Live data from Hacker News

How Purism avoids Intel’s Active Management Technology

puri.sm

21–30 of 121 posts

Re: How Purism avoids Intel’s Active Management Technology

#21
post #4
post #2

Looking forward to AMD laptops with Coreboot support as well.

Probaly won`t happen since AMD have their own secret code which no one could neutralize yet.

Recent (1-2 years?) AMD BIOS supports disabling the Platform Security Processor (their ME equivalent).

I haven't been able to figure out what exactly this means, but it does seem to be disabled after system initialization. Kind of like Intel's HAP bit, except user-settable.

Re: How Purism avoids Intel’s Active Management Technology

#23
post #3

Disabling is not removing. People have found motherboards that should ostensibly not support vPro (e.g. Asus gaming motherboards) that do report vPro ME functionality. There is no reason to believe the software switch is working, especially when even a system integrator can accidentally enable the features. If someone wants them on they turn on. Purism sells snakeoil. Presenting their offerings as FOSS-compatible wou…

It's not possible to remove, or at least account for all behavior of, the ME entirely until the BUP part is reverse engineered. You can't take that part out yet and have a working CPU as far as I understand. I'm surprised you didn't mention the FSP which is a binary blob from Intel required to be run by any boot firmware (UEFI, Coreboot, or whatever) very early in the platform initialization process (to my understand…

> Success here could indicate to CPU vendors there are people who care about these things.

If the Libreboot FAQ[1] is to be believed, then we are well past this stage. It states:

> Even Google, which sells millions of chromebooks (coreboot preinstalled) have been unable to persuade them.

[1] https://libreboot.org/faq.html

Re: How Purism avoids Intel’s Active Management Technology

#24

What are the odds that the chips that don't feature AMT/ME don't have it physically as opposed to it just being crippled in firmware ? In which case if one is worried about government backdoors this should alleviate exactly zero concerns.

This topic is well understood so there's no need for "odds". All the chips have ME. AMT is a firmware feature that can be removed or not bought.

Re: How Purism avoids Intel’s Active Management Technology

#25
post #16
post #8

Earlier quoted context omitted.

ME hasn't been removed at all. The hardware is still on the machine.

That’s a useless definition of “removed”; using that definition, ME can never be “removed” at all ! But that’s not what we’re talking about here. A more useful definition would be to use “removed” as in “not a security problem anymore”.

That definition doesn't change much, because the part that can't be removed can and will leave your system vulnerable to exploits like this one: https://www.intel.com/content/www/us/en/security-center/advi...

Re: How Purism avoids Intel’s Active Management Technology

#26
post #5
post #3

Disabling is not removing. People have found motherboards that should ostensibly not support vPro (e.g. Asus gaming motherboards) that do report vPro ME functionality. There is no reason to believe the software switch is working, especially when even a system integrator can accidentally enable the features. If someone wants them on they turn on. Purism sells snakeoil. Presenting their offerings as FOSS-compatible wou…

Even though it`s true that ME is not 100% removed, most of it is. https://puri.sm/learn/software-freedom-in-perspective/

The part that can't be removed still has had critical security vulnerabilities, though.

Re: How Purism avoids Intel’s Active Management Technology

#27
I've been hearing about Intel’s Active Management Technology for years, but I'd like to see a demonstration of how an attack would work. I have an unused laptop with:

1. an Intel CPU that supports the vPro feature set

2. an Intel networking card

3. the corporate version of the Intel Management Engine (Intel ME) binary (well, definitely, a corporate laptop that used to get updates, but how do I check for ME?)

Is there a website I can visit that can initiate a remote takeover (I'm consenting to it)? Why isn't this possible? What other step is required on my side to make it possible? Is it possible only through the physical ethernet connection? Why aren't we seeing wide scale exploits based on AMT?

Re: How Purism avoids Intel’s Active Management Technology

#29

I've been hearing about Intel’s Active Management Technology for years, but I'd like to see a demonstration of how an attack would work. I have an unused laptop with: 1. an Intel CPU that supports the vPro feature set 2. an Intel networking card 3. the corporate version of the Intel Management Engine (Intel ME) binary (well, definitely, a corporate laptop that used to get updates, but how do I check for ME?) Is there…

https://news.ycombinator.com/item?id=16238765

Re: How Purism avoids Intel’s Active Management Technology

#30
post #9

> We choose Intel CPUs that do not have vPro The Wikipedia article they link about vPro says: > Intel vPro technology ... [includes] VT-x, VT-d... Does this mean that Purism hardware won't support virtualization extensions? Seems like that would be a big downside, and would make it a non-starter for a lot of people (including myself).

Qubes OS, which requires VT-d, works flawlessly on my Librem 15, so virtualization is there.
Post reply on HN