Re: Putting together a computer from old components
Richard Kettlewell <[email protected]>
| Newsgroups | alt.comp.hardware,uk.comp.homebuilt |
|---|---|
| Organization | terraraq NNTP server |
| Message-ID | <[email protected]> |
Spiros Bousbouras <[email protected]> writes: > SH <[email protected]> wrote: >> what is it about the intel management engine that creeps you out? > > That there is a part of the processor running secret code which has > access to everything on the computer (memory , storage media , > internet communications) and nothing in the software that you choose > to run on your computer can affect this. You could say much the same about the CPU microcode or the platform firmware (e.g. UEFI, or BIOS if you can find something old enough). > Note also that these management engines are an additional large and > complicated attack surface which doesn't buy *me* anything. I'm not > even sure why they're there , I mean what is the official > justification ? Platform-level remote management. > I'd rather avoid Intel since their processors have had too many > vulnerabilities over the years even unrelated to the management > engine. How many is too many? AMD and ARM CPUs have had vulnerabilities too, and almost certainly will have more in the future. In all cases I suspect you’re more at risk from vulnerabilities in the software you run on them. Disabling this stuff may reduce your total risk, but not necessarily by as much as you hope. -- https://www.greenend.org.uk/rjk/