Re: Putting together a computer from old components
Spiros Bousbouras <[email protected]>
| Newsgroups | alt.comp.hardware,uk.comp.homebuilt |
|---|---|
| Organization | Aioe.org NNTP Server |
| Message-ID | <[email protected]> |
On Mon, 29 Nov 2021 20:05:24 +0000 Richard Kettlewell <[email protected]> wrote: > Spiros Bousbouras <[email protected]> writes: > > Richard Kettlewell <[email protected]> wrote: > >> Spiros Bousbouras <[email protected]> writes: > > >>> The Intel management engine and the analogous from AMD creep me out > >>> so I want to put a computer together using old processors from > >>> before these facilities came into the picture. > >> > >> Is there a reason why you don’t want to buy a current platform and > >> disable the feature in the firmware? You might need to do a bit of > >> research to ensure you get something where disabling it is possible > >> but it seems a lot easier than building a computer from old parts. > > > > Is it possible to disable them ? > > https://en.wikipedia.org/wiki/AMD_Secure_Technology does not say > > anything. > > https://software.intel.com/sites/manageability/AMT_Implementation_and_Reference_Guide/default.htm?turl=WordDocuments%2Fdisablingintelamt.htm This page is about disabling AMT : https://en.wikipedia.org/wiki/Intel_Management_Engine : The Management Engine is often confused with Intel AMT (Intel Active Management Technology). AMT runs on the ME, but is only available on processors with vPro. AMT gives device owners remote administration of their computer,^[6] such as powering it on or off, and reinstalling the operating system. However, the ME itself is built into all Intel chipsets since 2008, not only those with AMT. While AMT can be unprovisioned by the owner, there is no official, documented way to disable the ME.^[citation needed] Although it says "citation needed" , I find it unlikely that , if there was a way to disable the ME , someone would not have added it to the article by now. In any case see also https://www.techrepublic.com/article/is-the-intel-management-engine-a-backdoor/ : Various sources report that Intel's latest x86 chips contain a secret backdoor. SoftPedia cites security expert Damien Zammit as revealing that these Intel chips come with an embedded subsystem called the Management Engine (ME) that functions as a separate CPU and cannot be disabled, and the code is proprietary. [...] However, the ME contains the AMT instructions, which can function similarly to wake-on-LAN. That means if the right person used the ME to gain access to a machine, they could then take advantage of AMT and boot the machine. Viola! Your PC is now readily available for someone with the requisite skills to pick and choose what they want--this could include company data. [...] The good news is that you can disable the AMT feature. Here's how. * In the PC BIOS, go to Advance Chipset Feature | Intel AMT (Enabled,Disabled) * During boot, CTRL+P to go to AMT Menu | Intel ME Control State (Enabled,Disabled) There is no way to know if the ME has the ability to re-enable AMT on its own. Why? Because no one except Intel knows what exactly it contains. So, you could disable ATM on the machine and not know if the ME can circumvent that BIOS setting. -- There's a definition of horror: the genre where all the decisions are wrong ones. James Nicoll https://groups.google.com/group/rec.arts.sf.written/msg/292fed66d24dc0cf?dmode=source <[email protected]>