Live data from Hacker News

The Intel ME subsystem can take over your machine, can't be audited

boingboing.net

281–282 of 282 posts

Re: The Intel ME subsystem can take over your machine, can't be audited

#281

I wasn't aware about Intel ME until recently bought a brand new Lenovo ThinkPad and saw the "Intel Management Engine" on BIOS/UEFI boot menu. The thing is: how can I configure this ME thing in order to avoid (or minimize, at least) possible attacks?

You can't. The whole point of the thing is that it can't be disabled and will always be running to let your theoretical IT department take over your machine.

I got ME disabled in BIOS on my Lenovo S30 (manufactured around 2012 I think). Do you think this option in BIOS setup insufficient to turn it off? Is the ME still running and listening to commands coming from the network?

Re: The Intel ME subsystem can take over your machine, can't be audited

#282
post #119

Earlier quoted context omitted.

Wondering - when that happens - if their firmware is open source but monitored for ad targeting should we be OK with it?

Freedom 1 of the FSF is ( https://www.gnu.org/philosophy/free-sw.html ): "The freedom to study how the program works, and change it so it does your computing as you wish" In this sense you should be able to change the firmware (since it is open source in the sense of the OSI definition) and remove the monitoring for ad targeting. If this is not possible, Google's firmware is not open source (see https://opensource.or…

opensource != free software
Post reply on HN