9 ms·
Curious what your threat model is.
by samat 8y ago
Curious what your threat model is.
- chasil 8y agoThe Intel ME can be accessed over the connected ethernet even when the PC is shut down, as long as the power supply is attached. SA-00086 as an exploit is available through the ME. VISA is available for access by the (compromised) ME. This seems threatening enough to me.
- rzzzt 8y agoI am always confused about this part. Are systems that don't support vPro/AMT/MEBX also accessible over the motherboard's Ethernet connection?
- chasil 8y agoAs far as I know, yes. If you run the Linux ME reporting tool and it is identified, then ME is awaiting provisioning and commands. Every chipset has the CPU that serves the ME, separate from the CPU.
- magila 8y agoAll Intel systems contain ME hardware and firmware, but most consumer systems are not configured to support remote administration via the integrated ethernet port.
- beenBoutIT 8y agoOn older Intel chips it's possible to remove the ME and have a functional CPU. These Intel systems running Libreboot lack functional ME firmware/hardware.
- magila 8y agoNo. Systems which don't advertise vPro support probably don't include the necessary firmware even if the hardware is capable of supporting it.
- neop1x 8y agoit may be fully there, just disabled in software. I was able to query vpro firmware version from Linux on my laptop, which is "non-vPro" and I was able to use me_cleaner to remove most parts of ME firmware and physically flash the SPI flash chip. Now it shows "machine is not in committed state" in BIOS during booting but everything works (except ME of course).
- discreditable 8y agoThe Management Engine firmware blob for a non-vPro device is just under 2MB. For a vPro device it's 7MB. To me this hints that the functionality is not there rather than neutered. Of course, no one outside of Intel really knows.