I wonder what other (somehow) laptop-worthy CPUs offer a better management engine story? * AMD processors do have an equivalent management engine (PSP), but I didn't hear anything about remote exploits for it. * Beefier ARM CPUs also have something like a management engine ("trustzone" only accessible to the manufacturer). I have no idea if it has any remote-access capabilities on any common hardware. On RPi the trus…
I believe AMD lets you disable it from BIOS.
Intel patches new ME vulnerabilities
91–100 of 337 posts
Re: Intel patches new ME vulnerabilities
#92Has Intel offered an official "disable ME" patch? I'd like to close the door once and not worry about it again.
There are no official ways of disabling the ME. The Coreboot project and the Hardenedlinux project have worked on it, and here are some resources on their progress: https://hardenedlinux.github.io/firmware/2016/11/17/neutrali... https://www.coreboot.org/Intel_Management_Engine And here is a general writeup on the Intel chips and their "features": https://libreboot.org/faq.html#intel If Intel aren't going to patch old…
Re: Intel patches new ME vulnerabilities
#93I finally pushed the button on my lenovo T450S there is a setting in the bios to delete the AMT. While the best route is to reprogram... I would just rather click one button and set bios passwords afterwards.
The ME (AMT) is never actually disabled or deleted as long as the FW is there and running. Plus you should take advantage of the fact that the 450 is still supported and gets a ME FW update. Yesterday I updated all my machines with Gen 4 CPU with new BIOS, new ME FW, and (surprisingly) new TPM FW. The Gen 3 CPU machines barely got a BIOS update for Metldown/Spectre and that's it.
Re: Intel patches new ME vulnerabilities
#94Can MacBook owners do something to disable or cripple Intel ME? Is Apple disabling it for us? I can’t find Apple responses to these issues.
Re: Intel patches new ME vulnerabilities
#95Time to build a Ryzen rig.
Re: Intel patches new ME vulnerabilities
#96I don't want a patch. I don't use that thing for anything. I want them to disable that thing by default! Leaving those backdoors open in older products should lead to a recall because the flaw was there all along.
Re: Intel patches new ME vulnerabilities
#97Earlier quoted context omitted.
You can't disable ME.
I thought you can in C2D (Nehalem?) era ThinkPads? https://libreboot.org/ and you can minimize ME in Sandy and Ivy Bridge, using ME_Cleaner? edit: according to sounds' comment* in HN (2016), The ME is purportedly placed in "recovery" mode [*] https://news.ycombinator.com/item?id=13056997
Re: Intel patches new ME vulnerabilities
#98Earlier quoted context omitted.
As far as I understand: * In general you cannot. * You can try to remove ME with non-official tools like https://github.com/corna/me_cleaner * Some vendors ship specific laptops with ME disabled ( https://fossbytes.com/laptops-intel-me-chip-disabled/ ) * For servers or desktops, you can plug in a separate PCI network adapter instead of using the one on the mainboard (please correct me if this is wrong or confirm it a…
me_cleaner does not disable the ME. It is a partial disablement of ME functionality, but some functionality remains enabled. The ME firmware is an Intel-signed proprietary binary blob part of which is instrumental in the system boot process, so complete removal is impossible. me_cleaner and/or the HAP bit, or the services offered by laptop vendors which is basically doing the very same for you, may certainly reduce t…
Re: Intel patches new ME vulnerabilities
#99Earlier quoted context omitted.
The ME (AMT) is never actually disabled or deleted as long as the FW is there and running. Plus you should take advantage of the fact that the 450 is still supported and gets a ME FW update. Yesterday I updated all my machines with Gen 4 CPU with new BIOS, new ME FW, and (surprisingly) new TPM FW. The Gen 3 CPU machines barely got a BIOS update for Metldown/Spectre and that's it.
So I would just update the bios and it will return back to normal?
And as long as you are not using it and don't need it you might as well disable and unconfigure it in BIOS.
Of course in this state your machine is ready for reconfiguring it and it will accept the default "admin" ME password. Which means you have to make sure you have a good BIOS password. This will prevent someone who has 2 minutes alone with your machine from reenabling and configuring it without you even noticing.
Re: Intel patches new ME vulnerabilities
#100I wonder what other (somehow) laptop-worthy CPUs offer a better management engine story? * AMD processors do have an equivalent management engine (PSP), but I didn't hear anything about remote exploits for it. * Beefier ARM CPUs also have something like a management engine ("trustzone" only accessible to the manufacturer). I have no idea if it has any remote-access capabilities on any common hardware. On RPi the trus…
Then a supplier could configure bulk orders to enable the ME and it would be left up to the customer to choose the security-for-convenience tradeoff.