Live data from Hacker News

How Purism avoids Intel’s Active Management Technology

puri.sm

1–10 of 121 posts

Re: How Purism avoids Intel’s Active Management Technology

#3
Disabling is not removing. People have found motherboards that should ostensibly not support vPro (e.g. Asus gaming motherboards) that do report vPro ME functionality.

There is no reason to believe the software switch is working, especially when even a system integrator can accidentally enable the features. If someone wants them on they turn on.

Purism sells snakeoil. Presenting their offerings as FOSS-compatible would be honest. Claiming additional security is not.

Re: How Purism avoids Intel’s Active Management Technology

#5
post #3

Disabling is not removing. People have found motherboards that should ostensibly not support vPro (e.g. Asus gaming motherboards) that do report vPro ME functionality. There is no reason to believe the software switch is working, especially when even a system integrator can accidentally enable the features. If someone wants them on they turn on. Purism sells snakeoil. Presenting their offerings as FOSS-compatible wou…

Even though it`s true that ME is not 100% removed, most of it is.

https://puri.sm/learn/software-freedom-in-perspective/

Re: How Purism avoids Intel’s Active Management Technology

#6
post #3

Disabling is not removing. People have found motherboards that should ostensibly not support vPro (e.g. Asus gaming motherboards) that do report vPro ME functionality. There is no reason to believe the software switch is working, especially when even a system integrator can accidentally enable the features. If someone wants them on they turn on. Purism sells snakeoil. Presenting their offerings as FOSS-compatible wou…

It's not possible to remove, or at least account for all behavior of, the ME entirely until the BUP part is reverse engineered. You can't take that part out yet and have a working CPU as far as I understand.

I'm surprised you didn't mention the FSP which is a binary blob from Intel required to be run by any boot firmware (UEFI, Coreboot, or whatever) very early in the platform initialization process (to my understanding, basically as soon as possible after the reset vector, in the PEI phase) before anything is useable.

Baby steps. Don't let perfect be the enemy of good. Success here could indicate to CPU vendors there are people who care about these things.

Re: How Purism avoids Intel’s Active Management Technology

#7
post #3

Disabling is not removing. People have found motherboards that should ostensibly not support vPro (e.g. Asus gaming motherboards) that do report vPro ME functionality. There is no reason to believe the software switch is working, especially when even a system integrator can accidentally enable the features. If someone wants them on they turn on. Purism sells snakeoil. Presenting their offerings as FOSS-compatible wou…

It's not possible to remove, or at least account for all behavior of, the ME entirely until the BUP part is reverse engineered. You can't take that part out yet and have a working CPU as far as I understand. I'm surprised you didn't mention the FSP which is a binary blob from Intel required to be run by any boot firmware (UEFI, Coreboot, or whatever) very early in the platform initialization process (to my understand…

I know it isn't possible. Half measures are attractive short term but can serve to normalize failure, as is currently happening. Most people I know view Purism favorably and think it has actually made ME irrelevant. It hasn't, all the hardware is still there and can be enabled. You still are not the de facto owner of the machine.

Re: How Purism avoids Intel’s Active Management Technology

#8
post #5
post #3

Disabling is not removing. People have found motherboards that should ostensibly not support vPro (e.g. Asus gaming motherboards) that do report vPro ME functionality. There is no reason to believe the software switch is working, especially when even a system integrator can accidentally enable the features. If someone wants them on they turn on. Purism sells snakeoil. Presenting their offerings as FOSS-compatible wou…

Even though it`s true that ME is not 100% removed, most of it is. https://puri.sm/learn/software-freedom-in-perspective/

ME hasn't been removed at all. The hardware is still on the machine.

Re: How Purism avoids Intel’s Active Management Technology

#9
> We choose Intel CPUs that do not have vPro

The Wikipedia article they link about vPro says:

> Intel vPro technology ... [includes] VT-x, VT-d...

Does this mean that Purism hardware won't support virtualization extensions? Seems like that would be a big downside, and would make it a non-starter for a lot of people (including myself).

Re: How Purism avoids Intel’s Active Management Technology

#10
post #3

Disabling is not removing. People have found motherboards that should ostensibly not support vPro (e.g. Asus gaming motherboards) that do report vPro ME functionality. There is no reason to believe the software switch is working, especially when even a system integrator can accidentally enable the features. If someone wants them on they turn on. Purism sells snakeoil. Presenting their offerings as FOSS-compatible wou…

Even if they are not yet 100% sure, it's still far better than any other laptop from any other brand who don't even bother trying to do anything about it
Post reply on HN