3 ms·
You can run netstat and see it is no longer listening. Now, how you would verify this when the computer is off is beyond me (assuming it is the case - I have no
by gaia 9y ago
You can run netstat and see it is no longer listening. Now, how you would verify this when the computer is off is beyond me (assuming it is the case - I have not yet been able to go thru the PDF below)
- algesten 9y agoYou can use something like nmap to scan open ports from another machine. Nmap can both do host discovery (find IP addresses) as well as port scans. https://nmap.org https://nmap.org
- derefr 9y agoThe thing that was listening is just AMT. The ME consists of a much wider suite of behaviors. For example: there's an embedded-profile JVM for running Java Card smart-card software, allowing enterprises to deploy crypto auth firmware written for smart-cards directly to the device. This avoids the need to flash, deploy, and manage hardware smart cards, while also preventing the OS from being able to introspect said software's operation. (This particular feature almost sounds like a good thing, doesn't it? It's a programmable TPM!)
- lima 9y agoIn fact, AMT isn't listening in the operating system either but directly on the ME. What OP removed is probably some sort of OS-level agent that collects information about the system (installed software, patches, ...).
- deleted 9y ago[deleted]
- amluto 9y agoHmm, a programmable TPM / secure element running as a program on an undocumented OS that also runs a web server and is probably not hardened (and might not even have privilege separation or even an MMU for all I know) but nonetheless has superpowers over the main CPU. I'll stick with a hardware TPM, thank you very much. (Qualcomm's TrustZone kernel runs on a similarly limited but much better documented platform, does not run a web server, and has had a good share of vulnerabilities over the years. I see no reason to expect Intel's ME software stack to be any better.)
- lima 9y agoYou misunderstood what ME is - it's not only a piece of software running in your operating system, but also an entirely separate processor that runs its own firmware. It has its own network stack and entirely bypasses the operating system - you cannot see it listening using netstat, you wouldn't even see the actual communication using Wireshark. It works even when the computer is off (which makes sense for an out-of-band management solution).