5 ms·
As I understand it, ME is used to remotely control the processor like in a datacenter. If a datacenter is buying hundreds of thousands of these it makes sense
by blitmap 8y ago
As I understand it, ME is used to remotely control the processor like in a datacenter. If a datacenter is buying hundreds of thousands of these it makes sense to have it on by default so their people don't have to go in and turn anything on. As much as I recognize it as a vulnerability (to the extreme), it doesn't make sense to have it off by default. They should certainly support a way to _permanently_ disable it. I wish there were easy tools to verify ME is "not accessible" since I don't work in a datacenter and I wouldn't know how to test that it's off.
Things that come with great benefit to risk for abuse:
- Intel ME
- Computrace
- Device Guard
- philjohn 8y agoIIRC AMD allows their PSP to be disabled via the BIOS.
- IntelMiner 8y agoSome do. Though it's unclear what that does yet
- floatboth 8y agoIt definitely prevents the OS from accessing it over PCI, but whether it prevents the PSP from accessing the OS is indeed unclear.
- emsy 8y agoTheir motivations are irrelevant. Consumers aren't datacenters.
- TomMarius 8y agoYou know that companies deploy these processors as well, right? I just finished a deployment of 10k Intel i5 machines.
- emsy 8y agoAnd yet, customers still aren't datacenters, but still they carry the risks.
- JumpCrisscross 8y ago> Consumers aren't datacenters Consumers have also shown zero intention of paying more for secure devices. Until we have a public ME hack with real consequences, I do not expect that to change.
- emsy 8y agoThe funny thing is that making the processor more secure would require less work by not implementing a ME.
- daxorid 8y agoDemonstrably untrue. Consumers pay a premium for access to the Apple SEP and App Store review/analysis process (Jekyll and XCodeGhost notwithstanding, it's been a major security success)
- forapurpose 8y ago> ME is used to remotely control the processor like in a datacenter It's used to remotely manage almost all aspects of the computer; it's a parallel, out-of-band subsystem, complete with its own processor, memory and OS. It's very useful for managing computers at scale and at physical distances. Imagine making changes to thousands of computers; manual, one-at-a-time, hands-on solutions are very inefficient and error-prone. Imagine a campus or office building where the average distance from the IT support office to the computer is 20 minutes. Staff can spend most of their time in transit: 20 minutes there, 10 minute fix, 20 minutes back. 80% of the IT labor budget is paying people to walk. But I agree; there's no reason the computer's owners shouldn't have the power to disable it if they choose.
- acct1771 8y agoBackdoors that can be turned off are backdoors that can be turned on. Unless you have a fuse to be pulled, or blown.
- 76 8y agoIt might make sense only on Xeon CPUs, but consumer models like i7 are not meant for data centers.
- blitmap 8y agoThis is something obvious I had not considered. Good point!