3 ms·
Where do you get your information from? AFAIK, it's only has been stripped down to a bare minimum, putting it in some sort of recovery mode - but it can't be er
by timonovici 10y ago
Where do you get your information from? AFAIK, it's only has been stripped down to a bare minimum, putting it in some sort of recovery mode - but it can't be erased from the BIOS chip yet.
- eximius 10y agohttps://www.coreboot.org/pipermail/coreboot/2016-September/082049.html https://www.coreboot.org/pipermail/coreboot/2016-September/0...
- timonovici 10y agoI was thinking of this project - https://github.com/corna/me_cleaner https://github.com/corna/me_cleaner This is the one that strips most of the ME (which seems to be Java applets, if I remember correctly Igor Skochinsky's presentation), but there's still the core "OS" in PCH, which loads and executes the applets - we don't know what nefarious things that part of ME might be up to - and it has DMA, and access to the network controller - that's how they remotely wipe HDD's, even without an OS being installed, even without the computer being turned on - that shit is straight out of Orwell's 1984. Telescreen, that's what it is.
- walterbell 10y agoThanks for the info. Is there security benefit in running on a desktop with non-Intel (e.g. Broadcom) add-on NICs and nothing connected to the integrated Intel NIC?
- timonovici 10y agoYes. It seems this only works with Intel cards(wifi or ethernet); I don't know the reasons why, though - it might be some firmware support. Also, I find it odd that it can work with the wireless chip - shouldn't the laptop be associated with the AP? If somebody knows, I'd be happy to learn about it. Source: https://software.intel.com/en-us/blogs/2013/08/07/intel-vpro-technology-release-90-platform-requirements https://software.intel.com/en-us/blogs/2013/08/07/intel-vpro...