Earlier quoted context omitted.
Even though it`s true that ME is not 100% removed, most of it is. https://puri.sm/learn/software-freedom-in-perspective/
The part that can't be removed still has had critical security vulnerabilities, though.
How Purism avoids Intel’s Active Management Technology
31–40 of 121 posts
Re: How Purism avoids Intel’s Active Management Technology
#32I've been hearing about Intel’s Active Management Technology for years, but I'd like to see a demonstration of how an attack would work. I have an unused laptop with: 1. an Intel CPU that supports the vPro feature set 2. an Intel networking card 3. the corporate version of the Intel Management Engine (Intel ME) binary (well, definitely, a corporate laptop that used to get updates, but how do I check for ME?) Is there…
If the backdoor exists you will need to know a secret to open it. Currently, the public obviously doesn't know this secret or the doors would be wide open for virtually anybody. Because we don't know the secret key, we cannot open them to prove that they exist. So we don't know for sure if the backdoors exist. But the way the IME is designed and handled makes it possible and plausible that backdoors could exist. It's up to Intel to prove that they don't exist.
Re: How Purism avoids Intel’s Active Management Technology
#33Disabling is not removing. People have found motherboards that should ostensibly not support vPro (e.g. Asus gaming motherboards) that do report vPro ME functionality. There is no reason to believe the software switch is working, especially when even a system integrator can accidentally enable the features. If someone wants them on they turn on. Purism sells snakeoil. Presenting their offerings as FOSS-compatible wou…
https://www.phoronix.com/scan.php?page=news_item&px=Zlatan-T...
Re: How Purism avoids Intel’s Active Management Technology
#34> We choose Intel CPUs that do not have vPro The Wikipedia article they link about vPro says: > Intel vPro technology ... [includes] VT-x, VT-d... Does this mean that Purism hardware won't support virtualization extensions? Seems like that would be a big downside, and would make it a non-starter for a lot of people (including myself).
You have dig past the marketing labels and into the actual specs. Some CPUs have VT-x but not vPro https://ark.intel.com/content/www/us/en/ark/products/149091/...
Re: How Purism avoids Intel’s Active Management Technology
#35Earlier quoted context omitted.
That’s a useless definition of “removed”; using that definition, ME can never be “removed” at all ! But that’s not what we’re talking about here. A more useful definition would be to use “removed” as in “not a security problem anymore”.
> using that definition, ME can never be “removed” at all! This is my point. It can't be removed. It will always remain a security problem.
you have hardware on the cpu no longer accessible by software. you have a mellanox network card the me can't talk to. it's there, in the kitchen drawer. it's no longer in the door -so not a security problem.
the 'issue' requires physical access to the machine, and for you to be logged in with an admin account. if someone is physically sitting next to your server and logged in as root, you have no security anymore. they don't need to break into anything, the can just run what they want already.
someone is in your car with keys in the ignition. you're saying they can steal your car by hacking the entertainment system because it's insecure.
Re: How Purism avoids Intel’s Active Management Technology
#36Re: How Purism avoids Intel’s Active Management Technology
#37Earlier quoted context omitted.
Probaly won`t happen since AMD have their own secret code which no one could neutralize yet.
Recent (1-2 years?) AMD BIOS supports disabling the Platform Security Processor (their ME equivalent). I haven't been able to figure out what exactly this means, but it does seem to be disabled after system initialization. Kind of like Intel's HAP bit, except user-settable.
Re: How Purism avoids Intel’s Active Management Technology
#38I hear a lot about disabling the management engines... what about activating them for yourself?
Re: How Purism avoids Intel’s Active Management Technology
#39Earlier quoted context omitted.
Recent (1-2 years?) AMD BIOS supports disabling the Platform Security Processor (their ME equivalent). I haven't been able to figure out what exactly this means, but it does seem to be disabled after system initialization. Kind of like Intel's HAP bit, except user-settable.
Either like the HAP bit, or less — only disabling its visibility to the OS on the PCIe bus.
Re: How Purism avoids Intel’s Active Management Technology
#40Earlier quoted context omitted.
> using that definition, ME can never be “removed” at all! This is my point. It can't be removed. It will always remain a security problem.
that's like saying having a flimsy house door lock lying in your kitchen drawer is a security problem. you have hardware on the cpu no longer accessible by software. you have a mellanox network card the me can't talk to. it's there, in the kitchen drawer. it's no longer in the door -so not a security problem. the 'issue' requires physical access to the machine, and for you to be logged in with an admin account. if so…
Intel ME is still there. It is still potentially remotely configurable and remotely updateable. That those features are not advertised is irrelevant, they can be assumed to be there or easily added.