Live data from Hacker News

The Intel ME subsystem can take over your machine, can't be audited

boingboing.net

11–20 of 282 posts

Re: The Intel ME subsystem can take over your machine, can't be audited

#12
post #9

Earlier quoted context omitted.

From the article: "On some chipsets, the firmware running on the ME implements a system called Intel's Active Management Technology (AMT). This is entirely transparent to the operating system, which means that this extra computer can do its job regardless of which operating system is installed and running on the main CPU." So it sounds like yes, this would effect any OS.

I think they are asking if Apple ordered chips without this ME, give the former's penchant for security. I wonder similarly.

Ah, fair enough. That is a good question.

Re: The Intel ME subsystem can take over your machine, can't be audited

#15
post #14

Why can't Intel implement proper security and open up this blob to begin with? Not opening it and not allowing to disable it, suggests it's intended for something sinister.

This reminds me of the anti-theft features. The laptop anti-theft arms race is ridiculous.

Re: The Intel ME subsystem can take over your machine, can't be audited

#17
Taking another angle: What if the computer's owner wants to use it to access her computer remotely? Are there some instructions how to do this? Is it feasible?

If not, then there seems little justification to have a relatively new feature like this turned on by default. Who is this feature really for? If it's not for all users then why is activation mandatory in CPUs after Core2?

I mean, if ME has to be active, then the computer's owner should be able to use it, right?

Re: The Intel ME subsystem can take over your machine, can't be audited

#18

Does this apply to Macs?

Not sure. ME requires coordination/support from other electronic components to do its job. It only applies to Macs if Apple's motherboards have the necessary circuitry (I couldn't find this info so far).

Re: The Intel ME subsystem can take over your machine, can't be audited

#19

Taking another angle: What if the computer's owner wants to use it to access her computer remotely? Are there some instructions how to do this? Is it feasible? If not, then there seems little justification to have a relatively new feature like this turned on by default. Who is this feature really for? If it's not for all users then why is activation mandatory in CPUs after Core2? I mean, if ME has to be active, then…

I think it is intended for enterprises to enable.

Re: The Intel ME subsystem can take over your machine, can't be audited

#20
No doubt various three-letter agencies are having a field-day with this right now.

Hopefully a robin-hood type will reverse-engineer the blob and post a permanent fix to disable this thing before a more nefarious person/group uses it to devastate the PC landscape with something even worse than bitlocker.

Post reply on HN