯.jpg (6.3 KB, 180x228, 15:19, 8346aeb2c573f8a0951ed89bfa….jpg) so i guess this guy is basically fucked now right? the fbi can just use a spectre attack to break into his encrypted unpatched macbook. No.853623 File: 939c1119ae6d5cc⋯.jpg (128.71 KB, 1300x957, 1300:957, surprised-confused-funny-l….jpg) >>853085 So, what are developers using to develop the software users use? No.853625 >>852135 So a commie pc? No.853628 File: ca526a83e8dfc88⋯.png (302.21 KB, 906x509, 906:509, untitled.png) >>852266 Nope still gay No.853632 >>853625 No, more like a #2 Phillips screwdriver. A purpose built tool designed to restrict the user without restricting its use. Forget about PCs and say "Hallo" to the special purpose computing appliance. Imagine a painting tablet that only runs a single digital painting application, A technical drawing table that can only run a single CAD application, the IRS tablet that only runs your income tax form, a video cutting station that looks like an old film editing station and only runs a simple video editor, and a video FX station which only runs a selection of video processors, and electronic book that will only display a single ebook format, etc. pp. I don't agree with the post you replied to, that this will spell the death of the generic work station or home computer, but I do see this as a desirable future for consumer computing. It would solve all of the security problems and most of the usability problems with consumer computing. And it would put a clear barrier between "us", the people who actually create shit, and "them", the people who leach off our creations. No.853633 >>853632 To expand on the last sentence: It would be like the 70's again. When only the military, scientist, big corporations and nerds who really cared had computers. No.853639 File: 4cf94e5f9e2f9a9⋯.png (40.48 KB, 152x254, 76:127, YES.png) I keeps happening and getting worse. Year of AMD, maybe ? No.853643 No.854252 We just need more secu-crypto researchers looking for massive exploits. Then blackmail the said companies to remove such exploits otherwise threat them to crash the market by making the exploit public. You may also bluff if you like. >This kills the botnet The problem is they'll make even stronger botnet instead. No.854255 >>854252 Wat? Shit's just gonna get more bloated and full of bugs. Look at the shit languages they're pushing now, like Rust and Go. They're just excuses to write shit code and pretend the language will fix all problems. No you dense fuckers, only writing good, solid, simple code will fix anything. Terry Davis got the fucking message, and nobody else did apparently. So there's gonna be shitloads of botnet and bugs in the future. No.854263 Ideas >>853632 >>853633 I kind of agree with that anon. Multitasking was a mistake. How about cartridges? Stack: Cartridges (ROM) >games, software >CPU Cartridges (R/W) >operating systems >storage devices Hub (optional) >multi-monitor, multi-networking, multi-channel audio, etc. >connect/split peripherals, other hubs and catridges Peripheral1 (1 as in I/In) >keyboard, speakers, wifi >storage devices but not recommended Peripheral0 (0 as in O/Out) >HW: >screen monitor >cartridge and peripheral slot(s) >SW: >busybox-like with basic network stack - can be a cartridge slot if you want your own custom or hardened network stack or if you want none at all Cartridges in general are throw-aways. Makes it easier to discard the botnet. cons: >theoretically slower than mobo design >power is clusterfuck >standards will be a clusterfuck ^this idea is Public domain DO NOT PATENT No.854269 >>854255 >only writing good, solid, simple code will fix anything. Yeah, there's too many people out there born in the mid 70s. >So there's gonna be shitloads of botnet and bugs in the future. Just immune system at work. Good load off of my mind and x86_NSA_3PLA can go die finally No.854323 >>852012 >Why is this garbage even sold to home users who don't need or want it? Is it because NSA are the admins now? Yes, there is no other reason to add this to consumer CPU's in which 99 percent of the time won't be used, unless the NSA believes you're a journalist that needs to stop publishing information that it doesn't want you to publish. If you want to know something even more interesting there is a so-called ‘halt and catch fire’ instruction that was discovered inside Intel's' x86 processor. This instruction, executed in ring 3 from an unprivileged process, appears to lock the processor entirely. To rule out kernel bugs, the instruction was tested against three Linux kernels and two Windows kernels, yielding the same results. Kernel debugging with serial I/O and interrupt hooks appeared to corroborate the results. At the time of this paper’s publishing, the vendor has not been provided sufficient time to respond to the issue. If you would like to see all the undocumented x86 instruction sets your CPU has you can try it with sandsift here https://github.com/xoreaxeaxeax/sandsifter No.855063 >>853439 if the computer is still on they can dump characters from ram but that is about it. No.855245 >>853639 Trading one evil for another. POWER9 No.855265 >>853306 Yes, and only one Playstation console has AMD CPU and Graphics. The PS4. No.858224 >>852099 >old Thinkpad >left for dead by both Keknovo and driver OEMs >vulnerable ME: will never be patched >vulnerable AMT: will never be patched >vulnerable CPU (Meltdown/Spectre/Skyfall/Solace/JamesBond007WTFBBQ): will never be patched >vulnerable WiFi (KRACK): will never be patched >vulnerable Bluetooth (BlueBorne): will never be patched >assraping exploits for all of these will likely be released sooner or later by