Re: Putting together a computer from old components

Paul <[email protected]>
Newsgroups alt.comp.hardware,uk.comp.homebuilt
Organization A noiseless patient Spider
Message-ID <[email protected]>
On 12/5/2021 10:39 AM, Spiros Bousbouras wrote:
> On Mon, 29 Nov 2021 20:05:24 +0000
> Richard Kettlewell <[email protected]> wrote:
>> Spiros Bousbouras <[email protected]> writes:
>>> Richard Kettlewell <[email protected]> wrote:
>>>> Spiros Bousbouras <[email protected]> writes:
>>
>>>>> The Intel management engine and the analogous from AMD creep me out
>>>>> so I want to put a computer together using old processors from
>>>>> before these facilities came into the picture.
>>>>
>>>> Is there a reason why you don’t want to buy a current platform and
>>>> disable the feature in the firmware? You might need to do a bit of
>>>> research to ensure you get something where disabling it is possible
>>>> but it seems a lot easier than building a computer from old parts.
>>>
>>> Is it possible to disable them ?
>>> https://en.wikipedia.org/wiki/AMD_Secure_Technology  does not say
>>> anything.
>>
>> https://software.intel.com/sites/manageability/AMT_Implementation_and_Reference_Guide/default.htm?turl=WordDocuments%2Fdisablingintelamt.htm
> 
> This page is about disabling AMT :
> https://en.wikipedia.org/wiki/Intel_Management_Engine :
>      The Management Engine is often confused with Intel AMT (Intel Active
>      Management Technology). AMT runs on the ME, but is only available on
>      processors with vPro. AMT gives device owners remote administration of
>      their computer,^[6] such as powering it on or off, and reinstalling the
>      operating system.
> 
>      However, the ME itself is built into all Intel chipsets since 2008, not
>      only those with AMT. While AMT can be unprovisioned by the owner, there
>      is no official, documented way to disable the ME.^[citation needed]
> 
> Although it says "citation needed" , I find it unlikely that , if there was a
> way to disable the ME , someone would not have added it to the article by now. In
> any case see also
> 
> https://www.techrepublic.com/article/is-the-intel-management-engine-a-backdoor/ :
>      Various sources report that Intel's latest x86 chips contain a secret
>      backdoor. SoftPedia cites security expert Damien Zammit as revealing that
>      these Intel chips come with an embedded subsystem called the Management
>      Engine (ME) that functions as a separate CPU and cannot be disabled, and
>      the code is proprietary.
>      [...]
> 
>      However, the ME contains the AMT instructions, which can function
>      similarly to wake-on-LAN. That means if the right person used the ME to
>      gain access to a machine, they could then take advantage of AMT and boot
>      the machine. Viola! Your PC is now readily available for someone with the
>      requisite skills to pick and choose what they want--this could include
>      company data.
>      [...]
> 
>      The good news is that you can disable the AMT feature. Here's how.
> 
>        * In the PC BIOS, go to Advance Chipset Feature | Intel AMT
>          (Enabled,Disabled)
>        * During boot, CTRL+P to go to AMT Menu | Intel ME Control State
>          (Enabled,Disabled)
> 
>      There is no way to know if the ME has the ability to re-enable AMT on its
>      own. Why? Because no one except Intel knows what exactly it contains. So,
>      you could disable ATM on the machine and not know if the ME can
>      circumvent that BIOS setting.

It's not a "secret" enclave, as there was at least one slide
deck about the feature set.

I've not seen a slide deck since the Wifi was added to
the more modern setups. The Intel NIC is dual-headed
(so certain NICs are needed to make it work). And it is
possible the Intel Wifi modules have dual head as well.

http://pds4.egloos.com/pds/200706/04/57/ps_adts003.pdf

Since it potentially can be used for anti-theft purposes,
that's why there can't be a hardware jumper plug to
guarantee it is off. A thief would just use that.

    Paul
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.