Re: Intel Active Management Technology (AMT): not necessarily your friend
Ivan Sergio Borgonovo <[email protected]>
| Newsgroups | gmane.org.user-groups.linux.svlug |
|---|---|
| Organization | http://www.WebThatWorks.it |
| Message-ID | <[email protected]> |
On 05/04/2017 02:20 AM, Rick Moen wrote: > Pitfall inside. > > A decade-plust ago, Intel started building embedded control structures > deep into its chipsets. One, present in many but not all Intel x86 > motherboard chipset since 2008 starting with 'Nehalem', is the Active > Management Technology (AMT) out-of-band network service, intended to > permit out-of-band system management on one out of network ports > 16992i-16995[1] (over ethernet)[2], to remotely reboot, repair, and > tweak hosts, and has total control of the host from ring -2, below the > level of the normal hardware (ring 0). It's supposed to require an > access password, and then provide remote serial console or VNC After https://www.theregister.co.uk/2017/02/03/cisco_clock_component_may_fail/ time to buy AMD, or POWER or RISC-V? RISC-V is a very nice architecture, very promising, backed by big names and Open. No way bugs like CVE-2017-5689 are going to stay in the silicon for long. Unfortunately RISC-V specifications are still in development (no privileged level ISA specification, so not suited for virtualization yet). But you can already buy RISC-V CPU and dev board. https://dev.sifive.com/dev-kits/ BTW I'm waiting things settle a bit about BIOS and memory support to buy a Ryzen 7. -- Ivan Sergio Borgonovo http://www.webthatworks.it http://www.borgonovo.net