shadowbrokers or wlvault No.858233 >>852333 >The BIOS has a lot of legacy bloat. It should be removed and replaced with something more lightweight. You do realize it's going to be replaced by UEFI (which is orders of magnitude more bloated) and nothing else? No.858249 >>858233 UEFI is orders of magnitude more flexible in the bootstrapping process. Legacy assumptions about bootstrapping is done away allowing any number of features that BIOS backwards compatibility will not allow. It's also faster. No.858259 >>858249 Why is it so difficult to get a UEFI-compatible boot disk going? MBR is the easiest thing in the world. No.858263 >>858259 Proof of trust is a difficult concept. Turn off secure boot if you're having so much trouble. No.858266 >>858263 I think one of us is misunderstanding something. If I turn off secure boot, how will that make the UEFI partition a non-requirement? No.858271 >>858224 Not sure if people on /tech/ actually use thinkpads or if it is just a meme. Botnet and slow. What is the point? No.858273 >>858266 You're talking about the UEFI boot partition? I'm not sure what problems you have. Maybe I'm just lucky but it just works for me. No.858275 >>858271 Used Thinkpads are unusually cheap considering their specs and quality, and no more botnet than their contemporaries. They're shit in the ways all computers are shit, but they're pretty good compared to the alternatives. No.858278 >>858275 But aren't they 100% intel? Why would you want that? If your trying to be retro why not just get an old AMD laptop or PPC Powerbook? No.858408 >>858233 >You do realize it's going to be replaced by UEFI (which is orders of magnitude more bloated) and nothing else? Sadly yes. I don't understand why things have to get slower and more bloated overtime instead of less. No.858420 >>858278 If you want retro, get a Z80, 6502, or something of that era (except Intel). The AMD and PPC are probably pozzed too. I wouldn't trust anything past m68k tbh. No.858438 >>858420 >m68k 68k was the shit. If Carmack had started to write software for the Amiga instead of PC and if Commodore hadn'tt made all the blunders they in the early 90s, computing history could have played out much different than it did. No.858609 >>858438 Or if he managed to get away with stealing that Mac from school... No.858632 >>852112 >being literally autistic 😂 No.858677 >>851866 >Tl;DR: AMT is remotely vulnerable via default passwords learn what "remote" means first, skiddo >A BIOS password normally prevents an unauthorized user from making low-level changes to a device. However, the essence of this issue is that even when a BIOS password has been set, an attacker does not need it to configure AMT. Not only that, due to insecure defaults in the BIOS and AMT’s BIOS extension (MEBx) configuration, an attacker with physical access can eﬀectively backdoor a machine by provisioning AMT using the default password. keyword: physical in any case AMT is some homo shit that shouldn't even exist, and I knew this long before the skiddies started talking about it No.858760 >>858420 >not creating your own superior, super fast architecture by placing millions of transistors on a circuit board It's like you want to be cucked by the CIA No.858820 >>852200 >military, government and large corps still buy Intel You forgot normalfags. No.858826 >>852358 It was alive the whole time, Fujitsu never stopped making their own SPARC processors. They're expensive as fuck Big Iron stuff though. No.858890 >>852734 Forth is a programming language not an operating system. No.858914 >>858408 >I don't understand why things have to get slower and more bloated overtime instead of less. The same reason make-work exists: to provide an excuse for existing. Without this fake believe purpose in life, many bipedals would die out of sheer boredom. No.858919 >>851911 How exactly would one go about accessing the AMT? I never accessed this shit and recently lost my job so a new MB and CPU is out of the question. My BIOS is incredibly barebones and won't even let me turn off IME which is extremely unfortunate. At least I know what version it is! No.859344 >>851866 https://archive.fo/toZat https://techcrunch.com/2018/01/28/intel-reportedly-notified-chinese-companies-of-chip-security-flaw-before-the-u-s-government/ I'll just paste the title: Intel reportedly notified Chinese companies of chip security flaw before the U.S. government I'll check back with my relatives in the MSS PSB to see if they knew about it beforehand. No.859378 >>859344 Without jumping to conclusion, what do you think the reason for this was? It's a bigger country, more focused on cyber security because they are renown for having many cyber criminals, and obviously an important market to try and hold given their main competitor (AMD) is aggressive in the area already. Do you think they ordered their alert list based on something like liability, user count, user importance, and/or maybe something else or should conspiracy be assumed (I don't think so just yet)? No.859381 File: 4feee1908518c95⋯.jpg (1.6 MB, 1536x1929, 512:643, Jupiter-ACE_small_system_(….jpg) >>858890 It can, and has been used as an OS. Ditto with BASIC. No.859382 File: e432894c9d7d7cb⋯.jpg (33.46 KB, 640x480, 4:3, fujitsu-loox-uc30.jpg) >>851880 >Installing Linux on Gamecube Unless you like cutting your teeth on what is essentially a shitty PPC G3-tier CPU, I wouldn't recommend it. A saner alternative to this Spectre-Meltdown madness is to just get an old pre-2013 Intel Atom laptop/UMPC or Raspberry Pi 3 modded into a laptop. You can get a good netbook for ~$30 USD and a killer UMPC for ~\$130. Typing this from pic related running Void Linux.

