4 ms·
It is possible to use an Intel machine without the ME. Since there are constant vulnerabilities and exploits around the ME, many enthusiasts do not like the ide
by elagost 7y ago
It is possible to use an Intel machine without the ME. Since there are constant vulnerabilities and exploits around the ME, many enthusiasts do not like the idea of a vulnerable and secret super-admin computer on their computer. There is the option to disable the ME on supported devices (usually old Thinkpads) using me_cleaner[1].
I personally run Coreboot on my Thinkpad with the ME "disabled" (essentially just broken and stuck in a constant bring-up state), and System76[2], Purism[3], and Dell sell machines with the option of disabling the ME entirely, if one is super-paranoid.
[1] https://github.com/corna/me_cleaner https://github.com/corna/me_cleaner
[2] https://system76.com/laptops https://system76.com/laptops
[3] https://puri.sm/learn/intel-me/ https://puri.sm/learn/intel-me/
- smolder 7y agoYou can also flip the HAP bit in the bios descriptor region on the newest Intel chips (that me_cleaner does not support) using the Intel flashing tools. It's just called "reserved bit" and defaults to false.
- red_phone 7y agoI’m confused... other comments reference ME as the root-of-trust for the system, the chip that brings the CPU out of reset. How can a system be operational without that functionality?
- criddell 7y agoWhy wouldn't it work? Intel-based motherboards didn't always have a ME.
- wolf550e 7y agoCurrent Intel chipsets and CPUs cannot initialize the system without the ME. You can disable all the applications running on the ME, but it is required to bring up the system.
- wmf 7y agoYou can "disable" the ME but you can't disable it. People are being loose with terminology.
- chithanh 7y agoNo, you cannot use modern Intel systems without the ME. me_cleaner will only remove parts of it. What happens exactly (whether it actually stops working or goes into some undocumented free-for-all debug mode) is unknown as there is no introspection into the ME. HAP bit is asking the ME nicely to disable itself, sometime after it booted the system. https://twitter.com/rootkovska/status/939064351008395264 https://twitter.com/rootkovska/status/939064351008395264 Purism routinely overstates their capabilities in this regard, claiming to "neutralize" the ME. Also note that the ME is a hardware feature. Most efforts to remove/disable it focus on the ME firmware, which is loaded only some time after boot. Some ME function remains even if you completely zero out the firmware. See Peter Stuge's 30C3 Talk "Hardening hardware and choosing a #goodBIOS", noting IPv6 packet sent over the network interface even then (around 17:18 mark).