Here's the main product using HAP if anyone wants to see if they can buy it and RE its firmware. https://gdmissionsystems.com/cyber/products/trusted-computin... Some stuff is government only but some for businesses. You'll have to contact them to find out.
Disabling Intel ME 11 via undocumented mode
131–140 of 228 posts
Re: Disabling Intel ME 11 via undocumented mode
#132Earlier quoted context omitted.
>remote monitoring and control There are opensource ways to do out of band management without it. >consumer benefits. Related tech also helped DRM machines through Trusted Computing alliance. Nobody I knew who was knowledgeable wanted that shit in the first place. It was always edging away consumer control of the platform. DRM is part of the problem here! Same thing with web standards. What annoys me the most about t…
>>remote monitoring and control > There are opensource ways to do out of band management without it. I'd be surprised if there is a cost-effective open source alternative to this requirement: Remotely access and control a computer under any circumstance where it has power and a physical network connection. Solutions like AMT work even if there is no functioning processor or memory, because ME provides its own process…
Re: Disabling Intel ME 11 via undocumented mode
#133Q: How does one actually determine intel ME is present in a CPU... I've got an old P8600, I can find no definitive list of CPUs or ways to test for it. Some articles say all intel CPUs since 2006, others say only the newer "core" brand.
Intel's ME was first available in 2006, and by the end of 2008 it was on every CPU they produce.
According to ark.intel.com, the P8600 chip was produced Q3'08 so it's in the right timeline for having the ME. But the giveaway is that the chip has "Trusted Execution technology".
Intel® Trusted Execution Technology for safer computing is a versatile set
of hardware extensions to Intel® processors and chipsets that enhance the
digital office platform with security capabilities such as measured launch
and protected execution. It enables an environment where applications can
run within their own space, protected from all other software on the system.
On the bright side, older MEs are easier to de-fang. The 06-08 versions can sometimes be removed entirely.Re: Disabling Intel ME 11 via undocumented mode
#134Earlier quoted context omitted.
I'm simply intrigued how this bit has managed to elude so many developers and hackers over the years. It's literally an option in an intel software tool, and yet you have people who have vehemently complained about Intel ME for the past few years. I have some serious cognitive dissonance going on right now.
> I'm simply intrigued how this bit has managed to elude so many developers and hackers over the years. Lots of hackers already knew that for many years - I would rather call it "common knowledge". But they had no idea what one could do to change anything about this. Just like "AMD PSP"/"AMD Secure Processor" - it is common knowledge that it exists, but we have no idea what it really does or how one can disable/disar…
Re: Disabling Intel ME 11 via undocumented mode
#135Earlier quoted context omitted.
Years and years ago, when color printer/scanners were fairly new, I tried to scan and print a $5 dollar bill. I was curious. The machine printed out about a third of the image but the rest of what it printed was a very official looking notice to please call the US Treasury. (edit: HP was the manufacturer.)
Likely to do with the EURion constellation: https://en.wikipedia.org/wiki/EURion_constellation Another item of interest may be printer stenography, in which every piece of printed paper, seemingly from every printer, can be traced back to make, model and potentially even the unit used to print it: https://en.wikipedia.org/wiki/Printer_steganography
(Meaning that I always assumed something like this was going on, because that's what I would do, but I try to disbelieve it so as to be able to act normal. I believe all phones are continually listening to and scanning their ambient environments, because that's what I would do. But probably not, right? Right?)
The thing that bothers me the most is that "normal" people refuse to engage with reality. I used to tell people some of the things e.g. that Snowden revealed, but I was always accused of wearing the tinfoil hat. From my point of view, normal people are hugely intellectually dishonest. Poor Ed Snowden had to throw his life away to try to get people to notice and think about what's happening, and typically all most people do is whine about their precious privacy (the ones that don't immediately stick their heads back into the sand that is.) Like privacy is something that still exists. It doesn't.
I better wrap it up here before I get the urge to talk about forbidden technologies like REDACTED, REDACTED, and REDACTED. I mean, there's a certain tension knowing about a REDACTED that can cure all diseases, but that cannot be popularized because it can also REDACTED without a trace. Could you imagine the chaos if something like that became public knowledge!?
Re: Disabling Intel ME 11 via undocumented mode
#136Earlier quoted context omitted.
> I'm simply intrigued how this bit has managed to elude so many developers and hackers over the years. Lots of hackers already knew that for many years - I would rather call it "common knowledge". But they had no idea what one could do to change anything about this. Just like "AMD PSP"/"AMD Secure Processor" - it is common knowledge that it exists, but we have no idea what it really does or how one can disable/disar…
Know what's even crazier? If the CPU has the "Intel® Anti-Theft Technology", then the Management Engine has 3G built-in.
Re: Disabling Intel ME 11 via undocumented mode
#137This is why I support Power/MIPS/RISC development going forward. It's just a shame that we allowed intel and amd to both put in cpu backdoors at such an obvious level (I like x86 but it's not the cpu of the future unless it's open). I highly suspect some national security letter type shit is going on in the background, ala Promis and William A. Hamilton who has claimed on Bruce Schneiers blog they (intel agencies) we…
If some other CPU architecture were the dominant PC platform, do you think it wouldn't grow such features too? It's not hard to imagine an alternate universe in which we all have RISC workstations with the equivalent of ME, and Intel/AMD are the minorities who have more "open" CPUs without, but only because they hadn't grown enough. The underlying reason why ME became popular is the same reason why proprietary walled…
... is also because it provides management features that are wanted by enterprise customers. If you're running hundreds of servers in a data center, the more management you can do remotely, without visiting the machine room and preferably automated as much as possible, the better.
This is quite irrelevant and even undesirable for an individual's personal computer.
Re: Disabling Intel ME 11 via undocumented mode
#138Earlier quoted context omitted.
>remote monitoring and control There are opensource ways to do out of band management without it. >consumer benefits. Related tech also helped DRM machines through Trusted Computing alliance. Nobody I knew who was knowledgeable wanted that shit in the first place. It was always edging away consumer control of the platform. DRM is part of the problem here! Same thing with web standards. What annoys me the most about t…
>>remote monitoring and control > There are opensource ways to do out of band management without it. I'd be surprised if there is a cost-effective open source alternative to this requirement: Remotely access and control a computer under any circumstance where it has power and a physical network connection. Solutions like AMT work even if there is no functioning processor or memory, because ME provides its own process…
Re: Disabling Intel ME 11 via undocumented mode
#139Earlier quoted context omitted.
>remote monitoring and control There are opensource ways to do out of band management without it. >consumer benefits. Related tech also helped DRM machines through Trusted Computing alliance. Nobody I knew who was knowledgeable wanted that shit in the first place. It was always edging away consumer control of the platform. DRM is part of the problem here! Same thing with web standards. What annoys me the most about t…
>>remote monitoring and control > There are opensource ways to do out of band management without it. I'd be surprised if there is a cost-effective open source alternative to this requirement: Remotely access and control a computer under any circumstance where it has power and a physical network connection. Solutions like AMT work even if there is no functioning processor or memory, because ME provides its own process…
Our team has several racks of R&D servers 7500km away from the bulk of the team, and having OOB management is vital. Absolutely vital.
Re: Disabling Intel ME 11 via undocumented mode
#140If ME is not a backdoor then why doesn't Intel allow to disable it? Why don't they publish detailed descriptions? Why don't they allow user to run their programs on ME CPU?
[1]: I'm not suggesting most, if not all, people don't need the ability to disable Intel ME, only that, they more often than not don't value it enough to pay for it..