>>851972

>2005

gamecube was made in 2001, faggot.

No.859384

>>859381

Wrong. Forth and BASIC are USERLANDS, not complete OS'. The Commodore 64 for example, actually had a level of abstraction between the kernel and BASIC interface, the "KERNAL" and the KERNAL in fact used its own separate ROM that people could bootstrap other interfaces to like JiffyDOS. In overall function however, many consider it closer to a BIOS found in IBM PCs

No.859386

>>859382

>A saner alternative

A saner alternative to all of this would be to stop using computers.

Computers were a mistake.

No.859395

>>853632

Frankly that sucks. Your world is completely throw-away. What needs to happen is all general computing devices (which is just about anything electronic now-a-days) must follow open standards or that the hardware must be open or else face a very hefty VAT.

No.859401

>>852032

>dillo

>"web browser"

No.859404

>>859384

Interestingly enough, the C64 RAM was actually 64K, but many areas of the memory map are occupied by ROM. However the 6502 is smart enough to know that you can't write to ROM, and redirects writes to the ROM area to RAM instead. You can then change the area the VIC][][ chip uses to a ROM-occupied area to use previously unusable area. This can for using the KERNAL area for video memory, for example. Unfortunately this means you cannot read screen memory.

No.859494

>AMD appeared to be justing their own shit all these years

>Actually they were doing opposition research

>Meanwhile, they gave their engineers all the time in the world to create the perfect CPU to JUST Intel's shit

>Release CPU in 2017

>Intel loses its shit

>Intel releases rushed 8core cpus

>AMD then begins leaking Intel design flaws

>Intel's fw

Where were you when Intel was slowly raped into bankruptcy over a whole year?

