10 ms·
Has Intel offered an official "disable ME" patch? I'd like to close the door once and not worry about it again.
by ipsin 8y ago
Has Intel offered an official "disable ME" patch? I'd like to close the door once and not worry about it again.
- kawsper 8y agoThere are no official ways of disabling the ME. The Coreboot project and the Hardenedlinux project have worked on it, and here are some resources on their progress: https://hardenedlinux.github.io/firmware/2016/11/17/neutralize_ME_firmware_on_sandybridge_and_ivybridge.html https://hardenedlinux.github.io/firmware/2016/11/17/neutrali... https://www.coreboot.org/Intel_Management_Engine https://www.coreboot.org/Intel_Management_Engine And here is a general writeup on the Intel chips and their "features": https://libreboot.org/faq.html#intel https://libreboot.org/faq.html#intel If Intel aren't going to patch old systems, here to hoping that they will let us disable it, but it probably won't happen.
- chasil 8y agoThere is a Python script that can take a BIOS image (either from a vendor or scanned from a running system) and remove all ME components that are not absolutely required to operate the CPU. I have never tried it. https://github.com/corna/me_cleaner https://github.com/corna/me_cleaner
- FredFS456 8y agoThere's also the leaked NSA "high assurance" bit, that completely disables the ME. Also included in the excellent me_cleaner tool.
- kcolford 8y agoThere's also system76's method of disabling the ME
- rubatuga 8y agoFor those who need a step by step tutorial for using me_cleaner with the Raspberry Pi, check out my easy video guide, which assumes no background knowledge. https://youtu.be/aRUxfxp9dJ8 https://youtu.be/aRUxfxp9dJ8
- deleted 8y ago[deleted]