Live data from Hacker News

How Purism avoids Intel’s Active Management Technology

puri.sm

11–20 of 121 posts

Re: How Purism avoids Intel’s Active Management Technology

#11
post #7

Earlier quoted context omitted.

It's not possible to remove, or at least account for all behavior of, the ME entirely until the BUP part is reverse engineered. You can't take that part out yet and have a working CPU as far as I understand. I'm surprised you didn't mention the FSP which is a binary blob from Intel required to be run by any boot firmware (UEFI, Coreboot, or whatever) very early in the platform initialization process (to my understand…

I know it isn't possible. Half measures are attractive short term but can serve to normalize failure, as is currently happening. Most people I know view Purism favorably and think it has actually made ME irrelevant. It hasn't, all the hardware is still there and can be enabled. You still are not the de facto owner of the machine.

> but can serve to normalize failure

I agree, but it's not like they've given up. They're still working on it, and hope to find a way to permanently remove all the software that enables it, and run their own software instead. Whether or not they'll eventually be successful is of course an open question.

The alternative, at least right now, is that Purism doesn't sell any hardware at all, goes out of business, and then there's no one working credibly on this. That would be an even worse failure, IMO.

Re: How Purism avoids Intel’s Active Management Technology

#12
post #9

> We choose Intel CPUs that do not have vPro The Wikipedia article they link about vPro says: > Intel vPro technology ... [includes] VT-x, VT-d... Does this mean that Purism hardware won't support virtualization extensions? Seems like that would be a big downside, and would make it a non-starter for a lot of people (including myself).

The second sentence on Wikipedia says: When the vPro brand was launched (circa 2007), it was identified primarily with AMT, thus some journalists still consider AMT to be the essence of vPro.

(They have also added a small asterisk to the Purism article to clarify - I'm also just reading it now so don't know if it was there before)

Re: How Purism avoids Intel’s Active Management Technology

#13
post #4
post #2

Looking forward to AMD laptops with Coreboot support as well.

Probaly won`t happen since AMD have their own secret code which no one could neutralize yet.

Supposedly it's already in the works: https://twitter.com/jeremy_soller/status/1286457590289858560

Re: How Purism avoids Intel’s Active Management Technology

#14
post #7

Earlier quoted context omitted.

It's not possible to remove, or at least account for all behavior of, the ME entirely until the BUP part is reverse engineered. You can't take that part out yet and have a working CPU as far as I understand. I'm surprised you didn't mention the FSP which is a binary blob from Intel required to be run by any boot firmware (UEFI, Coreboot, or whatever) very early in the platform initialization process (to my understand…

I know it isn't possible. Half measures are attractive short term but can serve to normalize failure, as is currently happening. Most people I know view Purism favorably and think it has actually made ME irrelevant. It hasn't, all the hardware is still there and can be enabled. You still are not the de facto owner of the machine.

That's why for the long term they mention:

" We released a petition for, and continue to work with Intel to free it entirely (what Intel is calling a “ME-less” design). "

Do you have a better solution that trying to neutralise it + starting a petition + talking with Intel to remove it ?

If you to want to criticize brands for selling privacy snakeoil, and not making you "the de facto owner of the machine" then we should address your criticism at Apple, not Purism

Re: How Purism avoids Intel’s Active Management Technology

#15
post #9

> We choose Intel CPUs that do not have vPro The Wikipedia article they link about vPro says: > Intel vPro technology ... [includes] VT-x, VT-d... Does this mean that Purism hardware won't support virtualization extensions? Seems like that would be a big downside, and would make it a non-starter for a lot of people (including myself).

You have dig past the marketing labels and into the actual specs. Some CPUs have VT-x but not vPro

https://ark.intel.com/content/www/us/en/ark/products/149091/...

Re: How Purism avoids Intel’s Active Management Technology

#16
post #8
post #5

Earlier quoted context omitted.

Even though it`s true that ME is not 100% removed, most of it is. https://puri.sm/learn/software-freedom-in-perspective/

ME hasn't been removed at all. The hardware is still on the machine.

That’s a useless definition of “removed”; using that definition, ME can never be “removed” at all! But that’s not what we’re talking about here. A more useful definition would be to use “removed” as in “not a security problem anymore”.

Re: How Purism avoids Intel’s Active Management Technology

#17
post #16
post #8

Earlier quoted context omitted.

ME hasn't been removed at all. The hardware is still on the machine.

That’s a useless definition of “removed”; using that definition, ME can never be “removed” at all ! But that’s not what we’re talking about here. A more useful definition would be to use “removed” as in “not a security problem anymore”.

> using that definition, ME can never be “removed” at all!

This is my point. It can't be removed. It will always remain a security problem.

Re: How Purism avoids Intel’s Active Management Technology

#20
post #7

Earlier quoted context omitted.

It's not possible to remove, or at least account for all behavior of, the ME entirely until the BUP part is reverse engineered. You can't take that part out yet and have a working CPU as far as I understand. I'm surprised you didn't mention the FSP which is a binary blob from Intel required to be run by any boot firmware (UEFI, Coreboot, or whatever) very early in the platform initialization process (to my understand…

I know it isn't possible. Half measures are attractive short term but can serve to normalize failure, as is currently happening. Most people I know view Purism favorably and think it has actually made ME irrelevant. It hasn't, all the hardware is still there and can be enabled. You still are not the de facto owner of the machine.

> It hasn't, all the hardware is still there and can be enabled.

Can it be enabled by Intel?

A system that has ME installed with a NIC the ME can't access (non-Intel) seems like it makes the ME irrelevant via suffocation.

I'm not sure of the technical details of this board or if the ME can access non-Intel NICs.

Post reply on HN