No.859495

>>859384

I already knew that, but the OS is a lot more than the kernel. That said, you can write a kernel in Forth at least.

No.859707

>>859378

Not sure. But this shouldn't happen considering the tense state of China-US relations after that HK guy was detained for spying. I wonder if it has to do with China making their dragoncore processors, or just flat out threatening to fuck into over a la google style.

My relative in the MSS said there wasn't anything that he knew of, so probably just shitty planning on intels part thats gonna get spun into, "Intel help the chinese fuck the US gov over!!!?!?!"

No.859715

>>859707

>All the results are related to Yu-Gi-Oh

>All results are related to Qualcomm Snapdragon ARM chips

I guarantee you exactly 0 chipmakers see dragoncore as any kind of threat.

Are you a Chink? Why do I continue to see you shill Loongson processors all over this board?

No.859723

>>859386

>Computers were a mistake.

That's a realization too late to make. If all computers became disfunctional right now, society would immediately collapse with niggers running amuck looting anything there is to loot etc.

No.859741

>>859715

Not shrilling. Just saying its possible although it's outsourced to fab in Germany so and a single core costs 1000USD roughly soo.....

>In other words its all talk no do like usual with the CPC

No.859834

>>859723

It's not a realization, it's just hyperbole. Intel was the mistake, any other choice was better.

You don't just fucking pick the worst ever architecture and then say all computers are a mistake. You picked the shit computers, now you got shit. That's how it fucking works.

No.859956

>>859834

IBM could have chosen Motorola instead of Intel, but didn't. John Carmack could have been working on Amiga and could have made his groundbraking 90s games for it, but didn't, and they became PC killer apps instead while the Amiga died. Oh well.

No.860009

>>859834

The bigger mistake was when Microsoft picked C instead of Pascal or PL/I. Segmentation was created specifically to improve high-level programming languages and the OS environment. The main problems with C are null-terminated strings, the flat memory model, and arrays that suck.

If you want to fix hardware and software, you have to dispel some myths.

1. Programming languages are too hard to understand unless they look like C.

2. There is no point in replacing C with anything unless it's gigabytes of garbage per second PajeetScript.

3. Languages without a GC like Fortran, Pascal, and Ada are not worth learning, so you should use slow PajeetScript which has a runtime written in C.

4. All problems can be solved by abstraction and throwing more hardware at it so there is no need to care about the lower levels.

This problem is not permanent unless you want it to be. I read on the Mill forums where he said he would have built a capability architecture but it wouldn't be able to run C programs, and I think that's sad.

https://wiki.osdev.org/Segmentation

https://wiki.osdev.org/Segment_Limits

No.860037

No.860044

>>860009

I guess implementing MMUs were a waste anyway. Who doesn't have the memory to cover the entire address space anyway?

No.860076

>>859386

>>859723

it's not technologies fault that people are low tier consumer whores obsessed with shiny things. We are by default doomed based off societies average IQ alone

No.860087

>>860076

By definition, the average IQ is 100.

No.860089

>>860009

>null-terminated strings

A one-L NUL, it ends a string

A two-L NULL points to no thing

(But I will bet a golden bull

That there is no three-L NULLL)

No.860096

>>860044

The main overhead and complexity in operating systems comes from file I/O. Virtual memory was created to get rid of internal file I/O by treating the entire disk as if it was persistent RAM. That's called a single-level store and it's extremely powerful and scalable. Most of our OSes treat RAM and disk like paper tape. Null-terminated strings come from a paper tape convention. They do the opposite of single-level store. They remove parallelism and random access and make things more sequential.

https://en.wikipedia.org/wiki/Single-level_store

No.860703

>>860087

Does this mean my IQ score will go up as more niggers are imported into my country?

No.860924

No.860926

>>859382

it would be more practical to buy an Acer ZG5 bth

No.861042

>TL;DR: Motherboard manufacturer allows you to configure parts of the system even if you set BIOS/UEFI password.

This is not an Intel flaw. This is an a motherboard firmware flaw. In-fact Intel motherboards don't allow access to the AMT configuration before asking for the password.

