Intel AMT Checker for Linux
71–80 of 93 posts
Re: Intel AMT Checker for Linux
#72Why would Intel insist on being so secretive about their management engine? Is it some kind of competitive advantage for them? Supposedly, it's useful for management tasks in enterprise environments, but if I were CIO, I think I would ban VPro chips. Who wants ring -3 processes running on their network for which they have no information about?
> Why would Intel insist on being so secretive about their management engine? It includes DRM (Protected Audio/Video Path), for one.
Re: Intel AMT Checker for Linux
#73Earlier quoted context omitted.
> Why would Intel insist on being so secretive about their management engine? It includes DRM (Protected Audio/Video Path), for one.
Documenting it shouldn't alter its effectiveness. I can tell you how AES works and that doesn't compromise anything.
Personally, I think the right solution is to not have DRM for music, TV, and movies on PCs, purely for business reasons. What's happening today is that Intel is effectively shipping everyone who buys an x86 CPU a content decryption module, burning goodwill among free software advocates even though fewer than 1% of consumers will ever use the functionality (actually, does anyone use it?) It makes more business sense for consumers to just buy set-top boxes to consume content. It's not like anyone who buys a $450 Core i7 is going to balk at paying $35 for a Chromecast.
Re: Intel AMT Checker for Linux
#74Re: Intel AMT Checker for Linux
#75Did anyone read that code before using it? :)
Re: Intel AMT Checker for Linux
#76I'm shocked to say that the Thinkpad x260 does not have AMT at all. Shocked not because I think it's a huge conspiracy to control your computer but because I honestly do believe AMT was made with the best intentions of providing a level of theft mitigation for devices. Just like "Find my Mac" from Apple that seems to get very little flack. I'd be surprised if this meant that my pretty expensive Lenovo Thinkpad X-seri…
Lenovo lists the X260 as vulnerable to CVE-2017-5689 [0], implying it supports AMT. My X240 definitely has AMT, it would be a bit odd for them to remove it in later generations. [0] https://support.lenovo.com/us/en/product_security/LEN-14963
Re: Intel AMT Checker for Linux
#77Earlier quoted context omitted.
Thanks! Missed this part. Also, do you think it's a good idea to keep it in this state as opposed to updating in case Intel's new patches lock AMT down even further? This is the pattern I saw with Sony once - groups of users not updating their consoles because via exploiting it they could get more control over it.
You should be able to disable it in the BIOS. If you're not going to use it, I'd suggest disabling it. You could always reenable it later, should you find a need for it.
Intel AMT is present AMT is unprovisioned
So disabling it puts it in the same state.
Re: Intel AMT Checker for Linux
#78Earlier quoted context omitted.
> Why would Intel insist on being so secretive about their management engine? It includes DRM (Protected Audio/Video Path), for one.
Documenting it shouldn't alter its effectiveness. I can tell you how AES works and that doesn't compromise anything.
Re: Intel AMT Checker for Linux
#79Earlier quoted context omitted.
> Why would Intel insist on being so secretive about their management engine? It includes DRM (Protected Audio/Video Path), for one.
Documenting it shouldn't alter its effectiveness. I can tell you how AES works and that doesn't compromise anything.
DRM is based on "physical access is not complete access", which is different.
Re: Intel AMT Checker for Linux
#80God #$%@ing damn it, this is why we can't have nice things. You can do only so much to not get pwned software wise, now you need to be paranoid about the hardware too?! Going through all Xeon servers is going to be fun tomorrow.
I am tempted to go back to dialup style connectivity. Meaning i disconnect the router from the net unless i absolutely need something online.