No.861240

>>860096

>Null-terminated strings

You terminate strings by (void *)0 ? See >>860089

No.861887

>>860926

very good computer for pentest ops

No.861901

>>861042

you can turn on pre-bios passwords in nearly every system i have ever seen, its just disabled by default and nobody seems to use it

No.861940

>>861887

>capslock key forcefully removed

why

No.861976

my backspace key broke so i put the capslock key where the backspace was.

No.862014

>>861887

Have you tried not dunking your camera in vaseline?

No.862141

>>861887

I have actually compiled gentoo on one of these. Jesus christ it takes so long.

No.872741

No.873199

File: 32b8b3a85b2b087⋯.png (63.46 KB, 610x404, 305:202, uwp.png)

>>852863

>But I wasn't talking about VS2017 telemetry in the IDE however (and I'll laugh in your face when systemd adds telemetry of its own, enabled by default, in addition to leaking DNS to Google). I was talking about covertly adding telemetry stubs to user programs compiled with it, which VS2015 did but VS2017 doesn't do anymore... unless of course you have evidence to the contrary? Which I'd like to see? Pretty please?

Compare WPF/Silverlight (open source) to Universal Windows Platform (closed source).

Nobody is using the latter, ever wonder why?

No.873223

>>861240

This forced meme is kinda lame. NUL is just an abbreviation in the ASCII table, just as BEL and LF.

He was obviously refering to the null byte used to terminate all C language so-called "strings". Prove that you're a human and can parse natural language like one, else we'll just write you off as one of the markov bots that haunts this forsaken place.

No.873522

time to change to AMD and develop a standarize the use of an open source processor architecture.

No.881026

>over two months later

>Intel firmware fix still not available

>previous fixed firmware was bricking computers

Hahaha I can't wait for the Russians and Chinese to start (continue?) using these flaws.

No.881030

>everything is botnet

>to the point you more or less have plausible deniability for any data that may exist, because all of it could be fabricated out of whole cloth

wew

No.881038

>>881026

>Hahaha I can't wait for the Russians and Chinese to start (continue?) using these flaws.

Without a doubt any intelligence agency that isn't shit already uses it, or you think most 0days last forever?

No.881039

>>873199

>Nobody is using the latter, ever wonder why?

No.881042

>>881039

Pure coincidence

No.881072

>>881038

This vuln is now old af but no real fixes yet.

No.881261

>>861976

Thanks anon. I've never legitimately laughed out loud on an imageboard.

No.881272

>>860703

effectively, yes. IQ changes based on the average. It's funny, but most naysayers who claim that we aren't headed for an idiocracy-esque future cite that the average IQ is climbing but fail to realize that that is relative to a fixed point. Of course the IQ is climbing, the average is going down, so today's 100 is last decade's 95.

No.881278

No.881281

>>873223

'\0' is semantically distinct from (void *)0 .

No.881295

>>881278

Bots need to fucking die already.

No.882196

https://www.amdflaws.com/

Oh look, Intel’s Israeli branch has been busy making up flaws for AMD.

>must flash a malicious BIOS

>gave less than 24 hours notice to AMD before disclosure

Sure smells Jewy.

No.882197

>>852106

>what is a vm

No.882198

File: da946f91a61a5c3⋯.jpg (132.32 KB, 960x1198, 480:599, OkWlIxA.jpg)

they even look as jewy as they act

No.882206

File: c6a00b2b2a05379⋯.gif (1.08 MB, 200x222, 100:111, 0DFD04C2-AA0D-427F-9A62-13….gif)

>>882198

No, NO! Don’t post images like that you filthy goy.

BTW did you notice the CEO was in the IDF’s cyber security 8200 division? That’s their digital blackmail squad.

No.882259

>>851866

Isn't this already exploited in the last year

No.882276

>>882198

>could've filmed literally anywhere and nobody would bat an eye

I'm starting to think kike genetics make it impossible for them to tell the truth.

No.882310

File: 6e226a1b59d6bd8⋯.webm (6.74 MB, 1280x720, 16:9, annuda shoah.webm)

>>882198

Fucking Intel schlomos spreading FUD. Nuke Israel when?

No.882343

>>882276

Kek, I don’t get it either. That’s hilarious.

No.882349

>>882198

>that guy in the middle

My hand instinctively clutched my wallet when I saw him.

No.882360

>>872830

>i am not a shill. if i wanted to be subtle i would write a bot to necrobump 2 - 7 threads over the course of a day and leave it running forever to shit up board quality in general.

So /pol/ on a daily basis? ineffective.

No.882367

>>882349

better angle of that guy, source: https://youtu.be/pgYhOwikuGQ

No.882400

File: 9bf3b9d96f681fc⋯.jpg (1000.5 KB, 1536x2560, 3:5, tablet_jew.jpg)

>knows jews gonna jew

>doesn't realize jews know you know

>you've just told the jew where you keep your wallet

No.882467

I'm using Raspian on an overclocked Raspberry PI 3. I'm not claiming x86 has to die, or other nonsense. But Raspi3 is enough for surfing, if you don't open to many tabs. It's not vulnerable to Meltdown and Spectre. Alternative single board computers might even be more secure, and it helps with compartmentalization (don't do all you shit on one computer).

>>852732

>Linuxes were good until 2010 then suddenly went to shit due to systemd, Grub2, touchscreen DE's and other things. KDE and Gnome also went to shit.

Linux is the Kernel. The other mentioned technologies are ok or even good, but you don't need to use them. So what? Ever heard of Distrowatch?

No.882484

>>882367

every time

No.882485

>>882467

Pi's are all invulnerable to Spectre.

No.882493

>>854323

>Yes, there is no other reason to add this to consumer CPU's in which 99 percent of the time won't be used, unless the NSA believes you're a journalist that needs to stop publishing information that it doesn't want you to publish.

Cyberwar? Espionage against other countries. Americans tend to forget that they exist, sometimes...

No.882543

>>882400

>that pic

It's like someone stuck Mini-me's face onto Fat Bastard's body.

No.882574

>>882310

New York

Washington

Hollywood

London

Berlin

Brussels

Mecca

Vatican

San Francisco

....Lots of targets.

No.890151

Did intel ever fix this?

No.890179

No.890184

>>890179

Search for "raspberry pi speculative execution"

No.890188

>>882574

On one hand I hate this soyboy cuck supreme, on the other he supports the eradication of one of the most prominent mental illness' to plague our current society.

No.890200

>>890179

No.890930

>>882367

Fucking jews.

No.892171

>tfw I fell for integrated israel meme

Not even once

No.895251

>>888888

No.900817

Bump, it's been over three months, has Intel even made new microcode available to vendors yet?

I know they did once but it turned out that the first microcode fix they gave out was actually bricking machines. Has anybody gotten a BIOS update yet?

What a shitshow, they will never live this down.

No.902687

>>900817

No new microcode yet, Intel is still thinking about how they can sneak in some new backdoor to make up for the one they'll fix.

No.911485

More massive Intel flaws came out this week too.

No.911493

>>911485

Yes, and we have a thread discussing those

Too bad mods here are useless or they would've anchored this thread being bumped by a single fucking person at this point

No.911576

>>858438

I'm kinda glad it turned out like it did though. If Commodore and Atari had survived, they would have most likely just become pozzed and lamerized just like everything else.

No.917078

There are more new exploits that just came out. Jewtel's shitting the bed lately.

No.918515

TWO NEW CRITICAL SPECTRE VARIANTS DISCOVERED

ONE CAN WRITE TO YOUR FIRMWARE

No.918521

>>851879

why not buy an amd cpu?

also aren't ppc cpus already extremely exploitable?

No.918522

>>918515

>>917078

So what is the current status on real-life danger resulting from this? Are there drive-by kind of exploits where your system can get compromised and owned by executing some cancerous Javascript on some random page you visited or somesuch? What are the means to mitigate the risks, use an expendable system that has both firmware and OS reflashed/reimage once a week, and do anything else on airgapped systems?